*** NK8 RELS 3477 Release *** Total number of signatures: 3135 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 7 rule(s): --------------- 1136792 WEB rConfig commands.inc.php SQL Injection -1 (CVE-2020-10220) 1136793 WEB rConfig commands.inc.php SQL Injection -2 (CVE-2020-10220) 1136796 WEB-CLIENT Mozilla Firefox Custom Elements Object Write After Free (CVE-2018-18500) 1136797 WEB ACME mini_httpd Arbitrary File Read -2 (CVE-2018-18778) 1136798 WEB rConfig commands.inc.php SQL Injection -3 (CVE-2020-10220) 1136806 WEB PlaySMS index.php Unauthenticated Template Injection Code Execution (CVE-2020-8644) 1136810 WEB Apache Solr Remote Code Execution via Velocity Template (CVE-2019-17558) Modified 362 rule(s): --------------- 1051254 P2P FastTrack transfer via TCP -1 1051701 TUNNEL VNN Client login via UDP -1 1051825 MEDIA Windows Media Player media via TCP -2 1051826 MEDIA Windows Media Player media via TCP -3 1051827 MEDIA Windows Media Player media via TCP -4 1051850 MEDIA RealPlayer media via TCP -1 1052068 MEDIA RealPlayer media via TCP -2 1052069 MEDIA RealPlayer media via TCP -3 1052071 IM AIM/ICQ/iIM communicate via TCP -5 1052285 MEDIA QQLive login via TCP -1 1052287 MEDIA PPTV media via TCP -1 1052580 MAIL Yahoo access via TCP -2 1052616 GAME QQ/QQFO login via TCP -4 1052623 MEDIA PPTV media via TCP -2 1052641 WEB-IM iLoveIM access via TCP -1 1052642 WEB-IM iLoveIM login via TCP -1 1052832 MEDIA iQIYI/PPS media via TCP -1 1052852 MEDIA PPTV media via UDP -1 1052857 TUNNEL VNN Client login via UDP -2 1052858 MEDIA PPTV media via TCP -3 1052859 MEDIA PPTV media via TCP -4 1052902 MEDIA PPTV media via TCP -5 1052903 MEDIA PPTV media via TCP -6 1052905 CA Microsoft Authentication via SSL -4 1052918 MEDIA Windows Media Player media via TCP -5 1052993 P2P Ares access via TCP -2 1053006 MEDIA PPTV media via TCP -7 1053017 P2P Thunder transfer via TCP -9 1053019 CA AOL Authentication via SSL -1 1053020 IM AIM/ICQ/iIM media-audio via TCP -5 1053027 TUNNEL HTTP-Tunnel login via TCP -1 1053043 TUNNEL HTTP Proxy Server communicate via TCP -1 1053048 NETWORK SSL/TLS Handshake access via SSL -1 1053057 TERMINAL TeamViewer communicate via TCP -6 1053075 TUNNEL CCProxy access via TCP -1 1053076 TUNNEL CCProxy access via TCP -2 1053077 TUNNEL CCProxy access via TCP -3 1053078 TUNNEL CCProxy access via TCP -4 1053108 MEDIA PPTV access via TCP -1 1053109 MEDIA PPTV access via TCP -2 1053115 IM AIM/ICQ/iIM login via TCP -8 1053116 IM AIM/ICQ/iIM login via TCP -7 1053121 WEB-IM eBuddy login via TCP -6 1053122 WEB-IM eBuddy login via TCP -7 1053180 P2P BT-BitTorrent transfer via TCP -7 1053190 IM AliWW login via TCP -1 1053195 MEDIA FLV file media via TCP -1 1053196 IM Wlt login via TCP -1 1053197 IM Lava-Lava login via TCP -1 1053199 IM Paltalk login via TCP -1 1053200 IM ISPQ login via TCP -1 1053203 IM Kubao login via TCP -1 1053204 PRIPROTOCOL Jabber login via TCP -1 1053213 PRIPROTOCOL Jabber login via TCP -2 1053214 MEDIA SopCast media via UDP -1 1053218 IM WinpopupX login via UDP -1 1053221 IM Pidgin access via TCP -1 1053222 IM QQ/TM login via UDP -2 1053223 MEDIA iQIYI/PPS media via UDP -1 