Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2017-02-28

This SRU number: 2017-02-28-001
Previous SRU number: 2017-02-27-001

Applies to:

This SEU number: 1622
Previous SEU: 1621

Applies to:

This is the complete list of rules added in SRU 2017-02-28-001 and SEU 1622.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
141744POLICY-OTHERCisco IOS configuration transfer via TFTP detectedoffoffoff
141745FILE-MULTIMEDIAChrome Pepper Flash Player SampleCount heap overflow attemptoffdropdrop
141746FILE-MULTIMEDIAChrome Pepper Flash Player SampleCount heap overflow attemptoffdropdrop
141748SERVER-WEBAPPNetgear DGN2200 dnslookup.cgi command injection attemptoffoffdrop
141749SERVER-WEBAPPNetgear DGN2200 dnslookup.cgi command injection attemptoffoffdrop
141750SERVER-WEBAPPNetgear DGN2200 dnslookup.cgi command injection attemptoffoffdrop
141751SERVER-WEBAPPNetgear DGN2200 dnslookup.cgi command injection attemptoffoffdrop
341753FILE-OFFICETRUFFLEHUNTER TALOS-2017-0291 attack attemptoffoffdrop
341754FILE-OFFICETRUFFLEHUNTER TALOS-2017-0291 attack attemptoffoffdrop
141755INDICATOR-COMPROMISEd-link sharecenter dns-320 denial of service attemptoffoffoff
141756INDICATOR-COMPROMISEd-link sharecenter dns-320 denial of service attemptoffoffoff
141757INDICATOR-COMPROMISEd-link sharecenter dns-320 denial of service attemptoffoffoff
141758INDICATOR-COMPROMISEd-link sharecenter dns-320 denial of service attemptoffoffoff
341759FILE-OFFICETRUFFLEHUNTER TALOS-2017-0290 attack attemptoffoffdrop
341760FILE-OFFICETRUFFLEHUNTER TALOS-2017-0290 attack attemptoffoffdrop
141761POLICY-OTHERMicrosoft Word document with large docProps/core.xml fileoffoffoff
141762POLICY-OTHERMicrosoft Word document with large docProps/core.xml fileoffoffoff
141763BROWSER-IEMicrosoft Edge HandleColumnBreakOnColumnSpanningElement type confusion attemptoffdropdrop
141764BROWSER-IEMicrosoft Edge HandleColumnBreakOnColumnSpanningElement type confusion attemptoffdropdrop
341765FILE-OFFICETRUFFLEHUNTER TALOS-2017-0286 attack attemptoffoffdrop
341766FILE-OFFICETRUFFLEHUNTER TALOS-2017-0286 attack attemptoffoffdrop
141767SERVER-WEBAPPWP_Query plugin SQL injection attemptoffoffdrop
141768SERVER-WEBAPPWP_Query plugin SQL injection attemptoffoffdrop
141769SERVER-WEBAPPWP_Query plugin SQL injection attemptoffoffdrop
141770SERVER-WEBAPPWordpress NextGEN Gallery SQL injection attemptoffoffdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
141743PROTOCOL-SCADATwinCAT PLC DOS attemptoffoffdrop
141747PROTOCOL-SCADAMoxa SoftCMS webserver DOS attemptoffoffoff
141752PROTOCOL-SCADAPowerNet Twin Client DOS attemptoffoffdrop

Updated Rules:

Updated rules can be found at this link.