Snort mailing list archives

Re: Question regarding SNORT Rule


From: Alex McDonnell <amcdonnell () sourcefire com>
Date: Wed, 15 Jan 2020 14:48:27 -0500

The rules show up as disabled simply because they are not enabled in the
balanced policy. I believe they are enabled in balanced for the next build
(tomorrow)

thanks
Alex McDonnell
Talos

On Wed, Jan 15, 2020 at 2:24 PM Filice II, Anthony via Snort-sigs <
snort-sigs () lists snort org> wrote:

All,



Question regarding Microsoft Vulnerability CVE-2020-0601: A coding
deficiency exists in Microsoft Windows CryptoAPI that may lead to spoofing.



Why is this disabled in the new rules



1:52596 <-> DISABLED <-> OS-WINDOWS Microsoft Windows CryptoAPI signed
binary with spoofed certificate attempt (os-windows.rules)

* 1:52595 <-> DISABLED <-> OS-WINDOWS Microsoft Windows CryptoAPI signed
binary with spoofed certificate attempt (os-windows.rules)

* 1:52594 <-> DISABLED <-> OS-WINDOWS Microsoft Windows CryptoAPI signed
binary with spoofed certificate attempt (os-windows.rules)

* 1:52593 <-> DISABLED <-> OS-WINDOWS Microsoft Windows CryptoAPI signed
binary with spoofed certificate attempt (os-windows.rules)







Anthony C Filice II

IPS/NAC Engineer

IPR-IPR-SEC-F1840

313-656-3472 desk

702-287-6732 cell


_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules:
https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure
to stay up to date to catch the most <a href="
https://snort.org/downloads/#rule-downloads";>emerging threats</a>!

_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a 
href=" https://snort.org/downloads/#rule-downloads";>emerging threats</a>!

Current thread: