Lion Worm
select * from file where path in ('/dev/.lib', '/dev/.lib/1iOn.sh', '/bin/mjy', '/bin/in.telnetd', '/usr/info/torn');View Full Query Detailsselect * from file where path in ('/dev/.lib', '/dev/.lib/1iOn.sh', '/bin/mjy', '/bin/in.telnetd', '/usr/info/torn');View Full Query Detailsselect * from listening_ports;View Full Query Details
select * from file where path in ('/tmp/xp', '/tmp/kidd0.c', '/tmp/kidd0');View Full Query Detailsselect liu.*, p.name, p.cmdline, p.cwd, p.root from logged_in_users liu, processes p where liu.pid = p.pid;View Full Query Details
select key, subkey, value from plist where path = '/Library/Preferences/com.apple.loginwindow.plist';View Full Query Details
select key, subkey, value from plist where path = '/Library/Preferences/loginwindow.plist';View Full Query Details
select username, key, subkey, value from plist p, (select * from users where directory like '/Users/%') u where p.path = u.directory || '/Library/Preferences/com.apple.loginwindow.plist';View Full Query Details
select username, key, subkey, value from plist p, (select * from users where directory like '/Users/%') u where p.path = u.directory || '/Library/Preferences/loginwindow.plist';View Full Query Details
select * from file where path in ('/dev/ida/.inet');View Full Query DetailsSELECT * FROM processes WHERE LOWER(name)='lsass.exe' AND LOWER(path)!='c:\windows\system32\lsass.exe' AND path!='';View Full Query Details