<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Telnet Environment Variable Disclosure &amp; AS/400 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/telnet-environment-variable-disclosure-as-400/m-p/442395#M100097</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your inquiry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Signature 5526.0 looks for non-standard or unusual telnet environment variable commands issued from the server to the telnet client.  These are not necessarily malicious.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately some server implementations may cause the current version of this signature to fire, even though the cause may be benign.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have been made aware of this behavior and are modifying 5526.0 for the next signature release to address this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the meantime you can tune this signature by disabling it or apply filters as needed to reduce false positives.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you again, and please let us know if you have any other questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Al Roethlisberger&lt;/P&gt;&lt;P&gt;IPS Signature Development Team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Aug 2005 20:44:12 GMT</pubDate>
    <dc:creator>aroethli</dc:creator>
    <dc:date>2005-08-02T20:44:12Z</dc:date>
    <item>
      <title>Telnet Environment Variable Disclosure &amp; AS/400</title>
      <link>https://community.cisco.com/t5/network-security/telnet-environment-variable-disclosure-as-400/m-p/442394#M100089</link>
      <description>&lt;P&gt;With signature update 176, I am getting alerted constantly on this sigID: 5526.  The evironment has an AS400 that the clients access using IBM's Client Access software (uses Telnet).  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yesterday, all of the passwords expired and the users were required to change their passwords.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why would this signature be triggered by this?  It is obviously a false positive, but it has freaked out the upper management...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/telnet-environment-variable-disclosure-as-400/m-p/442394#M100089</guid>
      <dc:creator>mlowery</dc:creator>
      <dc:date>2019-03-10T09:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: Telnet Environment Variable Disclosure &amp; AS/400</title>
      <link>https://community.cisco.com/t5/network-security/telnet-environment-variable-disclosure-as-400/m-p/442395#M100097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your inquiry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Signature 5526.0 looks for non-standard or unusual telnet environment variable commands issued from the server to the telnet client.  These are not necessarily malicious.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately some server implementations may cause the current version of this signature to fire, even though the cause may be benign.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have been made aware of this behavior and are modifying 5526.0 for the next signature release to address this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the meantime you can tune this signature by disabling it or apply filters as needed to reduce false positives.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you again, and please let us know if you have any other questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Al Roethlisberger&lt;/P&gt;&lt;P&gt;IPS Signature Development Team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2005 20:44:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/telnet-environment-variable-disclosure-as-400/m-p/442395#M100097</guid>
      <dc:creator>aroethli</dc:creator>
      <dc:date>2005-08-02T20:44:12Z</dc:date>
    </item>
  </channel>
</rss>

