<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks guys.  We've decided in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936178#M43670</link>
    <description>&lt;P&gt;Thanks guys. &amp;nbsp;We've decided to disable this signature for right now. &amp;nbsp;ali.imran1, I'm sure you're right regarding Cisco retiring it in the next update. &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Aug 2016 12:19:11 GMT</pubDate>
    <dc:creator>Charles Carmichael</dc:creator>
    <dc:date>2016-08-04T12:19:11Z</dc:date>
    <item>
      <title>Problem with Signature Update 932</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936175#M43665</link>
      <description>&lt;P&gt;Hey everyone. &amp;nbsp;Signature update 932 was automatically applied to my IPS today at 12:16. &amp;nbsp;At 12:17, I started to get a ton of Adobe Acrobat Reader Memory Corruption hits on signature 7615. &amp;nbsp;I'm assuming this is a bug. &amp;nbsp;Is anyone else experiencing the same thing? &amp;nbsp;The alerts are continuing to roll in.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:39:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936175#M43665</guid>
      <dc:creator>Charles Carmichael</dc:creator>
      <dc:date>2019-03-10T13:39:50Z</dc:date>
    </item>
    <item>
      <title>Hi.Everyone.</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936176#M43667</link>
      <description>&lt;P&gt;&lt;SPAN class="" lang="en"&gt;&lt;SPAN&gt;Hi.Everyone.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN id="result_box" class="" lang="en"&gt;&lt;SPAN&gt;I also&lt;/SPAN&gt; &lt;SPAN&gt;you are experiencing this problem&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I would like to&lt;/SPAN&gt; &lt;SPAN&gt;quickly&lt;/SPAN&gt; &lt;SPAN class=""&gt;answer&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="" lang="en"&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="" lang="en"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Arial','sans-serif';"&gt;SigId&lt;/SPAN&gt;:7615&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="" lang="en"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Arial','sans-serif';"&gt;SubSigId&lt;/SPAN&gt;:0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="" lang="en"&gt;&lt;SPAN style="font-size: 10.5pt; font-family: 'Arial','sans-serif';"&gt;SigName&lt;/SPAN&gt;:&lt;SPAN style="font-size: 10.5pt; font-family: 'Arial','sans-serif';"&gt;&amp;nbsp;Adobe Acrobat Reader Memory Corruption&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 00:26:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936176#M43667</guid>
      <dc:creator>UBE_IPSinfo</dc:creator>
      <dc:date>2016-08-04T00:26:19Z</dc:date>
    </item>
    <item>
      <title>Yes, you are right 7615 is</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936177#M43669</link>
      <description>&lt;P&gt;Yes, you are right 7615 is generating too much false positives in our environment too.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We have retired this&amp;nbsp;signature and i can bet that you are gonna see in the next signature update that CISCO is also going to retire it as well.&lt;/P&gt;
&lt;P&gt;We have already experienced that the QA of IPS signatures at Cisco is really bad. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 12:01:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936177#M43669</guid>
      <dc:creator>ali.imran1</dc:creator>
      <dc:date>2016-08-04T12:01:42Z</dc:date>
    </item>
    <item>
      <title>Thanks guys.  We've decided</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936178#M43670</link>
      <description>&lt;P&gt;Thanks guys. &amp;nbsp;We've decided to disable this signature for right now. &amp;nbsp;ali.imran1, I'm sure you're right regarding Cisco retiring it in the next update. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 12:19:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936178#M43670</guid>
      <dc:creator>Charles Carmichael</dc:creator>
      <dc:date>2016-08-04T12:19:11Z</dc:date>
    </item>
    <item>
      <title>Same on our side. Many many</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936179#M43671</link>
      <description>&lt;P&gt;Same on our side. Many many alerts.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 15:57:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936179#M43671</guid>
      <dc:creator>leandro10</dc:creator>
      <dc:date>2016-08-04T15:57:48Z</dc:date>
    </item>
    <item>
      <title>We also have been</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936180#M43673</link>
      <description>&lt;P&gt;We also have been experiencing a huge number of alerts and the IPS was setup to shun the IP. This caused many sites to be unreachable. I set up a rule to not shun these alerts, but to drop the packet in line.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We also had some alerts from our own web server. We traced these alerts to the pdf that was being served and ran these pdf's threw &lt;A href="https://community.cisco.com/www.VirusTotal.com" target="_blank"&gt;www.VirusTotal.com&lt;/A&gt;, no virus was found in these pdf's. From our internal standpoint this is a false positive.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 16:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936180#M43673</guid>
