Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] Sourcefire VRT Certified Rules Update |
|---|---|
| Date: | Thu, 21 Sep 2006 16:32:59 -0400 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Sourcefire VRT Certified Rules Update Synopsis: The Sourcefire VRT has learned of a vulnerabilities in Microsoft Windows systems that may present an attacker with the opportunity to execute code of their choosing on affected systems. Details: Microsoft Security Advisory (925568) Microsoft Internet Explorer suffers from a buffer overflow condition that may allow an attacker to execute code of their choosing on an affected host. The condition is manifest when processing pages using Vector Markup Language. This vulnerability is being used as an attack vector for the Trojan Horse program Trojan.Vimalov. A rule to detect attacks targeting this vulnerability is included in this rule pack and is identified as sid 8416. Microsoft Security Bulletin MS06-039 Microsoft Office programs are prone to a buffer overflow condition when processing malformed GIF images. This may present an attacker with the opportunity to execute code of their choosing on an affected host. A rule to detect attacks targeting this vulnerability is included in this rule pack and is identified as sid 8414. New rules: 8352 <-> Disabled <-> SPYWARE-PUT Adware desktopmedia runtime detection - - ads popup (spyware-put.rules) 8353 <-> Disabled <-> SPYWARE-PUT Adware desktopmedia runtime detection - - auto update (spyware-put.rules) 8354 <-> Disabled <-> SPYWARE-PUT Adware desktopmedia runtime detection - - surf monitoring (spyware-put.rules) 8355 <-> Disabled <-> SPYWARE-PUT Keylogger spybuddy 3.72 runtime detection (spyware-put.rules) 8356 <-> Disabled <-> SPYWARE-PUT Keylogger spybuddy 3.72 runtime detection - send log out through email (spyware-put.rules) 8357 <-> Disabled <-> SPYWARE-PUT Keylogger spybuddy 3.72 runtime detection - send alert out through email (spyware-put.rules) 8358 <-> Disabled <-> SPYWARE-PUT Hijacker yok supersearch runtime detection - addressbar keyword search hijack (spyware-put.rules) 8359 <-> Disabled <-> SPYWARE-PUT Hijacker yok supersearch runtime detection - target website display (spyware-put.rules) 8360 <-> Disabled <-> SPYWARE-PUT Hijacker yok supersearch runtime detection - search info collect (spyware-put.rules) 8361 <-> Disabled <-> BACKDOOR black curse 4.0 runtime detection - inverse init connection (backdoor.rules) 8362 <-> Disabled <-> BACKDOOR black curse 4.0 runtime detection - normal init connection (backdoor.rules) 8363 <-> Enabled <-> WEB-CLIENT Business Object Factory ActiveX CLSID access (web-client.rules) 8364 <-> Enabled <-> WEB-CLIENT Business Object Factory ActiveX CLSID unicode access (web-client.rules) 8365 <-> Enabled <-> WEB-CLIENT DExplore.AppObj.8.0 ActiveX CLSID access (web-client.rules) 8366 <-> Enabled <-> WEB-CLIENT DExplore.AppObj.8.0 ActiveX CLSID unicode access (web-client.rules) 8367 <-> Enabled <-> WEB-CLIENT Microsoft.DbgClr.DTE.8.0 ActiveX CLSID access (web-client.rules) 8368 <-> Enabled <-> WEB-CLIENT Microsoft.DbgClr.DTE.8.0 ActiveX CLSID unicode access (web-client.rules) 8369 <-> Enabled <-> WEB-CLIENT WMIScriptUtils.WMIObjectBroker2.1 ActiveX CLSID access (web-client.rules) 8370 <-> Enabled <-> WEB-CLIENT WMIScriptUtils.WMIObjectBroker2.1 ActiveX CLSID unicode access (web-client.rules) 8371 <-> Enabled <-> WEB-CLIENT Outlook.Application ActiveX CLSID access (web-client.rules) 8372 <-> Enabled <-> WEB-CLIENT Outlook.Application ActiveX CLSID unicode access (web-client.rules) 8373 <-> Enabled <-> WEB-CLIENT VsmIDE.DTE ActiveX CLSID access (web-client.rules) 8374 <-> Enabled <-> WEB-CLIENT VsmIDE.DTE ActiveX CLSID unicode access (web-client.rules) 8375 <-> Enabled <-> WEB-CLIENT QuickTime Object ActiveX CLSID access (web-client.rules) 8376 <-> Enabled <-> WEB-CLIENT QuickTime Object ActiveX CLSID unicode access (web-client.rules) 8377 <-> Enabled <-> WEB-CLIENT RealPlayer Download Handler ActiveX CLSID access (web-client.rules) 8378 <-> Enabled <-> WEB-CLIENT RealPlayer Download Handler ActiveX CLSID unicode access (web-client.rules) 8379 <-> Enabled <-> WEB-CLIENT Xml2Dex ActiveX CLSID access (web-client.rules) 8380 <-> Enabled <-> WEB-CLIENT Xml2Dex ActiveX CLSID unicode access (web-client.rules) 8381 <-> Enabled <-> WEB-CLIENT RealPlayer SMIL Download Handler ActiveX CLSID