Snort mailing list archives
Re: Question regarding SNORT Rule
From: Alex McDonnell <amcdonnell () sourcefire com>
Date: Wed, 15 Jan 2020 14:48:27 -0500
The rules show up as disabled simply because they are not enabled in the balanced policy. I believe they are enabled in balanced for the next build (tomorrow) thanks Alex McDonnell Talos On Wed, Jan 15, 2020 at 2:24 PM Filice II, Anthony via Snort-sigs < snort-sigs () lists snort org> wrote:
All, Question regarding Microsoft Vulnerability CVE-2020-0601: A coding deficiency exists in Microsoft Windows CryptoAPI that may lead to spoofing. Why is this disabled in the new rules 1:52596 <-> DISABLED <-> OS-WINDOWS Microsoft Windows CryptoAPI signed binary with spoofed certificate attempt (os-windows.rules) * 1:52595 <-> DISABLED <-> OS-WINDOWS Microsoft Windows CryptoAPI signed binary with spoofed certificate attempt (os-windows.rules) * 1:52594 <-> DISABLED <-> OS-WINDOWS Microsoft Windows CryptoAPI signed binary with spoofed certificate attempt (os-windows.rules) * 1:52593 <-> DISABLED <-> OS-WINDOWS Microsoft Windows CryptoAPI signed binary with spoofed certificate attempt (os-windows.rules) Anthony C Filice II IPS/NAC Engineer IPR-IPR-SEC-F1840 313-656-3472 desk 702-287-6732 cell _______________________________________________ Snort-sigs mailing list Snort-sigs () lists snort org https://lists.snort.org/mailman/listinfo/snort-sigs Please visit http://blog.snort.org for the latest news about Snort! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
_______________________________________________ Snort-sigs mailing list Snort-sigs () lists snort org https://lists.snort.org/mailman/listinfo/snort-sigs Please visit http://blog.snort.org for the latest news about Snort! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
Current thread:
- Question regarding SNORT Rule Filice II, Anthony via Snort-sigs (Jan 15)
- Re: Question regarding SNORT Rule Joel Esler (jesler) via Snort-sigs (Jan 15)
- Re: Question regarding SNORT Rule Alex McDonnell (Jan 15)
- Re: Question regarding SNORT Rule Filice II, Anthony via Snort-sigs (Jan 15)