Cisco Router SYNFul Knock Command

Strike ID:
B15-fw101
CVSS:
4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
4
Year:
2015

Description

This strike simulates the sending of a controller command to a Cisco router infected with the malware commonly referred to as SYNFul Knock. After completing a modified three-way handshake a control command will be sent to the infected router, which will respond with an HTTP message.

References