Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

[Snort-sigs] Sourcefire VRT Certified Rules Update

Subject: [Snort-sigs] Sourcefire VRT Certified Rules Update
Date: Wed, 29 Mar 2006 19:08:28 -0500
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Sourcefire VRT Certified Rules Update

Synopsis:
The Sourcefire VRT has learned of vulnerabilities affecting hosts using
Sendmail and has identified additional attack vectors for
vulnerabilities affecting Microsoft HTML Help Workshop.


Details: A race condition exists in versions of Sendmail, this vulnerability may allow a remote attacker to execute code of their choosing on an affected server. A programming error in the way that Sendmail handles asynchronous signals may allow an attacker to overflow a fixed length buffer by supplying a large amount of data in an email header.

A rule to detect attacks targeting this vulnerability is included in
this update and is identified as sid 5739.

HTML Help Workshop fails to properly validate file contents before
reading and putting information into a fixed length buffer. A malicious
file may contain information that could overflow the buffer and execute
code on the affected system.

Rules to detect attacks targeting this vulnerability are included in
this update and are identified as sids 5740 and 5741.



New rules:
5739 - SMTP headers too long server response (smtp.rules)
5740 - WEB-CLIENT Microsoft HTML help workshop file .hhp download
attempt (web-client.rules)
5741 - WEB-CLIENT Microsoft HTML help workshop buffer overflow attempt
(web-client.rules)

Updated rules:
5727 - NETBIOS SMB-DS Trans Max Param DOS attempt (netbios.rules)
5728 - NETBIOS SMB-DS Trans unicode Max Param DOS attempt
(netbios.rules)
5729 - NETBIOS SMB Trans unicode Max Param DOS attempt (netbios.rules)
5730 - NETBIOS SMB Trans Max Param DOS attempt (netbios.rules)
5731 - NETBIOS-DG SMB Trans Max Param DOS attempt (netbios.rules)
5732 - NETBIOS-DG SMB Trans unicode Max Param DOS attempt
(netbios.rules)
5733 - NETBIOS SMB-DS Trans andx Max Param DOS attempt (netbios.rules)
5734 - NETBIOS SMB-DS Trans unicode andx Max Param DOS attempt
(netbios.rules)
5735 - NETBIOS SMB Trans unicode andx Max Param DOS attempt
(netbios.rules)
5736 - NETBIOS SMB Trans andx Max Param DOS attempt (netbios.rules)
5737 - NETBIOS-DG SMB Trans andx Max Param DOS attempt (netbios.rules)
5738 - NETBIOS-DG SMB Trans unicode andx Max Param DOS attempt
(netbios.rules)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (Darwin)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFEKyF8Mpm0ve0NhMcRAm74AJ4hXR76gW0yTcLDsduq1WknUKWyngCfW5hc
J5IVEAkZN4u+tRa1wJVssbs=
=xBC6
-----END PGP SIGNATURE-----


------------------------------------------------------- This SF.Net email is sponsored by xPML, a groundbreaking scripting language that extends applications into web and mobile media. Attend the live webcast and join the prime developer group breaking into this new coding territory! http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642 _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs

<Prev in Thread] Current Thread [Next in Thread>