      <dc:creator>gm-douglas</dc:creator>
      <dc:date>2016-08-04T16:19:07Z</dc:date>
    </item>
    <item>
      <title>Douglas, run the pdf though</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936181#M43674</link>
      <description>&lt;P&gt;Douglas, run the pdf though this site.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It does a real time analysis of the file.&lt;/P&gt;
&lt;P&gt;https://www.hybrid-analysis.com/&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Let us know the results, it might help us validate the signature. VirusTotal is just based on reputation.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 16:27:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936181#M43674</guid>
      <dc:creator>leandro10</dc:creator>
      <dc:date>2016-08-04T16:27:06Z</dc:date>
    </item>
    <item>
      <title>Can Cisco please confirm this</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936182#M43677</link>
      <description>&lt;P&gt;Can Cisco please confirm this is a bug? We've also been getting slammed by this since the signature updates around midnight.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 18:10:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936182#M43677</guid>
      <dc:creator>Joshua Schroth</dc:creator>
      <dc:date>2016-08-04T18:10:56Z</dc:date>
    </item>
    <item>
      <title>I'm assuming that users are</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936183#M43678</link>
      <description>&lt;P&gt;I'm assuming that users are also experiencing issues with their Adobe Acrobat Readers because the packets are being dropped by the IPS.&lt;/P&gt;
&lt;P&gt;Please fix or remove the sig.ID 7615/0 ....... ASAP, if you please.&lt;/P&gt;
&lt;P&gt;-Will&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 19:36:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936183#M43678</guid>
      <dc:creator>wgorman</dc:creator>
      <dc:date>2016-08-04T19:36:33Z</dc:date>
    </item>
    <item>
      <title>The pdf's came up clean on</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936184#M43679</link>
      <description>&lt;P&gt;The pdf's came up clean on that other site also. One of them was last modified in Aug of 2012. These are false positives.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 21:27:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936184#M43679</guid>
      <dc:creator>gm-douglas</dc:creator>
      <dc:date>2016-08-04T21:27:49Z</dc:date>
    </item>
    <item>
      <title>Hi,EveryOne.</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936185#M43680</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,EveryOne.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Last&amp;nbsp;day,&amp;nbsp;I&amp;nbsp;was carried out&lt;/SPAN&gt; &lt;SPAN&gt;the invalidation&lt;/SPAN&gt; &lt;SPAN&gt;of the relevant&lt;/SPAN&gt; &lt;SPAN&gt;signatures&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Also,&lt;/SPAN&gt; &lt;SPAN&gt;S933&lt;/SPAN&gt; &lt;SPAN&gt;was released at 4:00(JST)&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Saw&lt;/SPAN&gt; &lt;SPAN&gt;the release notes&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt; &lt;SPAN&gt;it seems&lt;/SPAN&gt; &lt;SPAN&gt;to be no&lt;/SPAN&gt; &lt;SPAN&gt;correspondence&lt;/SPAN&gt; &lt;SPAN&gt;of&lt;/SPAN&gt; &lt;SPAN&gt;Cisco.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 23:22:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936185#M43680</guid>
      <dc:creator>UBE_IPSinfo</dc:creator>
      <dc:date>2016-08-04T23:22:18Z</dc:date>
    </item>
    <item>
      <title>S933 did not fix the issue. I</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936186#M43681</link>
      <description>&lt;P&gt;S933 did not fix the issue. I re-enabled that signature and it's still firing. Disabled the signature again until Cisco fixes this...&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 13:26:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936186#M43681</guid>
      <dc:creator>Joshua Schroth</dc:creator>
      <dc:date>2016-08-05T13:26:36Z</dc:date>
    </item>
    <item>
      <title>No update from Cisco yet? ok.</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936187#M43682</link>
      <description>&lt;P&gt;No update from Cisco yet? ok.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 15:51:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936187#M43682</guid>
      <dc:creator>leandro10</dc:creator>
      <dc:date>2016-08-08T15:51:38Z</dc:date>
    </item>
    <item>
      <title>We are also receiving a high</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936188#M43683</link>
      <description>&lt;P&gt;We are also receiving a high number of alerts for this signature, but only when users are trying to access an internal website that displays images.&amp;nbsp; There are no PDFs involved.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2016 17:58:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-signature-update-932/m-p/2936188#M43683</guid>
      <dc:creator>CLCswagner</dc:creator>
      <dc:date>2016-08-08T17:58:58Z</dc:date>
    </item>
  </channel>
</rss>

