Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2015-06-23

This SRU number: 2015-06-23-001
Previous SRU number: 2015-06-17-001

Applies to:

This SEU number: 1310
Previous SEU: 1307

Applies to:

This is the complete list of rules modified in SRU 2015-06-23-001 and SEU 1310.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
115473FILE-MULTIMEDIAMultiple media players M3U playlist file handling buffer overflow attemptoffoffoff
125799EXPLOIT-KITStamp exploit kit pdf requestoffoffoff
125801EXPLOIT-KITStamp exploit kit jar file requestoffoffoff
128237EXPLOIT-KITMagnitude/Nuclear exploit kit outbound pdf download attemptoffoffoff
128477EXPLOIT-KITStyx exploit kit outbound pdf requestoffoffoff
128478EXPLOIT-KITStyx exploit kit landing page requestoffoffoff
129163EXPLOIT-KITCritX exploit kit outbound exploit requestoffoffdrop
129164EXPLOIT-KITCritX exploit kit outbound flash requestoffoffdrop
129165EXPLOIT-KITCritX exploit kit outbound jar requestoffoffdrop
129166EXPLOIT-KITCritX exploit kit payload download attemptoffoffdrop
129167EXPLOIT-KITCritX exploit kit payload download attemptoffoffdrop
129443EXPLOIT-KITFiesta exploit kit outbound connection attemptoffoffoff
129444EXPLOIT-KITFiesta exploit kit flashplayer11 payload downloadoffoffdrop
131965EXPLOIT-KITAstrum exploit kit landing pageoffoffdrop
131966EXPLOIT-KITAstrum exploit kit payload deliveryoffoffdrop
131967EXPLOIT-KITAstrum exploit kit payload deliveryoffoffdrop
131970EXPLOIT-KITAstrum exploit kit redirection attemptoffoffdrop
131971EXPLOIT-KITAstrum exploit kit multiple exploit download requestoffoffoff
131972EXPLOIT-KITAstrum exploit kit payload deliveryoffoffdrop
134334EXPLOIT-KITFiesta exploit kit Adobe Reader exploit downloadoffoffoff