[Snort-sigs] Sourcefire VRT Certified Rules Update

Sourcefire VRT research at ...435...
Fri Dec 30 16:13:01 EST 2005


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Sourcefire VRT Certified Rules Update

Synopsis:
The Sourcefire Vulnerability Research Team (VRT) has learned of
multiple vulnerabilities affecting hosts using the Microsoft operating
system. The VRT has also learned of a new Sober worm variant that
displays uniquely detectable infection characteristics.


Details:
The Microsoft Windows graphics rendering engine does not correctly
parse windows metafile (wmf) format files. As a result, viewing a
corrupted file may present an attacker with the opportunity to execute
code of their choosing.

The Sourcefire VRT has confirmed that a rule identified as sid 2436,
released on May 21, 2004, will generate events when an attempt is made
to exploit this vulnerability. Also, rules to detect attacks targeting
this vulnerability are included in this update and are identified as
sids 5318 and 5319.

Note: Due to the possibility of a high false positive rate, sid 5318 is
not enabled by default.

WARNING
To reduce the possibility of evasion, http_inspect needs to be
configured with "flow_depth 0" so that it can inspect all the traffic
from HTTP server responses. Setting flow_depth 0 will cause performance
problems in some situations.

The Sober worm is a mass mailer normally spread via email. A variant of
this worm displays more infection indicators that can be detected
easily using rules.

Rules to detect machines infected with this variant of the sober worm
are included in this update and are identified as sids 5321 through
5323.

Additionally, Sourcefire RNA customers can utilize the capabilities of
their RNA applicance to detect infections, instructions can be found on
the Sourcefire Customer Support Site.


