Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] Sourcefire VRT Certified Snort Rules Update |
|---|---|
| Date: | Tue, 10 Jul 2007 22:05:58 -0400 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Sourcefire VRT Certified Snort Rules Update Synopsis: The Sourcefire VRT is aware of vulnerabilities affecting hosts using Microsoft IIS, Microsoft Windows Firewall and the Microsoft .NET Framework. Details: Microsoft Security Bulletin MS07-041: Microsoft Internet Information Services (IIS) contains a programming error that may allow an attacker to execute code on a vulnerable system. The problem occurs in the processing of URLs, in that a malformed request may cause a null pointer dereference and present the attacker with the opportunity to execute code in the context of the user running the service. A rule to detect attacks targeting this vulnerability is included in this release and is identified as SID 12064. Microsoft Security Bulletin MS07-040: The Microsoft .NET Framework suffers from a vulnerability that may allow a remote attacker to compromise a host using the Framework. A previously released rule will detect attacks targeting this vulnerability and is identified as SID 11192. Microsoft Security Bulletin MS07-038: The Microsoft Windows Firewall fails to correctly handle IPv6 packets when tunnelled over UDP to traverse an IPv4 Network Address Translation. This may allow an attacker to initiate network communications with a host and bypass any Microsoft Windows based firewalls in the process. Rules to detect attacks targeting this vulnerability are included in this release and are identified as SIDs 12065 through 12068. Additionally, SID 8446 may also generate events on IPv6 traffic encapsulated in IPv4. For a complete list of new and modified rules please see: http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2007-07-10.html -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (Cygwin) iD8DBQFGlBWfoFlcG+k7cPwRAuQXAKDF9xA4475VZNriHV5rZmmnb2r8ggCgs1eR xVKzcDc3UkqAcbknWt0AT08= =HvvU -----END PGP SIGNATURE----- ------------------------------------------------------------------------- This SF.net email is sponsored by DB2 Express Download DB2 Express C - the FREE version of DB2 express and take control of your XML. No limits. Just data. Click to get it now. http://sourceforge.net/powerbar/db2/ _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] Bleeding Edge Threats Daily Signature Changes, bleeding |
|---|---|
| Next by Date: | [Snort-sigs] Unsubscribe, Smith, Jeff |
| Previous by Thread: | [Snort-sigs] Sourcefire VRT Certified Snort Rules Update, research |
| Next by Thread: | [Snort-sigs] Sourcefire VRT Certified Snort Rules Update, research |
| Indexes: | [Date] [Thread] [Top] [All Lists] |