Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dec0der
New Contributor

backdoor: China.Chopper.Webshell.Client.Connection (Inquiry)

Hello,

 

Our fortinet product detected the following:   backdoor: China.Chopper.Webshell.Client.Connection

 

I'd like to know how fortinet interprets this alert. Does this mean Webshell traffic was/is detected and confirmed to be happening on the system, or is this just an alert that lets us know when "attempted" Webshell exploit activity is detected?

 

Thanks in Advance!

1 REPLY 1
localhost
Contributor III

Signature default is blocking for China Chopper.

So if you didn't manually overwrite the action, it got blocked:

 

 

 

The action should also be visible in your IPS Log on your Fortigate. Example from FortiAnalyzer:

 

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors