Files
2025-04-26 22:42:45 +08:00

15 lines
669 B
Plaintext

rule Exploit_Linux_Looter_B_xp{
meta:
description = "Exploit:Linux/Looter.B!xp,SIGNATURE_TYPE_ELFHSTR_EXT,04 00 04 00 05 00 00 "
strings :
$a_01_0 = {73 75 63 6b 69 74 5f 73 65 6c 69 6e 75 78 } //2 suckit_selinux
$a_01_1 = {67 65 74 5f 65 78 70 6c 6f 69 74 5f 73 74 61 74 65 5f 70 74 72 } //2 get_exploit_state_ptr
$a_03_2 = {65 78 70 5f [0-15] 2e 63 } //2
$a_01_3 = {53 79 73 74 65 6d 20 69 73 20 6e 6f 74 20 76 75 6c 6e 65 72 61 62 6c 65 } //1 System is not vulnerable
$a_01_4 = {64 69 72 74 79 5f 63 6f 64 65 } //1 dirty_code
condition:
((#a_01_0 & 1)*2+(#a_01_1 & 1)*2+(#a_03_2 & 1)*2+(#a_01_3 & 1)*1+(#a_01_4 & 1)*1) >=4
}