<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 5477 / 2 - Possible Heap... How did you handle it? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110308#M78865</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To enable Cisco IOS URL filtering, use the urlfilter command in policy-map-class configuration mode. To disable URL filtering, use the no form of this command. &lt;/P&gt;&lt;P&gt;urlfilter parameter-map-name &lt;/P&gt;&lt;P&gt;no urlfilter parameter-map-name&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Sep 2008 15:06:29 GMT</pubDate>
    <dc:creator>sadbulali</dc:creator>
    <dc:date>2008-09-09T15:06:29Z</dc:date>
    <item>
      <title>5477 / 2 - Possible Heap... How did you handle it?</title>
      <link>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110307#M78864</link>
      <description>&lt;P&gt;Im sure everyone has figured out what to do with this signature. It fires a lot due to the code (ad revolver) used on some high traffic websites like lanebryant. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Intelli Shield recommends we filter out webservers hosting non-ASCII web pages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How am I supposed to know what webservers are hosting non-ASCII web pages? How can you filter this? I hate to disable this sig because it represents a high risk exploit, but so many false positives.. what have you done with 5477 - 2 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Description of 5477 / 2:&lt;/P&gt;&lt;P&gt;This signature fires on detecting unicode-encoded escape sequences in HTML pages. This is a common way to load values into memory and is frequently used in buffer overflow exploits. While the use of unescape() does not indicate anything malicious has occurred, further investigation may be warranted. This signature is also a component of META signature 5556-4. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recommended Filters&lt;/P&gt;&lt;P&gt;Filter webservers hosting non-ASCII web pages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Benign Triggers&lt;/P&gt;&lt;P&gt;Benign triggers have been identified with HTML pages represented in non-ASCII characters. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:17:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110307#M78864</guid>
      <dc:creator>kutukutu9</dc:creator>
      <dc:date>2019-03-10T11:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: 5477 / 2 - Possible Heap... How did you handle it?</title>
      <link>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110308#M78865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To enable Cisco IOS URL filtering, use the urlfilter command in policy-map-class configuration mode. To disable URL filtering, use the no form of this command. &lt;/P&gt;&lt;P&gt;urlfilter parameter-map-name &lt;/P&gt;&lt;P&gt;no urlfilter parameter-map-name&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Sep 2008 15:06:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110308#M78865</guid>
      <dc:creator>sadbulali</dc:creator>
      <dc:date>2008-09-09T15:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: 5477 / 2 - Possible Heap... How did you handle it?</title>
      <link>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110309#M78866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In Sig release 354 Cisco has removed the 'Produce Alert' from this signature:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S354 Release Notes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5.x, 6.x5477.2 Possible Heap Payload Construction STRING-TCP High True &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5477.2 "produce-alert" event-action was removed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just upgrade to reduce the noise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Sep 2008 07:26:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110309#M78866</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-09-13T07:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: 5477 / 2 - Possible Heap... How did you handle it?</title>
      <link>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110310#M78867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That makes me wonder what good is it to leave a signature enabled but not producing alerts or any other event for that matter? Wasting CPU yes?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Sep 2008 11:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110310#M78867</guid>
      <dc:creator>kutukutu9</dc:creator>
      <dc:date>2008-09-15T11:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: 5477 / 2 - Possible Heap... How did you handle it?</title>
      <link>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110311#M78868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried replying earlier, not sure if it's going to make it;-)  That signature is part of a META signature 5556-4, so removing the action prevents it from firing on its own (we disabled a long time ago due to high false positive rate).  If you disable/retire it, you'll have to deal with 5556-4 as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Sep 2008 12:17:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110311#M78868</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2008-09-15T12:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: 5477 / 2 - Possible Heap... How did you handle it?</title>
      <link>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110312#M78869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The signature is still used as a meta component in several signatures.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Sep 2008 14:20:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110312#M78869</guid>
      <dc:creator>craiwill</dc:creator>
      <dc:date>2008-09-15T14:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: 5477 / 2 - Possible Heap... How did you handle it?</title>
      <link>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110313#M78870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean more than just the one indicated?  I don't see how that's possible because intellishield.cisco.com only mentions the one (I laugh in Cisco's general direction). I'm not aware of any way to list which META signatures a component sig is part of, so perhaps you could list the relevant META sigs here?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Sep 2008 14:41:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110313#M78870</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2008-09-15T14:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: 5477 / 2 - Possible Heap... How did you handle it?</title>
      <link>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110314#M78871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'll update the documentation shortly. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This signature is also a component of the following META signatures: 5556-4, 6279-0, 6297-0, 6298-0, 6403-0, 6408-0, 6409-0, 6410-0, 6524-0, 6534-0, 6535-0, 6536-0, 6544-0, 6794-0, 6795-0, 6930-0, 6940-0, 6942-0, 6988-0, 6990-0, 7206-0, 7209-0, 7229-0 and 7237-0.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Sep 2008 17:31:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5477-2-possible-heap-how-did-you-handle-it/m-p/1110314#M78871</guid>
      <dc:creator>craiwill</dc:creator>
      <dc:date>2008-09-16T17:31:30Z</dc:date>
    </item>
  </channel>
</rss>

