Sourcefire VRT Update for Sourcefire 3D System

Date: 2014-07-24

This SRU number: 2014-07-23-001
Previous SRU number: 2014-07-21-001

Applies to:

This SEU number: 1146
Previous SEU: 1144

Applies to:

This is the complete list of rules added in SRU 2014-07-23-001 and SEU 1146.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
112784SERVER-OTHERCA ARCserve LGServer stack buffer overflow attemptoffoffoff
112785SERVER-OTHERCA ARCserve LGServer stack buffer overflow attemptoffoffoff
112786SERVER-OTHERCA ARCserve LGServer stack buffer overflow attemptoffoffoff
125549SERVER-OTHERNovell eDirectory NCP stack buffer overflow attemptdropdropdrop
125550SERVER-OTHERNovell eDirectory NCP stack buffer overflow attemptdropdropdrop
125589SERVER-OTHERlibupnp command buffer overflow attemptdropdropdrop
125601SERVER-OTHERlibupnp command buffer overflow attemptdropdropdrop
125612SERVER-OTHERlibupnp command buffer overflow attemptdropdropdrop
125617SERVER-OTHERlibupnp command buffer overflow attemptdropdropdrop
125618SERVER-OTHERlibupnp command buffer overflow attemptdropdropdrop
125619SERVER-OTHERlibupnp command buffer overflow attemptdropdropdrop
125620SERVER-OTHERlibupnp command buffer overflow attemptdropdropdrop
131497SERVER-WEBAPPOracle Event Processing FileUploadServlet directory traversal attemptoffdropdrop
131498SERVER-WEBAPPOracle Event Processing FileUploadServlet directory traversal attemptoffdropdrop
131499INDICATOR-COMPROMISELiz0ziM php shell download attemptoffdropdrop
131500INDICATOR-COMPROMISELiz0ziM php shell upload attemptoffdropdrop
131501INDICATOR-COMPROMISELiz0ziM php shell command and control attemptoffdropdrop
131502INDICATOR-COMPROMISELiz0ziM php shell command and control attemptoffdropdrop
131503INDICATOR-COMPROMISELiz0ziM php shell download attemptoffdropdrop
131504BROWSER-IEMicrosoft Internet Explorer outerHTML against incomplete element heap corruption attemptoffoffdrop
131505SERVER-WEBAPPAlienVault OSSIM av-centerd get_license command injection attemptdropdropdrop
131506SERVER-WEBAPPAlienVault OSSIM av-centerd get_log_line command injection attemptdropdropdrop
131507MALWARE-CNCWin.Trojan.HW32 variant spam attemptoffdropdrop
131508BLACKLISTDNS request for known malware domain getsearch.netoffdropdrop
131509BLACKLISTDNS request for known malware domain greatfindpage.comoffdropdrop
131510MALWARE-OTHERWin.Trojan.Injector outbound trafficoffdropdrop
131511FILE-JAVAOracle Java field bytecode verifier cache code execution attemptdropdropdrop
131512FILE-JAVAOracle Java field bytecode verifier cache code execution attemptdropdropdrop
131514BLACKLISTDNS request for known malware domain bastelfunboard.ch - Andr.Trojan.Emmentaloffdropdrop
131515BLACKLISTDNS request for known malware domain oguhtell.ch - Andr.Trojan.Emmentaloffdropdrop
131516BLACKLISTDNS request for known malware domain security-apps.biz - Andr.Trojan.Emmentaloffdropdrop
131517BLACKLISTDNS request for known malware domain security-apps.net - Andr.Trojan.Emmentaloffdropdrop
131518BLACKLISTDNS request for known malware domain tc-zo.ch - Andr.Trojan.Emmentaloffdropdrop
131519FILE-MULTIMEDIAAdobe Flash pixel bender buffer overflow attemptoffdropdrop
131520FILE-MULTIMEDIAAdobe Flash pixel bender buffer overflow attemptoffdropdrop
131521FILE-MULTIMEDIAAdobe Flash pixel bender buffer overflow attemptoffdropdrop
131522FILE-MULTIMEDIAAdobe Flash pixel bender buffer overflow attemptoffdropdrop
131523FILE-MULTIMEDIAAdobe Flash pixel bender buffer overflow attemptoffdropdrop
131524FILE-MULTIMEDIAAdobe Flash pixel bender buffer overflow attemptoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
125664SERVER-OTHERMiniUPnPd SSDP request buffer overflow attemptoffoffoff
130711SERVER-OTHEROpenVPN OpenSSL SSLv3 heartbeat read overrun attemptoffdropdrop
130712SERVER-OTHEROpenVPN OpenSSL SSLv3 heartbeat read overrun attemptoffdropdrop
130713SERVER-OTHEROpenVPN OpenSSL TLSv1 heartbeat read overrun attemptoffdropdrop
130714SERVER-OTHEROpenVPN OpenSSL TLSv1 heartbeat read overrun attemptoffdropdrop
130715SERVER-OTHEROpenVPN OpenSSL TLSv1.1 heartbeat read overrun attemptoffdropdrop
130716SERVER-OTHEROpenVPN OpenSSL TLSv1.1 heartbeat read overrun attemptoffdropdrop
130717SERVER-OTHEROpenVPN OpenSSL TLSv1.2 heartbeat read overrun attemptoffdropdrop
130718SERVER-OTHEROpenVPN OpenSSL TLSv1.2 heartbeat read overrun attemptoffdropdrop
130719SERVER-OTHEROpenVPN OpenSSL SSLv3 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130720SERVER-OTHEROpenVPN OpenSSL SSLv3 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130721SERVER-OTHEROpenVPN OpenSSL TLSv1 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130722SERVER-OTHEROpenVPN OpenSSL TLSv1 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130723SERVER-OTHEROpenVPN OpenSSL TLSv1.1 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130724SERVER-OTHEROpenVPN OpenSSL TLSv1.1 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130725SERVER-OTHEROpenVPN OpenSSL TLSv1.2 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130726SERVER-OTHEROpenVPN OpenSSL TLSv1.2 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130727SERVER-OTHEROpenVPN OpenSSL SSLv3 heartbeat read overrun attemptoffdropdrop
130728SERVER-OTHEROpenVPN OpenSSL SSLv3 heartbeat read overrun attemptoffdropdrop
130729SERVER-OTHEROpenVPN OpenSSL TLSv1 heartbeat read overrun attemptoffdropdrop
130730SERVER-OTHEROpenVPN OpenSSL TLSv1 heartbeat read overrun attemptoffdropdrop
130731SERVER-OTHEROpenVPN OpenSSL TLSv1.1 heartbeat read overrun attemptoffdropdrop
130732SERVER-OTHEROpenVPN OpenSSL TLSv1.1 heartbeat read overrun attemptoffdropdrop
130733SERVER-OTHEROpenVPN OpenSSL TLSv1.2 heartbeat read overrun attemptoffdropdrop
130734SERVER-OTHEROpenVPN OpenSSL TLSv1.2 heartbeat read overrun attemptoffdropdrop
130735SERVER-OTHEROpenVPN OpenSSL SSLv3 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130736SERVER-OTHEROpenVPN OpenSSL SSLv3 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130737SERVER-OTHEROpenVPN OpenSSL TLSv1 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130738SERVER-OTHEROpenVPN OpenSSL TLSv1 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130739SERVER-OTHEROpenVPN OpenSSL TLSv1.1 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130740SERVER-OTHEROpenVPN OpenSSL TLSv1.1 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130741SERVER-OTHEROpenVPN OpenSSL TLSv1.2 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
130742SERVER-OTHEROpenVPN OpenSSL TLSv1.2 large heartbeat response - possible ssl heartbleed attemptoffdropdrop
131513BROWSER-FIREFOXMultiple browser pressure function denial of service attemptoffoffoff

Updated Rules:

Updated rules can be found at this link.