<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sig Description - 5.x Platform Only in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524326#M66208</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great.&amp;nbsp; Thanks very much for clearing that up for me.&amp;nbsp; I might have gone enabling and un-retiring a bunch of unneeded signatures otherwise!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Nov 2010 05:18:43 GMT</pubDate>
    <dc:creator>mikecrowe4ICS_2</dc:creator>
    <dc:date>2010-11-08T05:18:43Z</dc:date>
    <item>
      <title>Sig Description - 5.x Platform Only</title>
      <link>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524320#M66185</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For some of the IPS-IDS signatures, the description says "&lt;STRONG&gt;signature is only available on the 5.x platform&lt;/STRONG&gt;".&amp;nbsp; Sometimes it adds "&lt;STRONG&gt;obseletes signature &amp;lt;X&amp;gt; on the 5.x platform.&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this actually mean "5.x OR LATER", such as a sensor running 7.x? Or is it really only 5.x?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example signatures stating this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=3654&amp;amp;signatureSubId=0&amp;amp;softwareVersion=6.0&amp;amp;releaseVersion=S181" target="_blank"&gt;3654/0 (SSH Gobbles Exploit)&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=4607&amp;amp;signatureSubId=6&amp;amp;softwareVersion=6.0&amp;amp;releaseVersion=S256" target="_blank"&gt;4607/6 (Deep Throat Reponse)&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=6203&amp;amp;signatureSubId=1&amp;amp;softwareVersion=6.0&amp;amp;releaseVersion=S256" target="_blank"&gt;6203/1 (sadmind directory traversal command exec)&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=9401&amp;amp;signatureSubId=2&amp;amp;softwareVersion=6.0&amp;amp;releaseVersion=S256" target="_blank"&gt;9401/2 (Back Door Y3K RAT)&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone provide clarification on this?&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:10:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524320#M66185</guid>
      <dc:creator>mikecrowe4ICS_2</dc:creator>
      <dc:date>2019-03-10T12:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Sig Description - 5.x Platform Only</title>
      <link>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524321#M66188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Those signatures are still available in version 7.0, however, some are not enabled by default.&lt;/P&gt;&lt;P&gt;All Cisco signature pack comes with default "enabled" signature, and Cisco dynamically retired, disabled signature on new signature pack accordingly, and they were documented in the release notes of each signature pack update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have double checked the 4 enquired signatures on version 7.0.1(E3), and they are not retired.&lt;/P&gt;&lt;P&gt;However, some of them are disabled (you can manually enable them if you deem that your environment might still be affected by those signatures) --&amp;gt; normally they are disabled for a reason by development team (ie: no longer applicable).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From your list,&amp;nbsp; please find the following:&lt;/P&gt;&lt;P&gt;- 3564/0 --&amp;gt; not retired, and enabled&lt;/P&gt;&lt;P&gt;- 4607/6 --&amp;gt; not retired, but disabled (4607/1 --&amp;gt; retired)&lt;/P&gt;&lt;P&gt;- 6203/1 --&amp;gt; not retired, but disabled&lt;/P&gt;&lt;P&gt;- 9401/2 --&amp;gt; not retired, but disabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To check whether a particular signature is retired or not, you can go to Cisco SIO page (under signature search):&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/security/center/search.x"&gt;http://tools.cisco.com/security/center/search.x&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Choose: Search: Signatures, keywords: the actual signature (for example: 4607), it will then give you a list of all 4607 sub-signatures.&lt;/P&gt;&lt;P&gt;Comparing the following 2 sub-signatures when you click on the actual signature name of the corresponding sub-signature:&lt;/P&gt;&lt;P&gt;4607/6 --&amp;gt; not retired (it lists "&lt;SPAN class="label1"&gt;Default Retired:&lt;/SPAN&gt;&lt;SPAN class="data1"&gt;&lt;STRONG&gt;False&lt;/STRONG&gt;")&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;4607/1 --&amp;gt; retired (it lists "&lt;SPAN class="label1"&gt;Default Retired:&lt;/SPAN&gt;&lt;SPAN class="data1"&gt;&lt;STRONG&gt;True&lt;/STRONG&gt;")&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Nov 2010 00:13:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524321#M66188</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-11-07T00:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: Sig Description - 5.x Platform Only</title>
