Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] Sourcefire VRT Certified Rules Update |
|---|---|
| Date: | Wed, 29 Jun 2005 15:36:56 -0400 |
Sourcefire VRT Certified Rules Update
A Rule to detect attacks against this vulnerability is included in this rule pack and is identified as sid 3694.
IBM WebSphere may use form-based authentication to permit access to applications. The CGI variables j_username and j_password are used for this authentication process. Overly long values passed to these variables can cause a buffer overflow and the subsequent execution of arbitrary code on the vulnerable server. This is due to a failure in the code to accommodate wide-character expansion for the receiving buffer.
A rule to detect attacks against this vulnerability is included in this rule pack and is identified as sid 3693.
New rules: 3690 - WEB-CGI Nucleus CMS action.php itemid SQL injection (web-cgi.rules) 3691 - CHAT Yahoo Messenger Message (chat.rules) 3692 - CHAT Yahoo Messenger File Transfer Initiation Request (chat.rules) 3693 - WEB-MISC IBM WebSphere j_security_check overflow attempt (web-misc.rules) 3694 - WEB-MISC Squid content length cache poisoning attempt (web-misc.rules)
Updated rules: 272 - DOS IGMP dos attack (dos.rules) 500 - MISC source route lssr (misc.rules) 501 - MISC source route lssre (misc.rules) 658 - SMTP exchange mime DOS (smtp.rules) 661 - SMTP majordomo ifs (smtp.rules) 939 - WEB-FRONTPAGE posting (web-frontpage.rules) 978 - WEB-IIS ASP contents view (web-iis.rules) 979 - WEB-IIS ASP contents view (web-iis.rules) 1007 - WEB-IIS cross-site scripting attempt (web-iis.rules) 1010 - WEB-IIS encoding access (web-iis.rules) 1019 - IIS Malformed Hit-Highlighting Argument File Access Attempt (web-iis.rules) 1021 - WEB-IIS ism.dll attempt (web-iis.rules) 1037 - WEB-IIS showcode.asp access (web-iis.rules) 1219 - WEB-CGI dfire.cgi access (web-cgi.rules) 1455 - WEB-CGI calendar.pl access (web-cgi.rules) 1507 - WEB-CGI alibaba.pl arbitrary command execution attempt (web-cgi.rules) 1725 - WEB-IIS +.htr code fragment attempt (web-iis.rules) 1847 - WEB-MISC webalizer access (web-misc.rules) 1911 - RPC sadmind UDP NETMGT_PROC_SERVICE CLIENT_DOMAIN overflow attempt (rpc.rules) 1936 - POP3 AUTH overflow attempt (pop3.rules) 1970 - WEB-IIS MDAC Content-Type overflow attempt (web-iis.rules) 1991 - CHAT MSN login attempt (chat.rules) 2128 - WEB-CGI swsrv.cgi access (web-cgi.rules) 2338 - FTP LIST buffer overflow attempt (ftp.rules) 2456 - CHAT Yahoo Messenger File Transfer Receive Request (chat.rules) 2485 - WEB-CLIENT Norton antivirus sysmspam.dll load attempt (web-client.rules) 3218 - NETBIOS SMB OpenKey overflow attempt (netbios.rules) 3233 - NETBIOS SMB-DS OpenKey unicode little endian andx overflow attempt (netbios.rules) 3442 - DOS WIN32 TCP print service denial of service attempt (dos.rules) 3687 - TELNET client ENV OPT USERVAR information disclosure (telnet.rules) 3688 - TELNET client ENV OPT VAR information disclosure (telnet.rules)
Cheers, Matthew Watchinski Director, Vulnerability Research Sourcefire, Inc.
------------------------------------------------------- SF.Net email is sponsored by: Discover Easy Linux Migration Strategies from IBM. Find simple to follow Roadmaps, straightforward articles, informative Webcasts and more! Get everything you need to get up to speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Next by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
|---|---|
| Next by Thread: | [Snort-sigs] Sourcefire VRT Certified Rules Update, Matthew Watchinski |
| Indexes: | [Date] [Thread] [Top] [All Lists] |