Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Rules » Need snort rule for MS05-001

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Need snort rule for MS05-001


Posted by jmh on March 16, 2005 06:03:09

Hi,

I can't seem to find a snort rule for the MS05-001 HTML Help ActiveX control exploits. I know that Enterasys Networks' Dragon IDS system has rules for it, well, they have two actually. I've tried searching this website as well as Google but can't find a Snort signature for this anywhere.

Someone must have written one. If anyone knows where it is, please could you point me in the right direction.

Many thanks,

jmh

Posted by jmh on March 16, 2005 06:36:11

The CVE code for this vulnerability is CAN-2004-1043