Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

[Snort-sigs] Unsubscribe

Subject: [Snort-sigs] Unsubscribe
Date: Tue, 10 Jul 2007 23:07:07 -0500
Unsubscribe

Jeff Smith

 -----Original Message-----
From:   research@sourcefire.com [mailto:research@sourcefire.com]
Sent:   Tuesday, July 10, 2007 10:52 PM Central Standard Time
To:     snort-sigs@lists.sourceforge.net
Subject:        [Snort-sigs] Sourcefire VRT Certified Snort Rules Update

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Sourcefire VRT Certified Snort Rules Update

Synopsis:
The Sourcefire VRT is aware of vulnerabilities affecting hosts using Microsoft 
IIS, Microsoft Windows Firewall and the Microsoft .NET Framework.

Details:
Microsoft Security Bulletin MS07-041:
Microsoft Internet Information Services (IIS) contains a programming error that 
may allow an attacker to execute code on a vulnerable system.  The problem 
occurs in the processing of URLs, in that a malformed request may cause a null 
pointer dereference and present the attacker with the opportunity to execute 
code in the context of the user running the service.

A rule to detect attacks targeting this vulnerability is included in this 
release and is identified as SID 12064.

Microsoft Security Bulletin MS07-040:
The Microsoft .NET Framework suffers from a vulnerability that may allow a 
remote attacker to compromise a host using the Framework.

A previously released rule will detect attacks targeting this vulnerability and 
is identified as SID 11192.

Microsoft Security Bulletin MS07-038:
The Microsoft Windows Firewall fails to correctly handle IPv6 packets when 
tunnelled over UDP to traverse an IPv4 Network Address Translation. This may 
allow an attacker to initiate network communications with a host and bypass any 
Microsoft Windows based firewalls in the process.

Rules to detect attacks targeting this vulnerability are included in this 
release and are identified as SIDs 12065 through 12068.

Additionally, SID 8446 may also generate events on IPv6 traffic encapsulated in 
IPv4.

For a complete list of new and modified rules please see:

http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2007-07-10.html

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Cygwin)

iD8DBQFGlBWfoFlcG+k7cPwRAuQXAKDF9xA4475VZNriHV5rZmmnb2r8ggCgs1eR
xVKzcDc3UkqAcbknWt0AT08=
=HvvU
-----END PGP SIGNATURE-----


-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
<Prev in Thread] Current Thread [Next in Thread>