Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] Sourcefire VRT Certified Rules Update |
|---|---|
| Date: | Wed, 15 Jun 2005 20:47:32 -0400 |
Sourcefire VRT Certified Rules Update
Synopsis: The Sourcefire Vulnerability Research Team (VRT) has learned of serious vulnerabilities affecting various vendor Telnet client software and Microsoft Internet Explorer.
Details: A telnet client and server can negotiate various options such as the character set to be used in the communication exchange. One particular option allows a client or server to send new environment options. Certain telnet clients will respond to a telnet server that issues a new environment send command for a particular environment variable, such as the current user. This information disclosure can be valuable to a potential attacker. Although this vulnerability affects multiple vendors it is also addressed in the Microsoft advisory MS05-033.
Rules to detect attacks against this vulnerability are included in this rule pack and are identifed as sids 3687 and 3688.
Internet Explorer has an optional feature known as Content Advisor that allows unsuitable content to be blocked. The Content Advisor uses a ratings description file to determine what is considered to be unsuitable content. The ratings description file contains several statements including a name statement. An overly long value supplied to a specific name statement can cause a buffer overflow and the subsequent execution of arbitrary code.
A rule to detect attacks against this vulnerbility is included in this rule pack and is identified as sid 3686.
A vulnerability exists in the way Internet Explorer handles the transparency chunk of a PNG file, enabling a buffer overflow and the subsequent execution of arbitrary code on a vulnerable client. This vulnerability is addressed in the Microsoft advisory MS05-025.
------------------------------------------------------- SF.Net email is sponsored by: Discover Easy Linux Migration Strategies from IBM. Find simple to follow Roadmaps, straightforward articles, informative Webcasts and more! Get everything you need to get up to speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] Question about sid:159, Paul Schmehl |
|---|---|
| Next by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
| Previous by Thread: | [Snort-sigs] Question about sid:159, Paul Schmehl |
| Next by Thread: | [Snort-sigs] Snort.conf Samples Project, Matt Jonkman |
| Indexes: | [Date] [Thread] [Top] [All Lists] |