Talos Rules 2022-05-19
This release adds and modifies rules in several categories.

Talos has added and modified multiple rules in the os-windows and server-webapp rule sets to provide coverage for emerging threats from these technologies.

For information about Snort Subscriber Rulesets available for purchase, please visit the Snort product page.

Change logs

2022-05-19 17:26:21 UTC

Snort Subscriber Rules Update

Date: 2022-05-19

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091900.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59802 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59803 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59804 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59805 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59806 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59807 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59808 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59809 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59810 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59811 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59812 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt (server-webapp.rules)
 * 1:59813 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59814 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59815 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59816 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59817 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59818 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59819 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59820 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59821 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59822 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59823 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59824 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 3:59646 <-> ENABLED <-> SERVER-OTHER OpenSSL X509_cmp_time out of bounds read attempt (server-other.rules)

Modified Rules:



2022-05-19 17:26:21 UTC

Snort Subscriber Rules Update

Date: 2022-05-19

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091801.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59823 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59816 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59822 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59815 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59824 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59802 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59803 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59804 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59805 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59806 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59807 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59808 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59809 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59810 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59811 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59812 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt (server-webapp.rules)
 * 1:59813 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59814 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59818 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59819 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59820 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59821 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59817 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 3:59646 <-> ENABLED <-> SERVER-OTHER OpenSSL X509_cmp_time out of bounds read attempt (server-other.rules)

Modified Rules:



2022-05-19 17:26:21 UTC

Snort Subscriber Rules Update

Date: 2022-05-19

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091701.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59824 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59823 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59821 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59822 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59802 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59805 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59806 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59807 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59808 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59809 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59810 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59811 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59812 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt (server-webapp.rules)
 * 1:59813 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59814 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59815 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59816 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59804 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59818 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59819 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59820 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59803 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59817 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 3:59646 <-> ENABLED <-> SERVER-OTHER OpenSSL X509_cmp_time out of bounds read attempt (server-other.rules)

Modified Rules:



2022-05-19 17:26:21 UTC

Snort Subscriber Rules Update

Date: 2022-05-19

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091700.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59816 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59817 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59824 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59823 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59822 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59819 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59818 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59820 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59821 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59804 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59803 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59805 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59808 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59807 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59802 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59809 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59810 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59806 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59811 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59814 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59813 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59812 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt (server-webapp.rules)
 * 1:59815 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 3:59646 <-> ENABLED <-> SERVER-OTHER OpenSSL X509_cmp_time out of bounds read attempt (server-other.rules)

Modified Rules:



2022-05-19 17:26:21 UTC

Snort Subscriber Rules Update

Date: 2022-05-19

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091601.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59821 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59819 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59824 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59822 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59802 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59803 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59820 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59808 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59806 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59805 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59807 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59804 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59810 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59809 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59812 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt (server-webapp.rules)
 * 1:59811 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59814 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59813 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59816 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59815 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59818 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59817 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59823 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 3:59646 <-> ENABLED <-> SERVER-OTHER OpenSSL X509_cmp_time out of bounds read attempt (server-other.rules)

Modified Rules:



2022-05-19 17:26:21 UTC

Snort Subscriber Rules Update

Date: 2022-05-19

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091600.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59819 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59821 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59820 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59824 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59822 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59823 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59802 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59803 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59804 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59805 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59808 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59807 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59809 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59810 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59811 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59814 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59813 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59806 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59815 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59818 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59817 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59812 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt (server-webapp.rules)
 * 1:59816 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 3:59646 <-> ENABLED <-> SERVER-OTHER OpenSSL X509_cmp_time out of bounds read attempt (server-other.rules)

Modified Rules:



2022-05-19 17:26:21 UTC

Snort Subscriber Rules Update

Date: 2022-05-19

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091501.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59820 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59824 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59823 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59821 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59819 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59822 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59804 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59802 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59808 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59806 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59807 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59815 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59814 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59810 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59805 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59812 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt (server-webapp.rules)
 * 1:59811 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59809 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59818 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59813 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59816 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59803 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59817 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 3:59646 <-> ENABLED <-> SERVER-OTHER OpenSSL X509_cmp_time out of bounds read attempt (server-other.rules)

Modified Rules:



2022-05-19 17:26:21 UTC

Snort Subscriber Rules Update

Date: 2022-05-19

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091401.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59819 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59818 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59824 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59823 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59803 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59804 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59805 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59806 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59807 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59808 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59809 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59810 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59811 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59812 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt (server-webapp.rules)
 * 1:59813 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59814 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59817 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59815 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59802 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59820 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59822 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59816 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59821 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 3:59646 <-> ENABLED <-> SERVER-OTHER OpenSSL X509_cmp_time out of bounds read attempt (server-other.rules)

Modified Rules:



2022-05-19 17:26:21 UTC

Snort Subscriber Rules Update

Date: 2022-05-19

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091300.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59822 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59802 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59821 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59804 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59806 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59807 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59808 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59809 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59810 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59811 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59824 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59812 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt (server-webapp.rules)
 * 1:59813 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59814 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59815 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59823 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59816 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59803 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59817 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59818 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59819 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59820 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59805 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 3:59646 <-> ENABLED <-> SERVER-OTHER OpenSSL X509_cmp_time out of bounds read attempt (server-other.rules)

