vulnerability id 31327

Reply
Highlighted
L4 Transporter

vulnerability id 31327

Hello,

 

Start 10/13,  I have been getting medium threat alert for vulnerability id 31327 (Attempted Antivirus Detection Bypass via Malformed ZIP Archive).  I beleve it is my iOS devices connect to apple store to download app updates.  Anyone else sees these?  It is using the action is reset-both, but I still able to complete the download and install without any problem.  

 

Screen Shot 2016-10-22 at 7.13.09 AM.png

Highlighted
L7 Applicator

I have the same problem.  I ended up making a "permit itunes-base" security policy that points to a vulnerability protection profile with that specific signature disabled.  

Highlighted
L4 Transporter

@jvalentine Thanks for confirming it.  The strange part that I don't understand is the app update is still successful.  Also, the file that is alerting are all from Apple Itune app store.  I will think " I can trust Apple?!?".    I just want to know if this is a false positive or something real.

 

E

Highlighted
L7 Applicator

I'm willing to bet it's a false-positive, because it's Apple, right?  I'd recommend opening a case with TAC.  

Highlighted
L4 Transporter

Reply from TAC

 

We have released the modification to signature  (TID: 31327/ Attempted Antivirus Detection Bypass via Malformed ZIP Archive) in content version 646 on 12/13/2016.

Highlighted
L7 Applicator

My firewall installed that content version yesterday, but today I'm still getting false-positive hits for 31327 via itunes-base.  I count 15 hits just today.  Looks like the signature needs some additional work still.  

Highlighted
L4 Transporter

Same here, TAC told me to use CLI to reinstall the 646 update again.  If it still does not work, perform another packet captures and update the case.   I don't understand why TAC can't test it?  It is just iOS / Itune download app update from apple itune store.  It is easy to replicate.

 

E

 

Highlighted
L4 Transporter

The signature is disabed on 650-3771.  According to TAC, there are too many false positive.  Not sure what is the future plan of this specific signature will be.

 

E

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!