CISA – Reports

Category Added in a WPeMatico Campaign

MAR-10443863-1.v1 CVE-2017-9248 Exploitation in U.S. Government IIS Server

   Summary Description CISA received three files for analysis. The files included three webshells written in PHP: Hypertext Preprocessor (PHP), Active Server Pages Extended (ASPX), and .NET Dynamic-Link Library (DLL). The sample “sd.php” is highly obfuscated and uses rot13 algorithm, zlib for compression and base64 encoding for obfuscation. The “osker.aspx” webshell code was padded with […]

MAR-10443863-1.v1 CVE-2017-9248 Exploitation in U.S. Government IIS Server Read More »

MAR-10413062-1.v1 Telerik Vulnerability in U.S. Government IIS Server

Notification This report is provided “as is” for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained herein. The DHS does not endorse any commercial product or service referenced in this bulletin or otherwise. This document is marked TLP:CLEAR–Disclosure is not limited. Sources

MAR-10413062-1.v1 Telerik Vulnerability in U.S. Government IIS Server Read More »

MAR-10365227-2.v1

Notification This report is provided “as is” for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained herein. The DHS does not endorse any commercial product or service referenced in this bulletin or otherwise. This document is marked TLP:WHITE–Disclosure is not limited. Sources

MAR-10365227-2.v1 Read More »