09-18-2012 08:53 AM
Is there a signature for the new IE 0 day yet?
There is a metasploit module out so.. that means there a working exploit 'in the wild' to base a sig on...
Normally I find the CVE and then look it up in Threat Vault which will give me the threats version number (eg: 839-1155) that I can confirm is installed on my FW.
However this time, I cant find a CVE number so Im asking here.
09-19-2012 01:55 AM
update 330-1516 available now
09-19-2012 02:08 AM
Thanks, downloaded and installed just fine !
09-19-2012 06:46 AM
thanks for the update. Anyway, I've got a question: Why are there two threat-ids obviously covering the same vulnerability? How do they differ and how do I have to interpret the different default actions?
The background of my question is that I'm not really sure what will happen if the vulnerability protection profile is configured to apply the "default" action for all "critical" threats --> will it execute "reset-client" or only "alert" or both?
PS: Sorry for asking, I'm aware that maybe this is a (dumb) newbie question...
09-19-2012 12:49 PM
My current guess is that both will fire since they have the same info:
so first it will reset-client and then it will log (alert)... but that sounds odd because if default action is reset-client then logging is included in that - isnt it?
Or if someone wants just to monitor/log if/when such packets are seen then they would set this manually to alert wouldnt they?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!