1053225 P2P eDonkey-easyMule access via TCP -1 1053226 P2P BT-BitTorrent transfer via TCP -8 1053229 GAME Sina Web login via TCP -1 1053249 GAME WoW login via TCP -1 1053270 MEDIA SopCast media via TCP -2 1053273 MEDIA FLV file media via TCP -2 1053282 STOCK 10JQKA login via TCP -1 1053283 STOCK DZH login via TCP -1 1053284 STOCK DZH login via TCP -2 1053285 STOCK Compass.cn login via TCP -1 1053296 P2P Thunder access via TCP -1 1053297 P2P Thunder access via TCP -2 1053298 P2P Thunder access via TCP -3 1053299 P2P Thunder access via TCP -4 1053303 TERMINAL GoToMyPC login via SSL -1 1053310 TUNNEL VNN Client login via TCP -1 1053316 IM Kubao login via TCP -2 1053325 WEB-IM ICQ login via TCP -2 1053326 WEB-IM ICQ login via TCP -3 1053341 WEB-IM AOL login via TCP -3 1053342 IM POPO login via TCP -3 1053364 MEDIA PPTV media via TCP -13 1053365 MEDIA PPTV media via UDP -2 1053366 MEDIA PPTV media via UDP -3 1053367 P2P BT-BitComet transfer via TCP -1 1053380 WEB-IM eBuddy login via TCP -8 1053384 MEDIA UUSee media via UDP -1 1053409 TERMINAL PCAnywhere access via TCP -1 1053415 MEDIA Sina Video media via UDP -1 1053426 P2P Gnutella-Foxy communicate via TCP-4 1053432 IM QQ/TM login via UDP -3 1053433 PRIPROTOCOL Jabber login via TCP -3 1053461 IM Caihong login via TCP -1 1053466 IM AliWW login via TCP -3 1053470 MEDIA PPTV media via TCP -8 1053472 MEDIA PPTV media via UDP -4 1053475 MEDIA KKBox login via TCP -1 1053577 CA Microsoft Authentication via SSL -2 1053592 IM POPO transfer via UDP -1 1053608 WEB-IM eBuddy login via TCP -9 1053609 IM Fetion communicate via TCP -1 1053610 STOCK DZH login via TCP -3 1053623 STOCK StockStar login via TCP -1 1053641 IM Fetion login via SSL -1 1053643 IM Fetion transfer via TCP -1 1053644 IM Fetion transfer via TCP -2 1053650 IM Fetion media-audio via TCP -1 1053656 IM QQ/TM login via UDP -5 1053672 GAME PopKart login via TCP -2 1053694 WEB-IM QQ login via TCP -1 1053701 IM Digsby login via TCP -1 1053707 STOCK DZH login via TCP -4 1053708 IM Alicall login via UDP -1 1053709 IM Alicall login via TCP -1 1053737 MEDIA SWF file media via TCP -1 1053752 MEDIA PPTV media via TCP -14 1053850 MEDIA PPTV media via TCP -9 1053851 MEDIA PPTV media via UDP -5 1053852 MEDIA PPTV media via UDP -6 1053855 MEDIA PPTV media via TCP -15 1053859 MEDIA Sina Video media via UDP -2 1053869 AP State - TUNNEL Freegate http request fragment evasion 0-1 1053872 IM Fetion login via SSL -2 1054135 WEB-IM QQ login via TCP -2 1054145 P2P Ares access via TCP -3 1054159 MEDIA PPTV media via TCP -10 1054160 MEDIA PPTV access via TCP -3 1060009 WEB-IM AirAim login via TCP -1 1060028 WEB-IM Instan-t login via TCP -1 1060035 SOCIAL Facebook access via TCP -1 1060210 WEB Evernote access via SSL -1 1061625 SOCIAL Plurk access via TCP -1 1061627 SOCIAL Twitter access via TCP -1 1061710 P2P eDonkey-easyMule access via TCP -2 1061724 MEDIA PPTV media via TCP -11 1061725 MEDIA PPTV media via UDP -7 1061726 P2P eDonkey-easyMule access via UDP -2 1061727 P2P eDonkey-easyMule access via UDP -3 1061728 PRIPROTOCOL QQ series transfer via TCP -1 1061729 PRIPROTOCOL QQ series transfer via UDP -1 1061730 MEDIA PPTV media via TCP -12 1061732 MEDIA 56.com access via TCP -1 1061733 MEDIA Sohu TV access via TCP -1 1061734 GAME WOW login via TCP -2 1061756 MEDIA PPTV media via UDP -12 1061757 MEDIA PPTV media via UDP -13 1061758 MEDIA PPTV media via UDP -14 1061759 MEDIA PPTV media via UDP -15 1061760 MEDIA PPTV media via UDP -16 1061761 MEDIA PPTV media via UDP -17 1061763 MEDIA iQIYI/PPS access via TCP -1 1061764 MEDIA iQIYI/PPS access via TCP -2 1061778 MEDIA Youku.com media via UDP -1 1061779 MEDIA Youku.com media via TCP -1 1061781 MEDIA PPTV media via UDP -18 1061808 STOCK DZH login via TCP -6 1061809 STOCK DZH login via TCP -7 1061811 MAIL Sina login via TCP -1 1061814 IM AIM/ICQ/iIM login via TCP -4 1061815 IM AIM/ICQ/iIM login via TCP -5 1061816 IM Fetion login via TCP -3 1062349 MEDIA PPTV media via UDP -20 1062353 MEDIA PPTV media via UDP -21 1062405 WEB-IM eBuddy login via TCP -10 1062441 CA AOL Authentication via SSL -2 1062444 MEDIA Ooyala login via SSL -1 1062460 MAIL Sina login via TCP -2 1062461 IM AIM/ICQ/iIM login via SSL -2 1063149 MAIL Sina access via TCP -1 1063196 PRIPROTOCOL QQ series transfer via TCP -2 1063214 PRIPROTOCOL QQ series transfer via TCP -3 1063219 PRIPROTOCOL QQ series transfer via TCP -4 1063238 IM AIM/ICQ/iIM login via SSL -1 1063302 FILE Dropbox access via TCP -1 1063351 STOCK DZH login via TCP -8 1063352 TUNNEL Wujie/UltraSurf login state 0 via SSL -3 1063356 GAME WoW communicate via TCP -2 1063364 MEDIA TudouVa communicate via TCP -1 1063365 MEDIA TudouVa communicate via TCP -2 1063373 STOCK DZH access via TCP -2 1063375 STOCK 10JQKA access via TCP -1 1063390 GAME Sina Web login via TCP -2 1063392 IM Fetion login via TCP -4 1063393 IM Fetion login via TCP -5 1063394 IM Fetion media-audio via TCP -2 1063395 IM Fetion media-video via TCP -3 1063437 MEDIA Sohu TV access via TCP -2.1 1063438 SOCIAL Facebook access via TCP -3 1063439 SOCIAL Facebook access via TCP -2 1063446 MEDIA Qvod media via UDP -1 1063447 MEDIA Qvod media via TCP -1 1063448 MEDIA Qvod media via TCP -2 1063453 MEDIA RTMP media via TCP -2 1063455 IM QQ/TM transfer via UDP -8 1063456 IM QQ/TM transfer via TCP -5 1063499 IM Fetion transfer via TCP -3 1063502 MEDIA Grooveshark login via SSL -1 1063503 MEDIA Grooveshark access via TCP -1 1063504 MEDIA Microsoft Silverlight media via TCP -1 1063505 MEDIA Microsoft Silverlight media via TCP -2 1063519 CA MicrosoftOnline Authentication via SSL -1 1063543 MAIL Pchome login via SSL -1 1063544 WEB RSS access via TCP -1 1063574 IM AIM/ICQ/iIM login via TCP -10 1063587 IM Digsby login via TCP -2 1063588 WEB-IM Karoo Lark login via TCP -1 1063592 IM POPO login via TCP -4 1063660 NETWORK SSL/TLS Handshake access via SSL -2 1063661 NETWORK SSL/TLS Handshake access via SSL -3 1063662 NETWORK SSL/TLS Handshake access via SSL -4 1063663 NETWORK SSL/TLS Handshake access via SSL -5 1063903 WEB Evernote access via TCP -1 1063919 MAIL NETEASE login via SSL -2 1063920 MAIL NETEASE login via SSL -3 1063939 NETWORK SSL/TLS Handshake access via SSL -6 1063943 SOCIAL Plurk login via TCP -1 1064002 MEDIA PPTV media via TCP -16 1064003 MEDIA PPTV media via UDP -24 1064015 IM WhatsApp login via SSL -1 1064016 IM Tlen login via SSL-1 1064020 IM Alicall login via TCP -2 1064021 IM Alicall login via TCP -3 1064025 MEDIA PPTV media via UDP -25 1064028 TERMINAL GoToMyPC login via TCP -1 1064063 IM Digsby login via TCP -3 1064064 MEDIA Letv access via TCP -1 1064065 PRIPROTOCOL QQ series transfer via TCP -6 1064078 STOCK Compass.cn login via TCP -2 1064083 IM AliWW transfer via TCP -2 1064085 MEDIA Qvod access via UDP -1 1064086 MEDIA Qvod access via UDP -2 1064125 TERMINAL TeamViewer communicate via TCP -3 1064171 TERMINAL GoToMyPC access via TCP -1 1064188 P2P eDonkey-easyMule access via SSL -1 1064191 P2P BT-BitComet transfer via TCP -2 1064373 IM QQ/TM login via UDP -4 1064399 TUNNEL VNN Client login via TCP -2 1064417 IM AliWW transfer via UDP -1 1064419 MEDIA SopCast media via UDP -2 1064591 MEDIA BaiduMusic access via TCP -1 1064592 MEDIA BaiduMusic access via UDP -1 1064623 MEDIA BaiduMusic access via TCP -2 1064625 MEDIA BaiduMusic media via TCP -1 1064627 MEDIA BaiduMusic media via UDP -1 1064805 MAIL Sina transfer via TCP -1 1064863 MEDIA iQIYI/PPS login via TCP -4 1064864 MEDIA iQIYI/PPS login via TCP -5 1064865 MEDIA iQIYI/PPS access via TCP -3 1064867 MEDIA iQIYI/PPS media via UDP -6 1064997 MEDIA Sohu TV media via TCP -5 1065468 MEDIA Sohu TV media via TCP -1 1065469 MEDIA Sohu TV media via TCP -2 1065489 MEDIA iQIYI/PPS media via TCP -3 1065493 MEDIA Letv media via TCP -1 1065709 MEDIA KKBox login via TCP -2 1065878 SOCIAL Facebook access via SSL -1 1065905 IM AliWW transfer via TCP -1 1065906 IM AliWW transfer via TCP -3 1065932 TERMINAL GoToMyPC access via TCP -2 1065957 MEDIA Letv login via TCP -1 1065963 MEDIA iQIYI/PPS login via SSL -1 1065984 WEB-IM QQ login via SSL -2 1065988 TUNNEL Wujie/UltraSurf login state 0 via SSL -1-1 1065989 TUNNEL Wujie/UltraSurf login via SSL -1 1066004 SOCIAL Facebook access via TCP -4 1066057 IM Alicall login via TCP -4 1066058 IM Alicall access via TCP -1 1066059 IM Alicall access via TCP -2 1066068 MEDIA TudouVa communicate via TCP -3 1066082 MEDIA 56.com login via TCP -1 1066083 MEDIA 56.com transfer-upload via TCP -1 1066095 MEDIA Sohu TV access via TCP -3 1066096 MEDIA Sohu TV access via TCP -4 1066100 MEDIA Sohu TV access via TCP -2.2 1066101 MEDIA Sohu TV access via TCP -6 1066147 MEDIA iQIYI/PPS transfer-upload via TCP -1 1066148 MEDIA iQIYI/PPS transfer-upload via TCP -2 1066172 MEDIA PPTV transfer-download via UDP -1 1066173 MEDIA PPTV transfer-download via TCP -1 1066180 MEDIA Qvod access via TCP -1 1066181 MEDIA Qvod access via TCP -2 1066186 MEDIA KKBox media via TCP -1 1066187 MEDIA KKBox media via TCP -2 1066188 MEDIA KKBox access via TCP -1 1066189 MEDIA KKBox access via TCP -2 1066219 MEDIA iTunes/App Store media via TCP -5 1066220 MEDIA iTunes/App Store media via TCP -6 1066221 MEDIA iTunes/App Store media via TCP -7 1066232 P2P Thunder access via TCP -5 1066233 MEDIA KKBox media via TCP -3 1066297 SOCIAL Facebook access via TCP -5 1066382 TERMINAL TeamViewer access via SSL -1 1066383 TERMINAL TeamViewer access via TCP -1 1066384 TERMINAL TeamViewer access via UDP -1 1066385 TERMINAL