On this page

Atomicorp WAF Rule 391158

Rule Summary

  • Rule ID: 391158
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: PHP c99 webshell
  • Observed CWEs: None documented
  • Revision: 1
  • Rule severity: Alert (1)
  • Phase: 2 (request body)
  • Request surfaces: Request argument names, JSON request data, SOAP request data
  • Rule action: deny
  • HTTP status: 404
  • Logging: log, auditlog

Description

This detects if the c99 web shell is installed on the system. The shell is often used by malicious parties to create a back door into the system.

Troubleshooting

False Positives

There are no known false positives with this rule. Please do not report this as a false positive if you allow the use of the c99 shell on your system.

If you believe this is a false positive, please report this following the process at the link below:

Tuning Guidance

Please see the Tuning the Atomicorp WAF Rules page for more information if you wish to disable or modify this rule.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

No selected related public CVE research notes are currently published.

Documentation Source

  • Original wiki page: WAF 391158
  • Source revision: 4959
  • Source revision date: 2014-06-24