Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] Sourcefire VRT Certified Rules Update |
|---|---|
| Date: | Wed, 29 Mar 2006 19:08:28 -0500 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
Sourcefire VRT Certified Rules Update
Synopsis: The Sourcefire VRT has learned of vulnerabilities affecting hosts using Sendmail and has identified additional attack vectors for vulnerabilities affecting Microsoft HTML Help Workshop.
Details: A race condition exists in versions of Sendmail, this vulnerability may allow a remote attacker to execute code of their choosing on an affected server. A programming error in the way that Sendmail handles asynchronous signals may allow an attacker to overflow a fixed length buffer by supplying a large amount of data in an email header.
A rule to detect attacks targeting this vulnerability is included in this update and is identified as sid 5739.
HTML Help Workshop fails to properly validate file contents before reading and putting information into a fixed length buffer. A malicious file may contain information that could overflow the buffer and execute code on the affected system.
Rules to detect attacks targeting this vulnerability are included in this update and are identified as sids 5740 and 5741.
New rules: 5739 - SMTP headers too long server response (smtp.rules) 5740 - WEB-CLIENT Microsoft HTML help workshop file .hhp download attempt (web-client.rules) 5741 - WEB-CLIENT Microsoft HTML help workshop buffer overflow attempt (web-client.rules)
Updated rules: 5727 - NETBIOS SMB-DS Trans Max Param DOS attempt (netbios.rules) 5728 - NETBIOS SMB-DS Trans unicode Max Param DOS attempt (netbios.rules) 5729 - NETBIOS SMB Trans unicode Max Param DOS attempt (netbios.rules) 5730 - NETBIOS SMB Trans Max Param DOS attempt (netbios.rules) 5731 - NETBIOS-DG SMB Trans Max Param DOS attempt (netbios.rules) 5732 - NETBIOS-DG SMB Trans unicode Max Param DOS attempt (netbios.rules) 5733 - NETBIOS SMB-DS Trans andx Max Param DOS attempt (netbios.rules) 5734 - NETBIOS SMB-DS Trans unicode andx Max Param DOS attempt (netbios.rules) 5735 - NETBIOS SMB Trans unicode andx Max Param DOS attempt (netbios.rules) 5736 - NETBIOS SMB Trans andx Max Param DOS attempt (netbios.rules) 5737 - NETBIOS-DG SMB Trans andx Max Param DOS attempt (netbios.rules) 5738 - NETBIOS-DG SMB Trans unicode andx Max Param DOS attempt (netbios.rules) -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (Darwin) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFEKyF8Mpm0ve0NhMcRAm74AJ4hXR76gW0yTcLDsduq1WknUKWyngCfW5hc J5IVEAkZN4u+tRa1wJVssbs= =xBC6 -----END PGP SIGNATURE-----
------------------------------------------------------- This SF.Net email is sponsored by xPML, a groundbreaking scripting language that extends applications into web and mobile media. Attend the live webcast and join the prime developer group breaking into this new coding territory! http://sel.as-us.falkag.net/sel?cmd=lnk&kid=110944&bid=241720&dat=121642 _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] IE Vulnerability Analysis and Detection, Sourcefire VRT |
|---|---|
| Next by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
| Previous by Thread: | [Snort-sigs] Sourcefire VRT Certified Rules Update, Sourcefire VRT |
| Next by Thread: | [Snort-sigs] Snort 2.4.4 and Snort 2.6 Beta Available, Jennifer Steffens |
| Indexes: | [Date] [Thread] [Top] [All Lists] |