Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2016-09-06

This SRU number: 2016-09-06-001
Previous SRU number: 2016-08-31-001

Applies to:

This SEU number: 1540
Previous SEU: 1539

Applies to:

This is the complete list of rules added in SRU 2016-09-06-001 and SEU 1540.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
140030SERVER-WEBAPPFreePBX Module Administration config.php remotemod command injection attemptoffoffdrop
140031SERVER-WEBAPPFreePBX Module Administration config.php remotemod command injection attemptoffoffdrop
140032SERVER-WEBAPPFreePBX Module Administration config.php remotemod command injection attemptoffoffdrop
140033SERVER-WEBAPPFreePBX Module Administration config.php remotemod command injection attemptoffoffdrop
140034EXPLOIT-KITExploit kit embedded iframe redirection attemptoffoffoff
140037PUA-ADWAREGoogle Chrome Google Contacts extension adwareoffoffoff
140038SERVER-WEBAPPPHP unserialize var_hash use-after-free attemptoffoffoff
140039SERVER-WEBAPPFreePBX config.php unauthenticated SQL injection attemptoffoffdrop
140040SERVER-WEBAPPFreePBX config.php unauthenticated SQL injection attemptoffoffdrop
140041SERVER-WEBAPPMeinberg LANTIME NTP appliance stack buffer overflow attemptoffoffdrop
140042SERVER-WEBAPPMeinberg LANTIME NTP appliance stack buffer overflow attemptoffoffdrop
140043MALWARE-CNCWin.Ransomware.Fantom outbound connectionoffdropdrop
140044MALWARE-CNCWin.Ransomware.Fantom post encryption outbound connectionoffdropdrop
140045MALWARE-CNCWin.Ransomware.Fantom post encryption outbound connectionoffdropdrop
140046SERVER-OTHERPHP locale_accept_from_http out of bounds read attemptoffoffoff
140047SERVER-WEBAPPBelkin F9K1122 webpage buffer overflow attemptoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
340048SERVER-OTHERCisco Application Control Engine SSL handshake parsing denial of service attemptoffoffdrop
340049SERVER-OTHERCisco IOS PPTP control message response information disclosure detectedoffoffalert
Low Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
140035FILE-IDENTIFYXLSB file magic detectedoffoffoff
140036FILE-IDENTIFYXLSB file magic detectedoffoffoff

Updated Rules:

Updated rules can be found at this link.