      <link>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524322#M66194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jennifer --&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&amp;nbsp; Let me make sure I understand.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If a signature with this description (only 5.x) is available for configuration - retired or not - it can work on the 7.x platform.&amp;nbsp; Is that correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The signature default configurations also mean:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" style="width: 100%; border: 1px solid #000000;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;Status&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;TH align="center" style="background-color: #6690bc;" valign="middle"&gt;&lt;SPAN style="color: #ffffff;"&gt;&lt;STRONG&gt;Explanation&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN style="font-weight: normal;"&gt;Enabled, Not Retired&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN style="font-weight: normal;"&gt;Recommended by Cisco for use&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN style="font-weight: normal;"&gt;Disabled, Not Retired&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;SPAN style="font-weight: normal;"&gt;Not recommended for default use, but possibly useful in some environments.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: normal;"&gt;Reasons for default disable could be: no longer applicable, high resource use with low return, high probability of false positives, etc.&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN style="font-weight: normal;"&gt;Disabled, Retired&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN style="font-weight: normal;"&gt;Not recommended for default use.&amp;nbsp; Not likely needed for most environments.&amp;nbsp; Possibly obsolete due to newer signature.&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN style="font-weight: normal;"&gt;Enabled, Retired&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN style="font-weight: normal;"&gt;Not a default configuration (except for "LowMem/MedMem Retired")&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Does all of that look correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 03:07:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524322#M66194</guid>
      <dc:creator>mikecrowe4ICS_2</dc:creator>
      <dc:date>2010-11-08T03:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: Sig Description - 5.x Platform Only</title>
      <link>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524323#M66199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;I wanted to do a separate reply about the part you mentioned with the 4607 sigs/sub-sigs.&amp;nbsp; The main signature (4607/0) is default &lt;STRONG&gt;disabled&lt;/STRONG&gt; and &lt;STRONG&gt;retired&lt;/STRONG&gt;. However, the sub-signature 4607-5 is &lt;STRONG&gt;enabled&lt;/STRONG&gt; by default, and obsoletes 4607/0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In cases like this, where the main signature (/0) is disabled/retired, does the sub-signature even work?&amp;nbsp; Are the sub-signatures not actually dependent on the main signature, just grouped together?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I always thought it was a dependent relationship, but perhaps I misunderstood.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 03:26:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524323#M66199</guid>
      <dc:creator>mikecrowe4ICS_2</dc:creator>
      <dc:date>2010-11-08T03:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Sig Description - 5.x Platform Only</title>
      <link>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524324#M66202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are absolutely correct with all the statements.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 05:05:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524324#M66202</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-11-08T05:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: Sig Description - 5.x Platform Only</title>
      <link>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524325#M66205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In terms of signature with sub-signature, 0 does not mean that it is the main signature. The sub-signature always starts from the number "0". Comparing sub-signature "0" and "1" for example, they will be inspecting different things within the same signature name, hence retiring sub-signature 0 is not dependant on other active/enabled sub-signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that clears the confusion.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 05:14:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524325#M66205</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-11-08T05:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: Sig Description - 5.x Platform Only</title>
      <link>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524326#M66208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great.&amp;nbsp; Thanks very much for clearing that up for me.&amp;nbsp; I might have gone enabling and un-retiring a bunch of unneeded signatures otherwise!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 05:18:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524326#M66208</guid>
      <dc:creator>mikecrowe4ICS_2</dc:creator>
      <dc:date>2010-11-08T05:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Sig Description - 5.x Platform Only</title>
      <link>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524327#M66216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cheers, and thanks for the ratings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Nov 2010 05:20:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-description-5-x-platform-only/m-p/1524327#M66216</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-11-08T05:20:39Z</dc:date>
    </item>
  </channel>
</rss>

