Cisco IOS Malicious IPV4 Packet Sequence Denial Of Service Vulnerability Signature
Jensenne Roculan <[email protected]> Fri, 18 Jul 2003 09:38:07 -0600 (MDT)
| Newsgroups | gmane.comp.security.aris |
|---|---|
| Message-ID | <[email protected]> |
Hi there, The DeepSight Threat Analyst Team have created a series of Snort signatures for the recently announced denial of service vulnerability in Cisco IOS, as detailed in the following advisory: http://www.cisco.com/warp/public/707/cisco-sa-20030717-blocked.shtml It should be noted that these signatures may be inappropriate for networks that see these uncommon IP protocol types for legitimate reasons on a regular basis. Signatures ---------- alert ip any any -> any any \ (msg:"Suspicious Traffic - IP Protocol 53 (SWIPE)"; \ ip_proto: 53; \ classtype:misc-activity; rev:1;) alert ip any any -> any any \ (msg:"Suspicious Traffic - IP Protocol 55 (IP Mobility)"; \ ip_proto: 55; \ classtype:misc-activity; rev:1;) alert ip any any -> any any \ (msg:"Suspicious Traffic - IP Protocol 77 (Sun ND)"; \ ip_proto: 77; \ classtype:misc-activity; rev:1;) alert ip any any -> any any \ (msg:"Suspicious Traffic - IP Protocol 103 (PIM)"; \ ip_proto: 103; \ classtype:misc-activity; rev:1;) False Positives --------------- In the event that the aforementioned IP protocols are being used legitimately within a network, these signatures will false positive on such traffic. These signatures are most effective if deployed in an environment that does not expect to see traffic containing any of these uncommon IP protocols. Jensenne Roculan Symantec Corporation http://www.symantec.com (403) 261-5431