Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] Sourcefire VRT Certified Rules Update |
|---|---|
| Date: | Fri, 30 Dec 2005 19:12:25 -0500 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
Sourcefire VRT Certified Rules Update
Synopsis: The Sourcefire Vulnerability Research Team (VRT) has learned of multiple vulnerabilities affecting hosts using the Microsoft operating system. The VRT has also learned of a new Sober worm variant that displays uniquely detectable infection characteristics.
Details: The Microsoft Windows graphics rendering engine does not correctly parse windows metafile (wmf) format files. As a result, viewing a corrupted file may present an attacker with the opportunity to execute code of their choosing.
The Sourcefire VRT has confirmed that a rule identified as sid 2436, released on May 21, 2004, will generate events when an attempt is made to exploit this vulnerability. Also, rules to detect attacks targeting this vulnerability are included in this update and are identified as sids 5318 and 5319.
Note: Due to the possibility of a high false positive rate, sid 5318 is not enabled by default.
WARNING To reduce the possibility of evasion, http_inspect needs to be configured with "flow_depth 0" so that it can inspect all the traffic from HTTP server responses. Setting flow_depth 0 will cause performance problems in some situations.
The Sober worm is a mass mailer normally spread via email. A variant of this worm displays more infection indicators that can be detected easily using rules.
Rules to detect machines infected with this variant of the sober worm are included in this update and are identified as sids 5321 through 5323.
Additionally, Sourcefire RNA customers can utilize the capabilities of their RNA applicance to detect infections, instructions can be found on the Sourcefire Customer Support Site.
New rules: 4982 - WEB-CLIENT Adodb.Stream ActiveX Object Access (web-client.rules) 4983 - WEB-CLIENT Adodb.Stream ActiveX Object Access CreateObject Function (web-client.rules) 4984 - MS-SQL/SMB sa brute force failed login unicode attempt (sql.rules) 4985 - WEB-MISC Twiki rdiff rev command injection attempt (web-misc.rules) 4986 - WEB-MISC Twiki view rev command injection attempt (web-misc.rules) 4987 - WEB-MISC Twiki viewfile rev command injection attempt (web-misc.rules) 4988 - WEB-MISC Barracuda IMG.PL directory traversal attempt (web-misc.rules) 4989 - MS-SQL Heap-Based Overflow Attempt (sql.rules) 4990 - MS-SQL Heap-Based Overflow Attempt (sql.rules) 4991 - NETBIOS SMB lsass unicode alter context attempt (netbios.rules) 4992 - NETBIOS SMB lsass WriteAndX unicode alter context attempt (netbios.rules) 4993 - NETBIOS SMB lsass unicode bind attempt (netbios.rules) 4994 - NETBIOS SMB lsass WriteAndX unicode bind attempt (netbios.rules) 4995 - NETBIOS SMB-DS lsass bind attempt (netbios.rules) 4996 - NETBIOS SMB-DS lsass WriteAndX bind attempt (netbios.rules) 4997 - NETBIOS SMB-DS lsass unicode bind attempt (netbios.rules) 4998 - NETBIOS SMB-DS lsass WriteAndX unicode bind attempt (netbios.rules) 4999 - NETBIOS-DG SMB lsass bind attempt (netbios.rules) 5000 - NETBIOS-DG SMB lsass WriteAndX bind attempt (netbios.rules) 5001 - NETBIOS-DG SMB lsass unicode bind attempt (netbios.rules) 5002 - NETBIOS-DG SMB lsass WriteAndX unicode bind attempt (netbios.rules) 5003 - NETBIOS SMB lsass little endian bind attempt (netbios.rules) 5004 - NETBIOS SMB lsass WriteAndX little endian bind attempt (netbios.rules) 5005 - NETBIOS SMB-DS lsass alter context attempt (netbios.rules) 5006 - NETBIOS-DG SMB lsass WriteAndX unicode alter context attempt (netbios.rules) 5007 - NETBIOS SMB lsass little endian alter context attempt (netbios.rules) 5008 - NETBIOS SMB lsass WriteAndX little endian alter context attempt (netbios.rules) 5009 - NETBIOS SMB lsass unicode little endian alter context attempt (netbios.rules) 5010 - NETBIOS SMB lsass WriteAndX unicode little endian alter context attempt (netbios.rules) 5011 - NETBIOS SMB-DS lsass little endian alter context attempt (netbios.rules) 5012 - NETBIOS SMB-DS lsass WriteAndX little endian alter context attempt (netbios.rules) 5013 - NETBIOS SMB-DS lsass unicode little endian alter context attempt (netbios.rules) 5014 - NETBIOS SMB-DS lsass WriteAndX unicode little endian alter context attempt (netbios.rules) 5015 - NETBIOS-DG SMB lsass little endian alter context attempt (netbios.rules) 5016 - NETBIOS-DG SMB lsass WriteAndX little endian alter context attempt (netbios.rules) 5017 - NETBIOS-DG SMB lsass unicode little endian alter context attempt (netbios.rules) 5018 - NETBIOS-DG SMB lsass WriteAndX unicode little endian alter context attempt (netbios.rules) 5019 - NETBIOS SMB lsass bind attempt (netbios.rules) 5020 - NETBIOS SMB lsass WriteAndX bind attempt (netbios.rules) 5021 - NETBIOS SMB lsass