access (web-client.rules) 8382 <-> Enabled <-> WEB-CLIENT RealPlayer SMIL Download Handler ActiveX CLSID unicode access (web-client.rules) 8383 <-> Enabled <-> WEB-CLIENT RealPlayer RAM Download Handler ActiveX CLSID access (web-client.rules) 8384 <-> Enabled <-> WEB-CLIENT RealPlayer RAM Download Handler ActiveX CLSID unicode access (web-client.rules) 8385 <-> Enabled <-> WEB-CLIENT RealPlayer Playback Handler ActiveX CLSID access (web-client.rules) 8386 <-> Enabled <-> WEB-CLIENT RealPlayer Playback Handler ActiveX CLSID unicode access (web-client.rules) 8387 <-> Enabled <-> WEB-CLIENT RealPlayer RNX Download Handler ActiveX CLSID access (web-client.rules) 8388 <-> Enabled <-> WEB-CLIENT RealPlayer RNX Download Handler ActiveX CLSID unicode access (web-client.rules) 8389 <-> Enabled <-> WEB-CLIENT RealPlayer RMP Download Handler ActiveX CLSID access (web-client.rules) 8390 <-> Enabled <-> WEB-CLIENT RealPlayer RMP Download Handler ActiveX CLSID unicode access (web-client.rules) 8391 <-> Enabled <-> WEB-CLIENT RFXInstMgr Class ActiveX CLSID access (web-client.rules) 8392 <-> Enabled <-> WEB-CLIENT RFXInstMgr Class ActiveX CLSID unicode access (web-client.rules) 8393 <-> Enabled <-> WEB-CLIENT WebDetectFrm ActiveX CLSID access (web-client.rules) 8394 <-> Enabled <-> WEB-CLIENT WebDetectFrm ActiveX CLSID unicode access (web-client.rules) 8395 <-> Enabled <-> WEB-CLIENT DX3DTransform.Microsoft.CrShatter ActiveX CLSID access (web-client.rules) 8396 <-> Enabled <-> WEB-CLIENT DX3DTransform.Microsoft.CrShatter ActiveX CLSID unicode access (web-client.rules) 8397 <-> Enabled <-> WEB-CLIENT Microsoft Office List 11.0 ActiveX CLSID access (web-client.rules) 8398 <-> Enabled <-> WEB-CLIENT Microsoft Office List 11.0 ActiveX CLSID unicode access (web-client.rules) 8399 <-> Enabled <-> WEB-CLIENT Microsoft.WebCapture ActiveX CLSID access (web-client.rules) 8400 <-> Enabled <-> WEB-CLIENT Microsoft.WebCapture ActiveX CLSID unicode access (web-client.rules) 8401 <-> Enabled <-> WEB-CLIENT Windows Media Services DRM Storage ActiveX CLSID access (web-client.rules) 8402 <-> Enabled <-> WEB-CLIENT Windows Media Services DRM Storage ActiveX CLSID unicode access (web-client.rules) 8403 <-> Enabled <-> WEB-CLIENT XML Schmea Cache 6.0 ActiveX CLSID access (web-client.rules) 8404 <-> Enabled <-> WEB-CLIENT XML Schmea Cache 6.0 ActiveX CLSID unicode access (web-client.rules) 8405 <-> Enabled <-> WEB-CLIENT XML HTTP 6.0 ActiveX CLSID access (web-client.rules) 8406 <-> Enabled <-> WEB-CLIENT XML HTTP 6.0 ActiveX CLSID unicode access (web-client.rules) 8407 <-> Enabled <-> WEB-CLIENT VisualExec Control ActiveX CLSID access (web-client.rules) 8408 <-> Enabled <-> WEB-CLIENT VisualExec Control ActiveX CLSID unicode access (web-client.rules) 8409 <-> Enabled <-> WEB-CLIENT RealPlayer Stream Handler ActiveX CLSID access (web-client.rules) 8410 <-> Enabled <-> WEB-CLIENT RealPlayer Stream Handler ActiveX CLSID unicode access (web-client.rules) 8411 <-> Enabled <-> WEB-CLIENT DocFind Command ActiveX CLSID access (web-client.rules) 8412 <-> Enabled <-> WEB-CLIENT DocFind Command ActiveX CLSID unicode access (web-client.rules) 8413 <-> Disabled <-> WEB-CLIENT HCP URI uplddrvinfo access (web-client.rules) 8414 <-> Disabled <-> WEB-CLIENT GIF image width descriptor buffer overflow attempt (web-client.rules) 8415 <-> Enabled <-> FTP SIZE overflow attempt (ftp.rules) 8416 <-> Enabled <-> WEB-CLIENT VML fill method overflow attempt (web-client.rules) Updated rules: 7842 <-> Disabled <-> SPYWARE-PUT Hacker-Tool davps runtime detection (spyware-put.rules) -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (Darwin) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFFEvb7Mpm0ve0NhMcRAt71AJ94UpbcgEo3EoW4Ny6yIPzOUhMkBQCdGifE 0Up49vB4tVmKN/pMn8x7DRs= =aRMi -----END PGP SIGNATURE----- ------------------------------------------------------------------------- Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys -- and earn cash http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] Bleedingsnort.com Daily Update, bleeding |
|---|---|
| Next by Date: | [Snort-sigs] Thank you Sourcefire, Ureleet Ureleet |
| Previous by Thread: | [Snort-sigs] Sourcefire VRT Certified Rules Update, Sourcefire VRT |
| Next by Thread: | [Snort-sigs] two new rules for detect Webmin/Usermin null char, rmkml |
| Indexes: | [Date] [Thread] [Top] [All Lists] |