TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

To All:

I know this does not pretain directly to the RealSecure product, however,
for those of you that are using the TopLayer AppSwitch with your IDS network
sensors, here are 10 URI filters that will stop the three worms from getting
into your network.  I am making an assumption that you positioned the
TopLayer switch just behind your connection to the public network, and in
front of your firewall.

Login to your TopLayer management utility.  
Click on policy setup, then Application Definition Library.  
Select Application tab, then web services group.  Add the following URI
filters...

Filter1
name="Code Red I"
application Definition 1 ="TCP:80"
application Definition 2= "/default.ida?NNNNN"

Filter2
name="Code Red II"
application Definition 1 ="TCP:80"
application Definition 2= "/default.ida?XXXXX"

Filter3
name="c-CMD.EXE Exploit"
application Definition 1 ="TCP:80"
application Definition 2= "/c/winnt/system32/cmd.exe"

Filter4
name="d-CMD.EXE Exploit"
application Definition 1 ="TCP:80"
application Definition 2= "/d/winnt/system32/cmd.exe"

Filter5
name="scripts-cmd.exe"
application Definition 1 ="TCP:80"
application Definition 2= "/scripts/..%"

Filter6
name="mem_bin-cmd.exe"
application Definition 1 ="TCP:80"
application Definition 2= "/_mem_bin/..%"

Filter7
name="vti_bin-cmd.exe"
application Definition 1 ="TCP:80"
application Definition 2= "/_vti_bin/..%"

Filter8
name="msadc-cmd.exe"
application Definition 1 ="TCP:80"
application Definition 2= "/msadc/..%"

Filter9
name="scripts-root.exe"
application Definition 1 = "TCP:80"
application Definition 2= "/scripts/root.exe?/c+dir"

Filter10
name="msadc-root.exe"
application Definition 1 = "TCP:80"
application Definition 2= "/msadc/root.exe?/c+dir"

Click on Policy setup, then policy set templates.  Click on Policy tab, and
select your Flow Mirror policy to your zone.
Add the URI filters to the existing policy.  Click on the policy update tab,
then click update policy now.

There is a possibility that you might have to reboot the Toplayer for it to
store the pattern into the ASIC.

Hope this helps!

Vincent Tan [MCSE, CNE, CIP]
101 Cold Harbor Dr.
Frankfort, KY 40601
502-564-1093
[EMAIL PROTECTED]
 



Reply via email to