TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! ---------------------------------------------------------------------------- To All: I know this does not pretain directly to the RealSecure product, however, for those of you that are using the TopLayer AppSwitch with your IDS network sensors, here are 10 URI filters that will stop the three worms from getting into your network. I am making an assumption that you positioned the TopLayer switch just behind your connection to the public network, and in front of your firewall. Login to your TopLayer management utility. Click on policy setup, then Application Definition Library. Select Application tab, then web services group. Add the following URI filters... Filter1 name="Code Red I" application Definition 1 ="TCP:80" application Definition 2= "/default.ida?NNNNN" Filter2 name="Code Red II" application Definition 1 ="TCP:80" application Definition 2= "/default.ida?XXXXX" Filter3 name="c-CMD.EXE Exploit" application Definition 1 ="TCP:80" application Definition 2= "/c/winnt/system32/cmd.exe" Filter4 name="d-CMD.EXE Exploit" application Definition 1 ="TCP:80" application Definition 2= "/d/winnt/system32/cmd.exe" Filter5 name="scripts-cmd.exe" application Definition 1 ="TCP:80" application Definition 2= "/scripts/..%" Filter6 name="mem_bin-cmd.exe" application Definition 1 ="TCP:80" application Definition 2= "/_mem_bin/..%" Filter7 name="vti_bin-cmd.exe" application Definition 1 ="TCP:80" application Definition 2= "/_vti_bin/..%" Filter8 name="msadc-cmd.exe" application Definition 1 ="TCP:80" application Definition 2= "/msadc/..%" Filter9 name="scripts-root.exe" application Definition 1 = "TCP:80" application Definition 2= "/scripts/root.exe?/c+dir" Filter10 name="msadc-root.exe" application Definition 1 = "TCP:80" application Definition 2= "/msadc/root.exe?/c+dir" Click on Policy setup, then policy set templates. Click on Policy tab, and select your Flow Mirror policy to your zone. Add the URI filters to the existing policy. Click on the policy update tab, then click update policy now. There is a possibility that you might have to reboot the Toplayer for it to store the pattern into the ASIC. Hope this helps! Vincent Tan [MCSE, CNE, CIP] 101 Cold Harbor Dr. Frankfort, KY 40601 502-564-1093 [EMAIL PROTECTED]
