<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IDS 4.1 PHP injection alarms in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ids-4-1-php-injection-alarms/m-p/501249#M100187</link>
    <description>&lt;P&gt;After updating one of the signature files (ver. 198) last week, I have been receiving several alarms for PHP injection coming from my site and out to Google and other addresses. None are inbound as I am not running PHP on any of our servers and they have all been patched. I've followed up on the machines in question and found them to be needing an update to the latest windows patches. They have all had updated antivirus signatures. The last straw was when my machine was flagged and I am meticulous about applying patches and anti-spyware scanning. Is there anyone else running into this? Is it a false positive?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 09:44:27 GMT</pubDate>
    <dc:creator>Loffhagen_Mark</dc:creator>
    <dc:date>2019-03-10T09:44:27Z</dc:date>
    <item>
      <title>IDS 4.1 PHP injection alarms</title>
      <link>https://community.cisco.com/t5/network-security/ids-4-1-php-injection-alarms/m-p/501249#M100187</link>
      <description>&lt;P&gt;After updating one of the signature files (ver. 198) last week, I have been receiving several alarms for PHP injection coming from my site and out to Google and other addresses. None are inbound as I am not running PHP on any of our servers and they have all been patched. I've followed up on the machines in question and found them to be needing an update to the latest windows patches. They have all had updated antivirus signatures. The last straw was when my machine was flagged and I am meticulous about applying patches and anti-spyware scanning. Is there anyone else running into this? Is it a false positive?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:44:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-4-1-php-injection-alarms/m-p/501249#M100187</guid>
      <dc:creator>Loffhagen_Mark</dc:creator>
      <dc:date>2019-03-10T09:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: IDS 4.1 PHP injection alarms</title>
      <link>https://community.cisco.com/t5/network-security/ids-4-1-php-injection-alarms/m-p/501250#M100207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have identified a false positive with signature 5638; this will be corrected in an upcoming signature update. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2005 19:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-4-1-php-injection-alarms/m-p/501250#M100207</guid>
      <dc:creator>craiwill</dc:creator>
      <dc:date>2005-11-07T19:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: IDS 4.1 PHP injection alarms</title>
      <link>https://community.cisco.com/t5/network-security/ids-4-1-php-injection-alarms/m-p/501251#M100225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for your fast reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a great day... Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2005 20:52:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-4-1-php-injection-alarms/m-p/501251#M100225</guid>
      <dc:creator>Loffhagen_Mark</dc:creator>
      <dc:date>2005-11-07T20:52:52Z</dc:date>
    </item>
  </channel>
</rss>

