<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The string is apparently in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/malware-backdoor-wow-23-runtime-detection/m-p/3070896#M18507</link>
    <description>&lt;P&gt;The string is apparently something found in the WOW 23 trojan horse program network communications. &amp;nbsp;The rule is only enabled today in the Security Over Connectivity rule set which means it probably has more false positives. &amp;nbsp;The real question is do you need a 10 year old Snort rule enabled? &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Jun 2017 03:02:58 GMT</pubDate>
    <dc:creator>atatistc</dc:creator>
    <dc:date>2017-06-01T03:02:58Z</dc:date>
    <item>
      <title>MALWARE-BACKDOOR wow 23 runtime detection</title>
      <link>https://community.cisco.com/t5/network-security/malware-backdoor-wow-23-runtime-detection/m-p/3070895#M18487</link>
      <description>&lt;P&gt;Please explain this rule how it works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it detecting the alert based only on the content &lt;STRONG&gt;&lt;U&gt;"R|00|23"&lt;/U&gt;&lt;/STRONG&gt;. &amp;nbsp;Please explain how to figure this out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;IPS Rule:&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET any (msg:"MALWARE-BACKDOOR wow 23 runtime detection"; flow:to_client,established; &lt;STRONG&gt;&lt;U&gt;content:"R|00|23";&lt;/U&gt;&lt;/STRONG&gt; depth:4; detection_filter:track by_src, count 3, seconds 300; metadata:policy security-ips alert; reference:url,www.megasecurity.org/trojans/0_9/23/23_0.3.html; classtype:trojan-activity; sid:10184; rev:6; )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2017 14:49:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-backdoor-wow-23-runtime-detection/m-p/3070895#M18487</guid>
      <dc:creator>ramachandran.gunasekaran</dc:creator>
      <dc:date>2017-05-29T14:49:02Z</dc:date>
    </item>
    <item>
      <title>The string is apparently</title>
      <link>https://community.cisco.com/t5/network-security/malware-backdoor-wow-23-runtime-detection/m-p/3070896#M18507</link>
      <description>&lt;P&gt;The string is apparently something found in the WOW 23 trojan horse program network communications. &amp;nbsp;The rule is only enabled today in the Security Over Connectivity rule set which means it probably has more false positives. &amp;nbsp;The real question is do you need a 10 year old Snort rule enabled? &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 03:02:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-backdoor-wow-23-runtime-detection/m-p/3070896#M18507</guid>
      <dc:creator>atatistc</dc:creator>
      <dc:date>2017-06-01T03:02:58Z</dc:date>
    </item>
  </channel>
</rss>

