Name:Juniper Networks Remote Code Execution Exploit Detection id:6cc4cc3d-b10a-4fac-be1e-55d384fc690e version:9 date:None author:Michael Haag, Splunk status:production type:TTP Description:The following analytic detects attempts to exploit a remote code execution vulnerability in Juniper Networks devices. It identifies requests to /webauth_operation.php?PHPRC=*, which are indicative of uploading and executing malicious PHP files. This detection leverages the Web data model, focusing on specific URL patterns and HTTP status codes. This activity is significant because it signals an attempt to gain unauthorized access and execute arbitrary code on the device. If confirmed malicious, the attacker could gain control over the device, leading to data theft, network compromise, or other severe consequences. Data_source:
-Suricata
search:| tstats count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Web WHERE Web.url IN ("*/webauth_operation.php?PHPRC=*") Web.status=200 BY Web.http_user_agent, Web.status Web.http_method, Web.url, Web.url_length, Web.src, Web.dest, sourcetype | `drop_dm_object_name("Web")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `juniper_networks_remote_code_execution_exploit_detection_filter`