TeamViewer access via TCP -2 1066386 TERMINAL TeamViewer communicate via TCP -4 1066387 TERMINAL TeamViewer communicate via TCP -5 1066499 MEDIA BaiduMusic access via TCP -3 1066500 MEDIA BaiduMusic access via TCP -4 1066525 CA AOL Authentication via SSL -3 1066526 MEDIA RealPlayer login via SSL -1 1066527 MEDIA RealPlayer access via TCP -1 1066582 MEDIA iTunes/App Store transfer-download via TCP -1 1066583 MEDIA iTunes/App Store transfer-download via TCP -2 1066804 TUNNEL Wujie/UltraSurf login state 0 via SSL -1-2 1066890 MEDIA Letv access via TCP -2 1066891 MEDIA Letv media via TCP -4 1066900 MEDIA Sohu TV access via TCP -8 1067175 FILE Dropbox access via TCP -2 1067176 FILE GetRight transfer via TCP -1 1067261 TUNNEL Wujie/UltraSurf login state 0 via SSL -1-3 1067262 TUNNEL Wujie/UltraSurf login state 0 via SSL -1-4 1067346 MEDIA Qvod login via TCP -1 1067436 TUNNEL VNN Client login via TCP -3 1067442 MEDIA KKBox login via SSL -2 1067691 FILE Dropbox login via SSL -2 1067733 TUNNEL Wujie/UltraSurf login via SSL -3 1067737 TERMINAL pcAnywhere access via TCP -2 1067739 TERMINAL Chrome Remote Desktop access via UDP -1 1067787 SOCIAL Twitter access via TCP -3 1067789 SOCIAL Twitter access via TCP -2 1067860 MEDIA iTunes/App Store access via TCP -2 1067888 MEDIA iTunes/App Store transfer-download via TCP -3 1067889 MEDIA iTunes/App Store transfer-download via TCP -4 1067890 MEDIA iTunes/App Store transfer-download via TCP -5 1067894 SOCIAL Facebook access via TCP -6 1067953 IM AIM/ICQ/iIM access via SSL -1 1067954 IM AIM/ICQ/iIM media via TCP -2 1067955 IM AIM/ICQ/iIM transfer via TCP -9 1068011 MEDIA PPTV media via TCP -19 1068012 MEDIA PPTV transfer-download via TCP -3 1068054 MEDIA iQIYI/PPS transfer-upload via TCP -3 1068055 MEDIA iQIYI/PPS transfer-upload via TCP -4 1068074 TERMINAL ShowMyPC access via TCP -2 1068075 TERMINAL ShowMyPC access via UDP -1 1068076 TERMINAL ShowMyPC access via SSL -1 1068077 TERMINAL ShowMyPC access via TCP -1 1068089 TERMINAL ISL Online login via TCP -1 1068090 TERMINAL ISL Online access via SSL -1 1068091 TERMINAL ISL Online access via TCP -1 1068114 CA Microsoft Authentication via SSL -6 1068115 CA Microsoft Authentication via SSL -7 1068247 MEDIA PPTV media via TCP -20 1068248 MEDIA PPTV media via TCP -21 1068250 MEDIA PPTV media via TCP -22 1068318 MEDIA Grooveshark access via TCP -2 1068431 MEDIA Letv access via TCP -3 1068568 IM AIM/ICQ/iIM access via SSL -2 1068569 IM AIM/ICQ/iIM access via SSL -3 1068601 MEDIA Letv access via TCP -4 1068985 MEDIA Sohu TV media via TCP -9 1069534 IM IPMSG access via TCP -1 1135173 WEB ACME mini_httpd Arbitrary File Read -1 (CVE-2018-18778) 1135965 WEB CentOS Web Panel Authenticated OS Command Injection -1.2 (CVE-2018-18322) 1160094 TERMINAL GoToMyPC login via SSL -2 1160095 TERMINAL GoToMyPC access via SSL -1 1160512 WEB Evernote access via SSL -2 1160517 VOIP LINE access via SSL -9 1160742 IM WhatsApp access via SSL -2 1161028 CA Google Static Content via SSL -1 1161557 MAIL NETEASE login via SSL -4 1161623 VOIP Skype access via DNS -1 1162234 VOIP Facetime access via SSL -1 Deleted 0 rule(s): ---------------