Snort mailing list archives

Re: SID 39379 Norton Antivirus ASPack


From: Alex McDonnell <amcdonnell () sourcefire com>
Date: Mon, 13 Feb 2017 15:11:47 -0500

This is a Shared Object rule that is detecting CVE-2016-2208 that was
published in https://bugs.chromium.org/p/project-zero/issues/detail?id=820

Thanks
Alex McDonnell
TALOS

On Mon, Feb 13, 2017 at 3:01 PM, Charlie Dyer <charlierwdyer () gmail com>
wrote:

Hello list

Could anyone shed light on the rule 39379?

I can't see any content matching, it simply alerts on any file that is an
executable being downloaded, is that right?
If so, what has this got to do with Norton Antivirus?

Many thanks in advance.

Charlie

------------------------------------------------------------
------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, SlashDot.org! http://sdm.link/slashdot
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs

http://www.snort.org

Please visit http://blog.snort.org for the latest news about Snort!

Visit the Snort.org to subscribe to the official Snort ruleset, make sure
to stay up to date to catch the most <a href="
https://snort.org/downloads/#rule-downloads";>emerging threats</a>!

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, SlashDot.org! http://sdm.link/slashdot
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs

http://www.snort.org

Please visit http://blog.snort.org for the latest news about Snort!

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a 
href=" https://snort.org/downloads/#rule-downloads";>emerging threats</a>!

Current thread: