* Talos combines our security experts from TRAC, SecApps, and VRT teams.
This SRU number: 2017-11-28-002
Previous SRU number: 2017-11-20-002
Applies to:
This SEU number: 1763
Previous SEU: 1760
Applies to:
This is the complete list of rules modified in SRU 2017-11-28-002 and SEU 1763.
The format of the file is:
GID - SID - Rule Group - Rule Message - Policy State
The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.
The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.
Note: Unless stated explicitly, the rules are for the series of products listed above.
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 2337 | PROTOCOL-TFTP | PUT filename overflow attempt | off | off | off |
1 | 18077 | BROWSER-FIREFOX | Mozilla products CSS rendering out-of-bounds array write attempt | off | off | off |
1 | 41095 | SERVER-WEBAPP | Netgear WNR2000 authentication bypass attempt | off | off | drop |
1 | 42285 | FILE-PDF | Multiple Products malformed JP2K codestream out of bounds read attempt | off | off | drop |
1 | 42286 | FILE-PDF | Multiple Products malformed JP2K codestream out of bounds read attempt | off | off | drop |
1 | 42311 | FILE-PDF | Multiple Products malformed JP2K codestream out of bounds read attempt | off | off | drop |
1 | 42312 | FILE-PDF | Multiple Products malformed JP2K codestream out of bounds read attempt | off | off | drop |
1 | 43598 | BROWSER-IE | Microsoft Internet Explorer object type confusion remote code execution attempt | off | off | off |
1 | 43599 | BROWSER-IE | Microsoft Internet Explorer object type confusion remote code execution attempt | off | off | off |
1 | 44728 | INDICATOR-COMPROMISE | Meterpreter payload download attempt | off | off | drop |
3 | 44863 | SERVER-WEBAPP | TRUFFLEHUNTER TALOS-2017-0483 attack attempt | off | off | drop |
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 42373 | POLICY-OTHER | eicar file detected | off | off | off |
1 | 42374 | POLICY-OTHER | eicar file detected | off | off | off |
1 | 42375 | POLICY-OTHER | eicar file detected | off | off | off |
1 | 42376 | POLICY-OTHER | eicar file detected | off | off | off |
1 | 43445 | DELETED | FILE-PDF malformed embedded JPEG2000 image information disclosure attempt | |||
1 | 43446 | DELETED | FILE-PDF malformed embedded JPEG2000 image information disclosure attempt | |||
1 | 43447 | DELETED | FILE-PDF malformed embedded JPEG2000 image information disclosure attempt | |||
1 | 43448 | DELETED | FILE-PDF malformed embedded JPEG2000 image information disclosure attempt |