Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [ISSForum] Content_Compound_Bad_File_Extension tunable? |
|---|---|
| Date: | Tue, 27 Feb 2007 12:08:05 +0300 |
AFAIK, yes, the situation is still the same: no turning params available. This is the only info in pam.chm (KB #2190): =========== Content_Compound_File_Bad_Extension Description This signature triggers when a compound file is found that has an inappropriate file name extension. "Compound file" refers to a specific file format used to store data by a number of Microsoft applications like Excel and Word. Type Attack Priority high Algorithm Id 2106192 Bugtraq References BID-13132 CVE References CVE-2005-0063 Known False Negatives A compound file may have an appropriate file name extension, yet still be a threat to a particular desktop system. If the file name extension is valid, but not recognized because the associated software is not installed, the file still poses a threat. For example, a malicious Microsoft Word document with the expected ".doc" extension is a threat to a system that does not have Microsoft Word installed. Vulnerabilities Exploited Microsoft Windows HTML Application Host command execution =========== --- Best regards, Sergey V. Soldatov. Information security department. tel/fax +7 495 745 89 50 tel +7 495 777 77 07 (1613)
-----Original Message----- From: issforum-bounces@atla-mm1.iss.net [mailto:issforum-bounces@atla-mm1.iss.net] On Behalf Of Johnson, Scott Sent: Thursday, February 22, 2007 8:03 PM To: issforum@iss.net Subject: [ISSForum] Content_Compound_Bad_File_Extension tunable? Last September I inquired with tech support about tuning the signature Content_Compound_Bad_File_Extension. I was told there was no pam or white list for this signature. Is this still the case? Scott Johnson Information Security Electric Reliability Council of Texas www.ercot.com Office: 512-248-3152 Cell: 512-917-9844 _______________________________________________ ISSForum mailing list ISSForum@atla-mm1.iss.net TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum To contact the ISSForum Moderator, send email to mod-issforum@iss.net The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.
_______________________________________________ ISSForum mailing list ISSForum@atla-mm1.iss.net TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum To contact the ISSForum Moderator, send email to mod-issforum@iss.net The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ISSForum] Content_Compound_Bad_File_Extension tunable?, Johnson, Scott |
|---|---|
| Next by Date: | [ISSForum] Cannot get master status on network sensor, Javier Reyna Padilla |
| Previous by Thread: | [ISSForum] Content_Compound_Bad_File_Extension tunable?, Johnson, Scott |
| Next by Thread: | [ISSForum] Cannot get master status on network sensor, Javier Reyna Padilla |
| Indexes: | [Date] [Thread] [Top] [All Lists] |