TerraMaster TOS CVE-2020-28188
Detects the exploitation of the TerraMaster TOS vulnerability described in CVE-2020-28188
Sigma rule (View on GitHub)
1title: TerraMaster TOS CVE-2020-28188
2id: 15c312b9-00d0-4feb-8870-7d940a4bdc5e
3status: test
4description: Detects the exploitation of the TerraMaster TOS vulnerability described in CVE-2020-28188
5references:
6 - https://www.ihteam.net/advisory/terramaster-tos-multiple-vulnerabilities/
7 - https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/
8author: Bhabesh Raj
9date: 2021-01-25
10modified: 2023-01-02
11tags:
12 - attack.t1190
13 - attack.initial-access
14 - cve.2020-28188
15 - detection.emerging-threats
16logsource:
17 category: webserver
18detection:
19 base_url:
20 cs-method: 'GET'
21 cs-uri-query|contains|all:
22 - '/include/makecvs.php'
23 - '?Event='
24 payload:
25 cs-uri-query|contains:
26 - 'curl'
27 - 'wget'
28 - '.py'
29 - '.sh'
30 - 'chmod'
31 - '_GET'
32 condition: base_url and payload
33fields:
34 - c-ip
35 - c-dns
36falsepositives:
37 - Unknown
38level: high
References
Related rules
- ADSelfService Exploitation
- Apache Spark Shell Command Injection - Weblogs
- Arcadyan Router Exploitations
- Atlassian Bitbucket Command Injection Via Archive API
- CVE-2010-5278 Exploitation Attempt