Modified Rules:



2022-05-19 17:26:21 UTC

Snort Subscriber Rules Update

Date: 2022-05-19

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091101.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59803 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59812 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt (server-webapp.rules)
 * 1:59819 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59802 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59806 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59818 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59820 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59816 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59811 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59805 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59817 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59823 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59824 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59804 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59807 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59822 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59809 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59810 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59813 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59808 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59821 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59815 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59814 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 3:59646 <-> ENABLED <-> SERVER-OTHER OpenSSL X509_cmp_time out of bounds read attempt (server-other.rules)

Modified Rules:



2022-05-19 17:26:21 UTC

Snort Subscriber Rules Update

Date: 2022-05-19

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3000.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59808 <-> ENABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (snort3-server-webapp.rules)
 * 1:59807 <-> ENABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (snort3-server-webapp.rules)
 * 1:59815 <-> ENABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (snort3-server-webapp.rules)
 * 1:59814 <-> ENABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (snort3-server-webapp.rules)
 * 1:300178 <-> ENABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (snort3-server-other.rules)
 * 1:59806 <-> ENABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (snort3-server-webapp.rules)
 * 1:59816 <-> ENABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (snort3-server-webapp.rules)
 * 1:59812 <-> ENABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt (snort3-server-webapp.rules)
 * 1:59817 <-> ENABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (snort3-server-webapp.rules)
 * 1:59819 <-> ENABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (snort3-server-webapp.rules)
 * 1:59804 <-> ENABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (snort3-server-webapp.rules)
 * 1:59820 <-> ENABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (snort3-server-webapp.rules)
 * 1:59811 <-> ENABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (snort3-server-webapp.rules)
 * 1:59818 <-> ENABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (snort3-server-webapp.rules)
 * 1:59813 <-> ENABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (snort3-server-webapp.rules)
 * 1:59803 <-> ENABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (snort3-server-other.rules)
 * 1:59805 <-> ENABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (snort3-server-webapp.rules)
 * 1:59809 <-> ENABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (snort3-server-webapp.rules)
 * 1:59810 <-> ENABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (snort3-server-webapp.rules)

Modified Rules:



2022-05-19 17:26:21 UTC

Snort Subscriber Rules Update

Date: 2022-05-19

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2983.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59824 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59818 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59823 <-> DISABLED <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt (server-webapp.rules)
 * 1:59812 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt (server-webapp.rules)
 * 1:59817 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59820 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59811 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59821 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)
 * 1:59816 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59802 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59803 <-> DISABLED <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt (server-other.rules)
 * 1:59804 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59805 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59814 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59806 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59807 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59808 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59809 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59813 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59810 <-> DISABLED <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt (server-webapp.rules)
 * 1:59819 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt (server-webapp.rules)
 * 1:59815 <-> DISABLED <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt (server-webapp.rules)
 * 1:59822 <-> DISABLED <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt (os-windows.rules)

Modified Rules:



2022-05-19 17:29:28 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.0.3.1.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules:



2022-05-19 17:29:28 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.0.3.4.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules:



2022-05-19 17:29:28 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.0.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules:



2022-05-19 17:29:28 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.0.1.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules:



2022-05-19 17:29:28 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.1.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules:



2022-05-19 17:29:28 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.3.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules:



2022-05-19 17:29:29 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.4.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules:



2022-05-19 17:29:29 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.5.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules:



2022-05-19 17:29:29 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.7.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules:



2022-05-19 17:29:29 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.9.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules:



2022-05-19 17:29:29 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.11.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules:



2022-05-19 17:29:29 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.15.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules:



2022-05-19 17:29:29 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.18.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules:



2022-05-19 17:29:29 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.20.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules:



2022-05-19 17:29:29 UTC

Snort Subscriber Rules Update

Date: 2022-05-19-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.21.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300178 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:300179 <-> OS-WINDOWS Microsoft Windows malicious LNK file download attempt
* 1:59803 <-> SERVER-OTHER LibVNCClient FramebufferUpdate Rectangle heap buffer overflow attempt
* 1:59804 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59805 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59806 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59807 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59808 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59809 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59810 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59811 <-> SERVER-WEBAPP LG N1A1 NAS command injection attempt
* 1:59812 <-> SERVER-WEBAPP Citrix SD-WAN Appliance SQL injection attempt
* 1:59813 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59814 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59815 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59816 <-> SERVER-WEBAPP Citrix SD-WAN Appliance command injection attempt
* 1:59817 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59818 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59819 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59820 <-> SERVER-WEBAPP Netgear R8500 multiple parameters command injection attempt
* 1:59823 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt
* 1:59824 <-> SERVER-WEBAPP VMware Workspace ONE Access server side template injection attempt

Modified Rules: