Talos has added and modified multiple rules in the browser-ie, policy-other and server-webapp rule sets to provide coverage for emerging threats from these technologies.
For information about Snort Subscriber Rulesets available for purchase, please visit the Snort product page.
This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2976.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:41918 <-> DISABLED <-> SERVER-WEBAPP Carel PlantVisorPRO malicious sql query attempt - RCmdComm (server-webapp.rules) * 1:41920 <-> DISABLED <-> SERVER-WEBAPP McAfee Virus Scan Linux authentication token brute force attempt (server-webapp.rules) * 1:41921 <-> DISABLED <-> SERVER-WEBAPP PAESSLER PRTG DoS attempt (server-webapp.rules) * 1:41919 <-> DISABLED <-> SERVER-WEBAPP Carel PlantVisorPRO malicious sql query attempt - RCmdComm2 (server-webapp.rules) * 1:41917 <-> ENABLED <-> SERVER-WEBAPP Carel PlantVisorPRO default login attempt (server-webapp.rules) * 1:41915 <-> DISABLED <-> POLICY-OTHER Carel PlantVisorPRO insecure SQL query transmission (policy-other.rules) * 1:41912 <-> ENABLED <-> BROWSER-IE Microsoft Internet Explorer Chakra.dll proxy object prototype return type confusion attempt (browser-ie.rules) * 1:41914 <-> DISABLED <-> SERVER-WEBAPP WordPress Plugin RevSlider file upload attempt (server-webapp.rules) * 1:41913 <-> DISABLED <-> SERVER-WEBAPP InterSystem Cache DOS attempt (server-webapp.rules) * 1:41911 <-> ENABLED <-> BROWSER-IE Microsoft Internet Explorer Chakra.dll proxy object prototype return type confusion attempt (browser-ie.rules) * 1:41923 <-> ENABLED <-> SERVER-APACHE Apache Struts remote code execution attempt (server-apache.rules) * 1:41922 <-> ENABLED <-> SERVER-APACHE Apache Struts remote code execution attempt (server-apache.rules) * 1:41916 <-> DISABLED <-> SERVER-WEBAPP Carel PlantVisorPRO malicious sql query attempt - DBCommander (server-webapp.rules)
* 1:40497 <-> DISABLED <-> SERVER-WEBAPP WordPress Plugin RevSlider file upload attempt (server-webapp.rules) * 1:41190 <-> DISABLED <-> POLICY-OTHER Adobe Flash SMTP MIME attachment detected (policy-other.rules) * 1:41191 <-> DISABLED <-> POLICY-OTHER Adobe Flash SMTP MIME attachment detected (policy-other.rules) * 1:41192 <-> DISABLED <-> POLICY-OTHER Adobe Flash SMTP MIME attachment detected (policy-other.rules)
This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2983.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:41921 <-> DISABLED <-> SERVER-WEBAPP PAESSLER PRTG DoS attempt (server-webapp.rules) * 1:41915 <-> DISABLED <-> POLICY-OTHER Carel PlantVisorPRO insecure SQL query transmission (policy-other.rules) * 1:41911 <-> ENABLED <-> BROWSER-IE Microsoft Internet Explorer Chakra.dll proxy object prototype return type confusion attempt (browser-ie.rules) * 1:41912 <-> ENABLED <-> BROWSER-IE Microsoft Internet Explorer Chakra.dll proxy object prototype return type confusion attempt (browser-ie.rules) * 1:41916 <-> DISABLED <-> SERVER-WEBAPP Carel PlantVisorPRO malicious sql query attempt - DBCommander (server-webapp.rules) * 1:41914 <-> DISABLED <-> SERVER-WEBAPP WordPress Plugin RevSlider file upload attempt (server-webapp.rules) * 1:41913 <-> DISABLED <-> SERVER-WEBAPP InterSystem Cache DOS attempt (server-webapp.rules) * 1:41917 <-> ENABLED <-> SERVER-WEBAPP Carel PlantVisorPRO default login attempt (server-webapp.rules) * 1:41918 <-> DISABLED <-> SERVER-WEBAPP Carel PlantVisorPRO malicious sql query attempt - RCmdComm (server-webapp.rules) * 1:41919 <-> DISABLED <-> SERVER-WEBAPP Carel PlantVisorPRO malicious sql query attempt - RCmdComm2 (server-webapp.rules) * 1:41920 <-> DISABLED <-> SERVER-WEBAPP McAfee Virus Scan Linux authentication token brute force attempt (server-webapp.rules) * 1:41923 <-> ENABLED <-> SERVER-APACHE Apache Struts remote code execution attempt (server-apache.rules) * 1:41922 <-> ENABLED <-> SERVER-APACHE Apache Struts remote code execution attempt (server-apache.rules)
* 1:40497 <-> DISABLED <-> SERVER-WEBAPP WordPress Plugin RevSlider file upload attempt (server-webapp.rules) * 1:41190 <-> DISABLED <-> POLICY-OTHER Adobe Flash SMTP MIME attachment detected (policy-other.rules) * 1:41191 <-> DISABLED <-> POLICY-OTHER Adobe Flash SMTP MIME attachment detected (policy-other.rules) * 1:41192 <-> DISABLED <-> POLICY-OTHER Adobe Flash SMTP MIME attachment detected (policy-other.rules)
This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2990.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:41923 <-> ENABLED <-> SERVER-APACHE Apache Struts remote code execution attempt (server-apache.rules) * 1:41922 <-> ENABLED <-> SERVER-APACHE Apache Struts remote code execution attempt (server-apache.rules) * 1:41921 <-> DISABLED <-> SERVER-WEBAPP PAESSLER PRTG DoS attempt (server-webapp.rules) * 1:41920 <-> DISABLED <-> SERVER-WEBAPP McAfee Virus Scan Linux authentication token brute force attempt (server-webapp.rules) * 1:41919 <-> DISABLED <-> SERVER-WEBAPP Carel PlantVisorPRO malicious sql query attempt - RCmdComm2 (server-webapp.rules) * 1:41918 <-> DISABLED <-> SERVER-WEBAPP Carel PlantVisorPRO malicious sql query attempt - RCmdComm (server-webapp.rules) * 1:41917 <-> ENABLED <-> SERVER-WEBAPP Carel PlantVisorPRO default login attempt (server-webapp.rules) * 1:41916 <-> DISABLED <-> SERVER-WEBAPP Carel PlantVisorPRO malicious sql query attempt - DBCommander (server-webapp.rules) * 1:41915 <-> DISABLED <-> POLICY-OTHER Carel PlantVisorPRO insecure SQL query transmission (policy-other.rules) * 1:41914 <-> DISABLED <-> SERVER-WEBAPP WordPress Plugin RevSlider file upload attempt (server-webapp.rules) * 1:41913 <-> DISABLED <-> SERVER-WEBAPP InterSystem Cache DOS attempt (server-webapp.rules) * 1:41912 <-> ENABLED <-> BROWSER-IE Microsoft Internet Explorer Chakra.dll proxy object prototype return type confusion attempt (browser-ie.rules) * 1:41911 <-> ENABLED <-> BROWSER-IE Microsoft Internet Explorer Chakra.dll proxy object prototype return type confusion attempt (browser-ie.rules)
* 1:41191 <-> DISABLED <-> POLICY-OTHER Adobe Flash SMTP MIME attachment detected (policy-other.rules) * 1:41192 <-> DISABLED <-> POLICY-OTHER Adobe Flash SMTP MIME attachment detected (policy-other.rules) * 1:40497 <-> DISABLED <-> SERVER-WEBAPP WordPress Plugin RevSlider file upload attempt (server-webapp.rules) * 1:41190 <-> DISABLED <-> POLICY-OTHER Adobe Flash SMTP MIME attachment detected (policy-other.rules)