NetScaler Remote Code Execution Forensics
ID: 9e4fdc13-f520-5d5c-ab5d-c4ab3d662b17
STIX ID: report--9e4fdc13-f520-5d5c-ab5d-c4ab3d662b17
Feed Name: TrustedSec blog
This TrustedSec advisory documents forensic indicators and investigative steps for Citrix ADC/NetScaler CVE-2019-19781, describing how an unauthenticated directory-traversal RCE can be exploited to run commands as user nobody and install backdoors; it lists relevant FreeBSD log files (bash.log, sh.log, notice.log, httpaccess/httperror), suspicious HTTP request patterns, file locations (/netscaler/portal/templates, /var/tmp/netscaler/portal/templates), process signs (child httpd processes running shells/python), and suggests checking nobody's cron jobs and obtaining disk images, plus links to mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
