* Talos combines our security experts from TRAC, SecApps, and VRT teams.
This SRU number: 2017-11-28-002
Previous SRU number: 2017-11-20-002
Applies to:
This SEU number: 1763
Previous SEU: 1760
Applies to:
This is the complete list of rules added in SRU 2017-11-28-002 and SEU 1763.
The format of the file is:
GID - SID - Rule Group - Rule Message - Policy State
The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.
The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.
Note: Unless stated explicitly, the rules are for the series of products listed above.
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 44991 | BROWSER-FIREFOX | Mozilla products CSS rendering out-of-bounds array write attempt | off | off | off |
1 | 44992 | SERVER-WEBAPP | ManageEngine ServiceDesk Plus policy bypass attempt | off | off | off |
1 | 44993 | SERVER-WEBAPP | ManageEngine ServiceDesk Plus policy bypass attempt | off | off | off |
1 | 44994 | SERVER-WEBAPP | ManageEngine ServiceDesk Plus policy bypass attempt | off | off | off |
1 | 44995 | SERVER-WEBAPP | ManageEngine ServiceDesk Plus policy bypass attempt | off | off | off |
1 | 44996 | SERVER-WEBAPP | ManageEngine ServiceDesk Plus policy bypass attempt | off | off | off |
1 | 44997 | MALWARE-CNC | Legend irc bot cnc attempt | off | alert | drop |
1 | 44998 | MALWARE-CNC | Legend irc bot cnc attempt | off | alert | drop |
1 | 44999 | SERVER-WEBAPP | Ruby on Rails file inclusion attempt | off | off | off |
1 | 45000 | SERVER-WEBAPP | Ruby on Rails file inclusion attempt | off | off | off |
1 | 45002 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
1 | 45003 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
1 | 45004 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
1 | 45005 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
1 | 45006 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
1 | 45007 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
1 | 45008 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
1 | 45009 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
1 | 45010 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
1 | 45011 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
1 | 45012 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
1 | 45013 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
1 | 45014 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
1 | 45015 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
1 | 45016 | FILE-OTHER | Jackson databind deserialization remote code execution attempt | off | off | drop |
3 | 45017 | FILE-IMAGE | TRUFFLEHUNTER TALOS-2017-0497 attack attempt | off | off | drop |
3 | 45018 | FILE-IMAGE | TRUFFLEHUNTER TALOS-2017-0497 attack attempt | off | off | drop |
3 | 45019 | FILE-IMAGE | TRUFFLEHUNTER TALOS-2017-0490 attack attempt | off | off | drop |
3 | 45020 | FILE-IMAGE | TRUFFLEHUNTER TALOS-2017-0490 attack attempt | off | off | drop |
3 | 45021 | FILE-IMAGE | TRUFFLEHUNTER TALOS-2017-0491 attack attempt | off | off | drop |
3 | 45022 | FILE-IMAGE | TRUFFLEHUNTER TALOS-2017-0491 attack attempt | off | off | drop |
1 | 45023 | FILE-PDF | Adobe Acrobat out of bound read exploitation attempt | off | off | off |
1 | 45024 | FILE-PDF | Adobe Acrobat out of bound read exploitation attempt | off | off | off |
3 | 45025 | FILE-IMAGE | TRUFFLEHUNTER TALOS-2017-0489 attack attempt | off | off | drop |
3 | 45026 | FILE-IMAGE | TRUFFLEHUNTER TALOS-2017-0489 attack attempt | off | off | drop |
1 | 45027 | FILE-PDF | Adobe Acrobat out of bound read exploitation attempt | off | off | off |
1 | 45028 | FILE-PDF | Adobe Acrobat out of bound read exploitation attempt | off | off | off |
1 | 45031 | FILE-OTHER | Adobe Acrobat JPEG2000 out of bounds buffer overflow attempt | off | off | drop |
1 | 45032 | FILE-OTHER | Adobe Acrobat JPEG2000 out of bounds buffer overflow attempt | off | off | drop |
3 | 45033 | FILE-IMAGE | TRUFFLEHUNTER TALOS-2017-0488 attack attempt | off | off | drop |
3 | 45034 | FILE-IMAGE | TRUFFLEHUNTER TALOS-2017-0488 attack attempt | off | off | drop |
1 | 45035 | FILE-PDF | Adobe Acrobat Reader Annotation use after free attempt | off | drop | drop |
1 | 45036 | FILE-PDF | Adobe Acrobat Reader Annotation use after free attempt | off | drop | drop |
1 | 45037 | SERVER-WEBAPP | Joomla LDAP authentication plugin information disclosure exploitation attempt | off | off | drop |
1 | 45038 | SERVER-WEBAPP | Joomla LDAP authentication plugin information disclosure exploitation attempt | off | off | drop |
1 | 45039 | SERVER-WEBAPP | Joomla LDAP authentication plugin information disclosure exploitation attempt | off | off | drop |
1 | 45040 | FILE-PDF | Adobe Acrobat Reader Annotation use after free attempt | off | off | drop |
1 | 45041 | FILE-PDF | Adobe Acrobat Reader Annotation use after free attempt | off | drop | drop |
1 | 45042 | BROWSER-OTHER | Adobe Acrobat Pro WebCapture information disclosure attempt | off | off | off |
1 | 45043 | BROWSER-OTHER | Adobe Acrobat Pro WebCapture information disclosure attempt | off | off | off |
1 | 45044 | FILE-PDF | Adobe Reader out of bounds memory access violation attempt | off | off | drop |
1 | 45045 | FILE-PDF | Adobe Reader out of bounds memory access violation attempt | off | off | drop |
1 | 45046 | SERVER-OTHER | Exim malformed BDAT code execution attempt | off | drop | drop |
3 | 45047 | FILE-IMAGE | TRUFFLEHUNTER TALOS-2017-0499 attack attempt | off | off | drop |
3 | 45048 | FILE-IMAGE | TRUFFLEHUNTER TALOS-2017-0499 attack attempt | off | off | drop |
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 45001 | SERVER-WEBAPP | Netgear WNR2000 information leak attempt | off | off | drop |
3 | 45049 | SERVER-WEBAPP | TRUFFLEHUNTER TALOS-2017-0492 attack attempt | off | off | off |
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 45029 | FILE-PDF | JPEG2000 image coding style default information disclosure attempt | off | off | off |
1 | 45030 | FILE-PDF | JPEG2000 image coding style default information disclosure attempt | off | off | off |
Updated rules can be found at this link.