Bug in community ruleset rule (sid 975)

Noah Dietrich <[email protected]>
Newsgroups gmane.comp.security.ids.snort.sigs
Message-ID <CA+N0JEwPf7VxN79bwsRrxb_rqEz5jGhnQMH=pLEmbOhLGo0qkg@mail.gmail.com>
While parsing the community-rules file, i found an incorrectly-formatted
reference:url:
the url is listed as:
  support.microsoft.com/default.aspx?scid=kb*\;*EN-US*\;*q188806
(you'll note the *\;* here which seems incorrect)

The whole Rule is:
# alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (
msg:"SERVER-IIS Alternate Data streams ASP file access attempt";
flow:to_server,established; http_uri; content:".asp|3A 3A 24|DATA",nocase;
metadata:ruleset community; service:http; reference:bugtraq,149;
reference:cve,1999-0278; reference:nessus,10362; reference:url,
support.microsoft.com/default.aspx?scid=kb\;EN-US\;q188806;
classtype:web-application-attack; sid:975; rev:26; )

Also: the Microsoft KB link is no longer available (since this cve is for
NT4 i think). a valid URL for this CVE is:
https://docs.microsoft.com/en-us/security-updates/securitybulletins/1998/ms98-003


However, I'm not sure how useful it is to look for a 20 year old
vulnerability on software that is this old.

Noah

_______________________________________________
Snort-sigs mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.