New rules:
4982 - WEB-CLIENT Adodb.Stream ActiveX Object Access (web-client.rules)
4983 - WEB-CLIENT Adodb.Stream ActiveX Object Access CreateObject
Function (web-client.rules)
4984 - MS-SQL/SMB sa brute force failed login unicode attempt
(sql.rules)
4985 - WEB-MISC Twiki rdiff rev command injection attempt
(web-misc.rules)
4986 - WEB-MISC Twiki view rev command injection attempt
(web-misc.rules)
4987 - WEB-MISC Twiki viewfile rev command injection attempt
(web-misc.rules)
4988 - WEB-MISC Barracuda IMG.PL directory traversal attempt
(web-misc.rules)
4989 - MS-SQL Heap-Based Overflow Attempt (sql.rules)
4990 - MS-SQL Heap-Based Overflow Attempt (sql.rules)
4991 - NETBIOS SMB lsass unicode alter context attempt (netbios.rules)
4992 - NETBIOS SMB lsass WriteAndX unicode alter context attempt
(netbios.rules)
4993 - NETBIOS SMB lsass unicode bind attempt (netbios.rules)
4994 - NETBIOS SMB lsass WriteAndX unicode bind attempt (netbios.rules)
4995 - NETBIOS SMB-DS lsass bind attempt (netbios.rules)
4996 - NETBIOS SMB-DS lsass WriteAndX bind attempt (netbios.rules)
4997 - NETBIOS SMB-DS lsass unicode bind attempt (netbios.rules)
4998 - NETBIOS SMB-DS lsass WriteAndX unicode bind attempt
(netbios.rules)
4999 - NETBIOS-DG SMB lsass bind attempt (netbios.rules)
5000 - NETBIOS-DG SMB lsass WriteAndX bind attempt (netbios.rules)
5001 - NETBIOS-DG SMB lsass unicode bind attempt (netbios.rules)
5002 - NETBIOS-DG SMB lsass WriteAndX unicode bind attempt
(netbios.rules)
5003 - NETBIOS SMB lsass little endian bind attempt (netbios.rules)
5004 - NETBIOS SMB lsass WriteAndX little endian bind attempt
(netbios.rules)
5005 - NETBIOS SMB-DS lsass alter context attempt (netbios.rules)
5006 - NETBIOS-DG SMB lsass WriteAndX unicode alter context attempt
(netbios.rules)
5007 - NETBIOS SMB lsass little endian alter context attempt
(netbios.rules)
5008 - NETBIOS SMB lsass WriteAndX little endian alter context attempt
(netbios.rules)
5009 - NETBIOS SMB lsass unicode little endian alter context attempt
(netbios.rules)
5010 - NETBIOS SMB lsass WriteAndX unicode little endian alter context
attempt (netbios.rules)
5011 - NETBIOS SMB-DS lsass little endian alter context attempt
(netbios.rules)
5012 - NETBIOS SMB-DS lsass WriteAndX little endian alter context
attempt (netbios.rules)
5013 - NETBIOS SMB-DS lsass unicode little endian alter context attempt
(netbios.rules)
5014 - NETBIOS SMB-DS lsass WriteAndX unicode little endian alter
context attempt (netbios.rules)
5015 - NETBIOS-DG SMB lsass little endian alter context attempt
(netbios.rules)
5016 - NETBIOS-DG SMB lsass WriteAndX little endian alter context
attempt (netbios.rules)
5017 - NETBIOS-DG SMB lsass unicode little endian alter context attempt
(netbios.rules)
5018 - NETBIOS-DG SMB lsass WriteAndX unicode little endian alter
context attempt (netbios.rules)
5019 - NETBIOS SMB lsass bind attempt (netbios.rules)
5020 - NETBIOS SMB lsass WriteAndX bind attempt (netbios.rules)
5021 - NETBIOS SMB lsass unicode little endian bind attempt
(netbios.rules)
5022 - NETBIOS SMB lsass WriteAndX unicode little endian bind attempt
(netbios.rules)
5023 - NETBIOS SMB-DS lsass little endian bind attempt (netbios.rules)
5024 - NETBIOS SMB-DS lsass WriteAndX little endian bind attempt
(netbios.rules)
5025 - NETBIOS SMB-DS lsass unicode little endian bind attempt
(netbios.rules)
5026 - NETBIOS SMB-DS lsass WriteAndX unicode little endian bind
attempt (netbios.rules)
5027 - NETBIOS-DG SMB lsass little endian bind attempt (netbios.rules)
5028 - NETBIOS-DG SMB lsass WriteAndX little endian bind attempt
(netbios.rules)
5029 - NETBIOS-DG SMB lsass unicode little endian bind attempt
(netbios.rules)
5030 - NETBIOS-DG SMB lsass WriteAndX unicode little endian bind
attempt (netbios.rules)
5031 - NETBIOS SMB lsass andx alter context attempt (netbios.rules)
5032 - NETBIOS SMB-DS lsass WriteAndX andx alter context attempt
(netbios.rules)
5033 - NETBIOS SMB-DS lsass unicode andx alter context attempt
(netbios.rules)
5034 - NETBIOS SMB lsass WriteAndX andx alter context attempt
(netbios.rules)
5035 - NETBIOS SMB-DS lsass WriteAndX unicode andx alter context
attempt (netbios.rules)
5036 - NETBIOS-DG SMB lsass andx alter context attempt (netbios.rules)
5037 - NETBIOS-DG SMB lsass WriteAndX andx alter context attempt
(netbios.rules)
5038 - NETBIOS-DG SMB lsass unicode andx alter context attempt
(netbios.rules)
5039 - NETBIOS SMB lsass unicode andx alter context attempt
(netbios.rules)
5040 - NETBIOS SMB lsass WriteAndX unicode andx alter context attempt
(netbios.rules)
5041 - NETBIOS SMB lsass unicode andx bind attempt (netbios.rules)
5042 - NETBIOS SMB lsass WriteAndX unicode andx bind attempt
(netbios.rules)
5043 - NETBIOS SMB-DS lsass andx bind attempt (netbios.rules)
5044 - NETBIOS SMB-DS lsass WriteAndX andx bind attempt (netbios.rules)
5045 - NETBIOS SMB-DS lsass unicode andx bind attempt (netbios.rules)
5046 - NETBIOS SMB-DS lsass WriteAndX unicode andx bind attempt
(netbios.rules)
5047 - NETBIOS-DG SMB lsass andx bind attempt (netbios.rules)
5048 - NETBIOS-DG SMB lsass WriteAndX andx bind attempt (netbios.rules)
5049 - NETBIOS-DG SMB lsass unicode andx bind attempt (netbios.rules)
5050 - NETBIOS-DG SMB lsass WriteAndX unicode andx bind attempt
(netbios.rules)
5051 - NETBIOS SMB lsass little endian andx bind attempt
(netbios.rules)
5052 - NETBIOS SMB lsass WriteAndX little endian andx bind attempt
(netbios.rules)
5053 - NETBIOS SMB-DS lsass andx alter context attempt (netbios.rules)
5054 - NETBIOS-DG SMB lsass WriteAndX unicode andx alter context
attempt (netbios.rules)
5055 - NETBIOS SMB lsass little endian andx alter context attempt
(netbios.rules)
5056 - NETBIOS SMB lsass WriteAndX little endian andx alter context
attempt (netbios.rules)
5057 - NETBIOS SMB lsass unicode little endian andx alter context
attempt (netbios.rules)
5058 - NETBIOS SMB lsass WriteAndX unicode little endian andx alter
context attempt (netbios.rules)
5059 - NETBIOS SMB-DS lsass little endian andx alter context attempt
(netbios.rules)
5060 - NETBIOS SMB-DS lsass WriteAndX little endian andx alter context
attempt (netbios.rules)
5061 - NETBIOS SMB-DS lsass unicode little endian andx alter context
attempt (netbios.rules)
5062 - NETBIOS SMB-DS lsass WriteAndX unicode little endian andx alter
context attempt (netbios.rules)
5063 - NETBIOS-DG SMB lsass little endian andx alter context attempt
(netbios.rules)
5064 - NETBIOS-DG SMB lsass WriteAndX little endian andx alter context
attempt (netbios.rules)
5065 - NETBIOS-DG SMB lsass unicode little endian andx alter context
attempt (netbios.rules)
5066 - NETBIOS-DG SMB lsass WriteAndX unicode little endian andx alter
context attempt (netbios.rules)
5067 - NETBIOS SMB lsass andx bind attempt (netbios.rules)
5068 - NETBIOS SMB lsass WriteAndX andx bind attempt (netbios.rules)
5069 - NETBIOS SMB lsass unicode little endian andx bind attempt
(netbios.rules)
5070 - NETBIOS SMB lsass WriteAndX unicode little endian andx bind
attempt (netbios.rules)
5071 - NETBIOS SMB-DS lsass little endian andx bind attempt
(netbios.rules)
(list truncated do to message size)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (Darwin)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFDtczUMpm0ve0NhMcRAs73AJwJErGwJ5ml/TRYI4sILZU6vVzQLwCdHHT0
pBSJ8DM7W/VnExzKo7mStIw=
=BUUv
-----END PGP SIGNATURE-----




More information about the Snort-sigs mailing list