unicode little endian bind attempt (netbios.rules) 5022 - NETBIOS SMB lsass WriteAndX unicode little endian bind attempt (netbios.rules) 5023 - NETBIOS SMB-DS lsass little endian bind attempt (netbios.rules) 5024 - NETBIOS SMB-DS lsass WriteAndX little endian bind attempt (netbios.rules) 5025 - NETBIOS SMB-DS lsass unicode little endian bind attempt (netbios.rules) 5026 - NETBIOS SMB-DS lsass WriteAndX unicode little endian bind attempt (netbios.rules) 5027 - NETBIOS-DG SMB lsass little endian bind attempt (netbios.rules) 5028 - NETBIOS-DG SMB lsass WriteAndX little endian bind attempt (netbios.rules) 5029 - NETBIOS-DG SMB lsass unicode little endian bind attempt (netbios.rules) 5030 - NETBIOS-DG SMB lsass WriteAndX unicode little endian bind attempt (netbios.rules) 5031 - NETBIOS SMB lsass andx alter context attempt (netbios.rules) 5032 - NETBIOS SMB-DS lsass WriteAndX andx alter context attempt (netbios.rules) 5033 - NETBIOS SMB-DS lsass unicode andx alter context attempt (netbios.rules) 5034 - NETBIOS SMB lsass WriteAndX andx alter context attempt (netbios.rules) 5035 - NETBIOS SMB-DS lsass WriteAndX unicode andx alter context attempt (netbios.rules) 5036 - NETBIOS-DG SMB lsass andx alter context attempt (netbios.rules) 5037 - NETBIOS-DG SMB lsass WriteAndX andx alter context attempt (netbios.rules) 5038 - NETBIOS-DG SMB lsass unicode andx alter context attempt (netbios.rules) 5039 - NETBIOS SMB lsass unicode andx alter context attempt (netbios.rules) 5040 - NETBIOS SMB lsass WriteAndX unicode andx alter context attempt (netbios.rules) 5041 - NETBIOS SMB lsass unicode andx bind attempt (netbios.rules) 5042 - NETBIOS SMB lsass WriteAndX unicode andx bind attempt (netbios.rules) 5043 - NETBIOS SMB-DS lsass andx bind attempt (netbios.rules) 5044 - NETBIOS SMB-DS lsass WriteAndX andx bind attempt (netbios.rules) 5045 - NETBIOS SMB-DS lsass unicode andx bind attempt (netbios.rules) 5046 - NETBIOS SMB-DS lsass WriteAndX unicode andx bind attempt (netbios.rules) 5047 - NETBIOS-DG SMB lsass andx bind attempt (netbios.rules) 5048 - NETBIOS-DG SMB lsass WriteAndX andx bind attempt (netbios.rules) 5049 - NETBIOS-DG SMB lsass unicode andx bind attempt (netbios.rules) 5050 - NETBIOS-DG SMB lsass WriteAndX unicode andx bind attempt (netbios.rules) 5051 - NETBIOS SMB lsass little endian andx bind attempt (netbios.rules) 5052 - NETBIOS SMB lsass WriteAndX little endian andx bind attempt (netbios.rules) 5053 - NETBIOS SMB-DS lsass andx alter context attempt (netbios.rules) 5054 - NETBIOS-DG SMB lsass WriteAndX unicode andx alter context attempt (netbios.rules) 5055 - NETBIOS SMB lsass little endian andx alter context attempt (netbios.rules) 5056 - NETBIOS SMB lsass WriteAndX little endian andx alter context attempt (netbios.rules) 5057 - NETBIOS SMB lsass unicode little endian andx alter context attempt (netbios.rules) 5058 - NETBIOS SMB lsass WriteAndX unicode little endian andx alter context attempt (netbios.rules) 5059 - NETBIOS SMB-DS lsass little endian andx alter context attempt (netbios.rules) 5060 - NETBIOS SMB-DS lsass WriteAndX little endian andx alter context attempt (netbios.rules) 5061 - NETBIOS SMB-DS lsass unicode little endian andx alter context attempt (netbios.rules) 5062 - NETBIOS SMB-DS lsass WriteAndX unicode little endian andx alter context attempt (netbios.rules) 5063 - NETBIOS-DG SMB lsass little endian andx alter context attempt (netbios.rules) 5064 - NETBIOS-DG SMB lsass WriteAndX little endian andx alter context attempt (netbios.rules) 5065 - NETBIOS-DG SMB lsass unicode little endian andx alter context attempt (netbios.rules) 5066 - NETBIOS-DG SMB lsass WriteAndX unicode little endian andx alter context attempt (netbios.rules) 5067 - NETBIOS SMB lsass andx bind attempt (netbios.rules) 5068 - NETBIOS SMB lsass WriteAndX andx bind attempt (netbios.rules) 5069 - NETBIOS SMB lsass unicode little endian andx bind attempt (netbios.rules) 5070 - NETBIOS SMB lsass WriteAndX unicode little endian andx bind attempt (netbios.rules) 5071 - NETBIOS SMB-DS lsass little endian andx bind attempt (netbios.rules) (list truncated do to message size) -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (Darwin) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFDtczUMpm0ve0NhMcRAs73AJwJErGwJ5ml/TRYI4sILZU6vVzQLwCdHHT0 pBSJ8DM7W/VnExzKo7mStIw= =BUUv -----END PGP SIGNATURE-----
------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://ads.osdn.com/?ad_id=7637&alloc_id=16865&op=click _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
|---|---|
| Next by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
| Previous by Thread: | [Snort-sigs] Sourcefire VRT Certified Rules Update, Sourcefire VRT |
| Next by Thread: | [Snort-sigs] new rule for detect Symantec Brightmail Antispam default login, rmkml |
| Indexes: | [Date] [Thread] [Top] [All Lists] |