Snort mailing list archives

Sourcefire VRT Certified Snort Rules Update 2013-04-09


From: Research <research () sourcefire com>
Date: Tue, 9 Apr 2013 13:34:21 -0400 (EDT)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Sourcefire VRT Certified Snort Rules Update

Synopsis:
The Sourcefire VRT is aware of vulnerabilities affecting products from
Microsoft Corporation.

Details:
Microsoft Security Bulletin MS13-029:
Microsoft Remote Desktop Client contains programming errors that may
allow a remote attacker to execute code on a vulnerable system.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 26355 through 26365.


Microsoft Security Bulletin MS13-032:
A vulnerability in Microsoft Active Directory could lead to a denial of
service.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SID 26354.

Additionally, the Sourcefire VRT has added and modified multiple rules
in the bad-traffic, blacklist, browser-ie, browser-plugins, deleted,
dos, exploit-kit, file-other, indicator-compromise,
indicator-obfuscation, malware-cnc, malware-other, netbios, os-windows,
protocol-ftp and server-webapp rule sets to provide coverage for
emerging threats from these technologies.

For a complete list of new and modified rules please see:

http://www.snort.org/vrt/docs/ruleset_changelogs/changes-2013-04-09.html
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iD8DBQFRZFEfaBoqZBVJfwMRAnxLAJ0eoHPnPfWMwHQ8fm6gEqVa5ALZGQCeIQzy
/qI/Hqqkz4iK9XO2sUTKBFg=
=Rt9C
-----END PGP SIGNATURE-----


------------------------------------------------------------------------------
Precog is a next-generation analytics platform capable of advanced
analytics on semi-structured data. The platform includes APIs for building
apps and a phenomenal toolset for data science. Developers can use
our toolset for easy data analysis & visualization. Get a free account!
http://www2.precog.com/precogplatform/slashdotnewsletter
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
http://www.snort.org


Please visit http://blog.snort.org for the latest news about Snort!


Current thread: