ThreatID 33542 and Facebook

Reply
Highlighted
L1 Bithead

ThreatID 33542 and Facebook

I'm seeing a lot of alerts in the last couple days for threatID 33542 when users are visiting facebook via http://www.facebook.com/

Could this be a false positive?  Anyone else seeing a jump in this threat?

Tnx, Tom

Highlighted
L0 Member

Re: ThreatID 33542 and Facebook

We are seeing the same thing over here. Every source IP seems to be Akami CDN servers that serve Facebook from our ISP, so I'm really thinking this is a false positive.

app: facebook-base
proto: tcp
threatid: Mozilla Firefox GeckoActiveXObject Method Denial of Service Vulnerability(33542)

Highlighted
L6 Presenter

Re: ThreatID 33542 and Facebook

Some more info:

http://wwapps.paloaltonetworks.com/ThreatVault/

http://wwapps.paloaltonetworks.com/ThreatVault/Home.aspx/ThreatDetail/33542

Attack Name: Mozilla Firefox GeckoActiveXObject Method Denial of Service Vulnerability

Description: Mozilla Firefox is prone to a denial of service vulnerability while parsing certain crafted HTTP responses.The vulnerability is due to the lack of proper checks on GeckoActiveXObject Method in the HTTP response, leading to an exploitable denial of service vulnerability. An attacker could exploit the vulnerability by sending a crafted HTTP response. A successful attack could lead to denial of service with the privileges of the current logged-in user.

Threat ID: 36871

References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3803

Severity: high

Category: dos

Highlighted
L4 Transporter

Re: ThreatID 33542 and Facebook

Also seeing the same high count of events.  Not all events are stemming from workstations that have Firefox installed.

-mike

Highlighted
L4 Transporter

Re: ThreatID 33542 and Facebook

There have been some changes made to Facebook code that is causing some false positives to be triggered for this ThreatID. We are working to address this issue in next week's update.

-Stefan

Highlighted
Not applicable

Re: ThreatID 33542 and Facebook

Is there an ETA on the patch / update?

Highlighted
L3 Networker

Re: ThreatID 33542 and Facebook

Would think/hope that it would be fixed in the weekly content (wednesday AM CET, tuesday PM USA) Update. Cheers.

Highlighted
Not applicable

Re: ThreatID 33542 and Facebook

Hello All,

According to the result of our lab test,

it may be fixed with the latest content ver.308-1390.

- there is not this fix on release note though...

Tomoyuki Komure

Highlighted
Not applicable

Re: ThreatID 33542 and Facebook

Yes, we also have updated the content to 308-1390, and the alerts have stopped. Thanks!

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!