Sourcefire VRT Rules Update
Date: 2009-01-06
This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2.7.
The format of the file is:
sid - Message (rule group, priority)
Updated rules: 14265 <-> EXPLOIT CitectSCADA ODBC buffer overflow attempt (exploit.rules, High) 15147 <-> SPECIFIC-THREATS Microsoft IE malformed iframe buffer overflow attempt (specific-threats.rules, High) 15165 <-> BACKDOOR Pushdo client communication attempt (backdoor.rules, High) New rules: 15167 <-> POLICY Suspicious .cn dns query (policy.rules, High) 15168 <-> POLICY Suspicious .ru dns query (policy.rules, High) 15170 <-> POLICY XBOX Netflix client active (policy.rules, High) 15171 <-> POLICY XBOX Marketplace http request (policy.rules, High) 15172 <-> POLICY XBOX avatar retrieval request (policy.rules, High) 15183 <-> CHAT Yahoo messenger http link transmission attempt (chat.rules, High) 15184 <-> CHAT MSN messenger http link transmission attempt (chat.rules, High) 15185 <-> POLICY Nintendo Wii SSL Server Hello (policy.rules, High) 15186 <-> MISC Multiple vendors CUPS HPGL filter remote code execution attempt (misc.rules, High) 15187 <-> MISC Multiple vendors CUPS HPGL filter remote code execution attempt (misc.rules, High) 15188 <-> MISC Multiple vendors CUPS HPGL filter remote code execution attempt (misc.rules, High) 15189 <-> MISC Multiple vendors CUPS HPGL filter remote code execution attempt (misc.rules, High) 15190 <-> WEB-MISC Youngzsoft CCProxy CONNECT Request buffer overflow attempt (web-misc.rules, High) 15191 <-> SPECIFIC-THREATS Mozilla Firefox animated PNG processing integer overflow (specific-threats.rules, High)
