Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2017-06-22

This SRU number: 2017-06-21-001
Previous SRU number: 2017-06-19-001

Applies to:

This SEU number: 1698
Previous SEU: 1697

Applies to:

This is the complete list of rules added in SRU 2017-06-21-001 and SEU 1698.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
143240BROWSER-PLUGINSRising Online Virus Scanner ActiveX clsid access attemptoffoffoff
143241BROWSER-PLUGINSRising Online Virus Scanner ActiveX clsid access attemptoffoffoff
143242BROWSER-PLUGINSRising Online Virus Scanner ActiveX clsid access attemptoffoffoff
143243BROWSER-PLUGINSRising Online Virus Scanner ActiveX clsid access attemptoffoffoff
143244SERVER-WEBAPPActive Calendar showcode.php directory traversal attemptoffoffoff
143245SERVER-WEBAPPActive Calendar showcode.php directory traversal attemptoffoffoff
143246SERVER-WEBAPPActive Calendar showcode.php directory traversal attemptoffoffoff
143248MALWARE-CNCWin.Trojan.VEye2 remote access tool installationoffdropdrop
143249SERVER-WEBAPPNuxeo CMS BatchUploadObject arbitrary JSP file upload attemptoffoffdrop
143250SERVER-WEBAPPNuxeo CMS BatchUploadObject directory traversal attemptoffoffdrop
143251SERVER-WEBAPPTrend Micro InterScan WSA LogSettingHandler command injection attemptoffoffdrop
143254INDICATOR-SHELLCODEKUSER_SHARED_DATA NtMajorVersion and NtMinorVersion offsetsoffoffoff
143255INDICATOR-SHELLCODEsingle byte x86 xor decryption routineoffoffdrop
143256INDICATOR-OBFUSCATIONRig EK fromCharCode offset 33 obfuscated getElementsByTagName calloffdropdrop
143257SERVER-WEBAPPCA eHealth command injection command injection attemptoffoffdrop
143258SERVER-WEBAPPCA eHealth command injection command injection attemptoffoffdrop
143259FILE-OTHERHangul Word Processor type confusion attemptoffoffoff
143260FILE-OTHERHangul Word Processor type confusion attemptoffoffoff
143261FILE-OTHERHangul Word Processor type confusion attemptoffoffoff
143262FILE-OTHERHangul Word Processor type confusion attemptoffoffoff
143263FILE-OTHERHangul Word Processor type confusion attemptoffoffoff
143264FILE-OTHERHangul Word Processor type confusion attemptoffoffoff
143265SERVER-WEBAPPSERVER-WEBAPP Novell NetIQ Sentinel Server ReportViewServlet directory traversal attempt directory traversal attemptoffoffoff
143266SERVER-WEBAPPSERVER-WEBAPP Novell NetIQ Sentinel Server ReportViewServlet directory traversal attempt directory traversal attemptoffoffoff
143267SERVER-WEBAPPSERVER-WEBAPP Novell NetIQ Sentinel Server ReportViewServlet directory traversal attempt directory traversal attemptoffoffoff
143268SERVER-WEBAPPSquid ESI processing buffer overflow attemptoffoffoff
143269FILE-MULTIMEDIAMicrosoft Windows DirectX directshow wav file overflow attemptoffoffoff
143270FILE-MULTIMEDIAMicrosoft Windows DirectX directshow wav file overflow attemptoffoffoff
343271SERVER-WEBAPPCisco Prime Infrastructure XML external entity injection attemptoffoffdrop
143272SERVER-WEBAPPAdvantech WebAccess openWidget directory traversal attempt directory traversal attemptoffoffdrop
143273SERVER-WEBAPPAdvantech WebAccess openWidget directory traversal attempt directory traversal attemptoffoffdrop
143274SERVER-WEBAPPAdvantech WebAccess openWidget directory traversal attempt directory traversal attemptoffoffdrop
143279SERVER-WEBAPPAdvantech WebAccess cross site scripting attemptoffoffoff
143280SERVER-WEBAPPAdvantech WebAccess cross site scripting attemptoffoffoff
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
143238SERVER-WEBAPPImatix Xitami web server head processing denial of service attemptoffoffoff
143239PROTOCOL-FTPWS-FTP REST command overly large file creation attemptoffoffoff
143247SERVER-APACHEApache Rave information disclosure attemptoffoffoff
143252PROTOCOL-SCADAIEC 61850 device connection enumeration attemptoffoffoff
143253PROTOCOL-SCADAIEC 61850 virtual manufacturing device domain variable enumeration attemptoffoffoff
143275OS-WINDOWSMicrosoft Windows MFT denial of service attemptoffoffoff
143276OS-WINDOWSMicrosoft Windows MFT denial of service attemptoffoffoff
143277OS-WINDOWSMicrosoft Windows MFT denial of service attemptoffoffoff
143278OS-WINDOWSMicrosoft Windows MFT denial of service attemptoffoffoff