Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

[Snort-sigs] VRT Certified Rule Update

Subject: [Snort-sigs] VRT Certified Rule Update
Date: Wed, 20 Apr 2005 18:39:07 -0400
VRT Certified Rule Update

Synopsis:
The Sourcefire VRT has received reliable reports that a worm is being developed that propagates using a vulnerability announced in the Microsoft Security Bulletin (MS05-021) released on Tuesday April 12 2005. The VRT has released a new rule to detect
possible attempts to exploit this vulnerability, which is associated with an extended verb request in Microsoft Exchange servers.


Details:
Microsoft Exchange Servers are able to use extensions to the SMTP
protocol to help communicate between Exchange servers. The
"X-Link2State" verb is used to share routing information between
Exchange servers.

A buffer overflow condition in the processing of this command may
present an attacker with the opportunity to execute code of their
choosing on an affected host.

A rule to detect attacks against this vulnerability is included in this
rule pack and is identified as sid 3627.

WARNING: This rule will generate false positive events on normal traffic
between Exchange servers. If these extensions are implemented in a
network where Exchange servers are used, administrators should configure
this rule as appropriate for their environment.

References:

Microsoft Security Bulletin MS05-019
http://www.microsoft.com/technet/security/Bulletin/ms05-021.mspx



-------------------------------------------------------
This SF.Net email is sponsored by: New Crystal Reports XI.
Version 11 adds new functionality designed to reduce time involved in
creating, integrating, and deploying reporting solutions. Free runtime info,
new features, or free trial, at: http://www.businessobjects.com/devxi/728
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs

<Prev in Thread] Current Thread [Next in Thread>