Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

WORM:MARE-D-SCAN

Severity

High

Recommended

No

Recommended Action

Drop

Category

WORM

Keywords

Mare.D Scan

Release Date

2006/02/28

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

WORM: Mare.D Scan


This signature detects the activity of the Mare.D worm as it scans for vulnerable Linux servers. Mare.D exploits known vulnerabilities in the Mambo content management system and the PHP XML-RPC library. When a successful attack is made, this worm leaves multiple backdoors on infected systems. Two of these are connectback shell backdoors that link to a remote host, while a third backdoor allows the malware's writer to access and control infected systems through Internet Relay Chat (IRC).

Extended Description

None

References

  • CVE: CVE-2005-0512

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out