<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWStats configdir exec in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/awstats-configdir-exec/m-p/1062582#M79274</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not really sure.  I don't use it myself but honestly someone inside the network could be. I just get the alerts, do the research, pass-on advice, etc...Thanks for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 Jul 2008 11:04:25 GMT</pubDate>
    <dc:creator>shiznitide</dc:creator>
    <dc:date>2008-07-29T11:04:25Z</dc:date>
    <item>
      <title>AWStats configdir exec</title>
      <link>https://community.cisco.com/t5/network-security/awstats-configdir-exec/m-p/1062580#M79272</link>
      <description>&lt;P&gt;In the past week, I have received a plethera of alerts with this High Level title.  After blacklisting the host IP it is back with a different one.  I am starting to get concerned because the first IP address that was blacklisted was a hacker.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone tell me if this is a false positive or not?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or, what is actually setting this sensor off?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:13:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/awstats-configdir-exec/m-p/1062580#M79272</guid>
      <dc:creator>shiznitide</dc:creator>
      <dc:date>2019-03-10T11:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: AWStats configdir exec</title>
      <link>https://community.cisco.com/t5/network-security/awstats-configdir-exec/m-p/1062581#M79273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That signatures fires on a match of an attempt to call the awstats.pl cgi script with a parameter of configdir and a parameter value containing a ";" or "|".  It seems pretty unlikely to be a false positive in the sense that it is probably not legitimate traffic. It isn't necessarily a hacker targeting your systems...it may just be a worm or script that scans the Internets looking for vulnerable systems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you use awstats?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2008 16:46:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/awstats-configdir-exec/m-p/1062581#M79273</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2008-07-28T16:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: AWStats configdir exec</title>
      <link>https://community.cisco.com/t5/network-security/awstats-configdir-exec/m-p/1062582#M79274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not really sure.  I don't use it myself but honestly someone inside the network could be. I just get the alerts, do the research, pass-on advice, etc...Thanks for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jul 2008 11:04:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/awstats-configdir-exec/m-p/1062582#M79274</guid>
      <dc:creator>shiznitide</dc:creator>
      <dc:date>2008-07-29T11:04:25Z</dc:date>
    </item>
  </channel>
</rss>

