<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need solution in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-solution/m-p/861074#M85017</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank q for ur response.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Jan 2008 11:51:21 GMT</pubDate>
    <dc:creator>sureshkum</dc:creator>
    <dc:date>2008-01-01T11:51:21Z</dc:date>
    <item>
      <title>Need solution</title>
      <link>https://community.cisco.com/t5/network-security/need-solution/m-p/861072#M85015</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt; Kindly provde me solution how can i implement the bellow.We are using IDS-4235 v 4.1..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Update: In addition to the domains mentioned above, more malicious domains&lt;/P&gt;&lt;P&gt;are being reported. The comple list of malicious domains is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;uhave post card DOT com &lt;/P&gt;&lt;P&gt;merrychristmasdude DOT com &lt;/P&gt;&lt;P&gt;americangreetings DOT b719 DOT cn &lt;/P&gt;&lt;P&gt;americangreetings DOT 846123 DOT cn &lt;/P&gt;&lt;P&gt;lbss DOT 3322 DOT org &lt;/P&gt;&lt;P&gt;happycards2008 DOT com  &lt;/P&gt;&lt;P&gt;newyear2008 DOT com &lt;/P&gt;&lt;P&gt;newyearcards2008 DOT com &lt;/P&gt;&lt;P&gt;newyearwithlove DOT com &lt;/P&gt;&lt;P&gt;Note: Users are advised to visit this page regularly to get the updated&lt;/P&gt;&lt;P&gt;list of malicious domains. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users are advised to implement following countermeasures:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It has been observed that the malicious domains such as mentioned above are&lt;/P&gt;&lt;P&gt;hosted by the Storm Botnet mostly using nginx/0.5.17 web server . Consider&lt;/P&gt;&lt;P&gt;blocking packets from the nginx/0.5.17 web server through Proxy or set an&lt;/P&gt;&lt;P&gt;appropriate alert/rule at IDS/IPS &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:55:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-solution/m-p/861072#M85015</guid>
      <dc:creator>sureshkum</dc:creator>
      <dc:date>2019-03-10T10:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: Need solution</title>
      <link>https://community.cisco.com/t5/network-security/need-solution/m-p/861073#M85016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can use the string.tcp engine, with the following regex:&lt;/P&gt;&lt;P&gt;[\r\n]Server[:]\x20nginx\x2f0[.]5[.]17&lt;/P&gt;&lt;P&gt;*from* #WEBPORTS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to detect the nginx webserver.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also use string.udp (setting *to* port 53) to trigger alerts on  dns requests for the domains mentioned. For the dns regex, you need to be aware that the query will take the form of:&lt;/P&gt;&lt;P&gt;length-byte -- characters -- length-byte -- characters&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So something like my.domain.com 2 characters, 6 characters, then 3 characters. Gets strung together as such:&lt;/P&gt;&lt;P&gt;\x02[Mm][Yy]\x06[Dd][Oo][Mm][Aa][Ii][Nn]\x03[Cc][Oo][Mm]&lt;/P&gt;&lt;P&gt;That is the regex to catch my.domain.com regardless of case in a dns query (UDP).&lt;/P&gt;&lt;P&gt;(note that the dots in the name, do not appear in the regex string) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Dec 2007 15:20:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-solution/m-p/861073#M85016</guid>
      <dc:creator>wsulym</dc:creator>
      <dc:date>2007-12-31T15:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: Need solution</title>
      <link>https://community.cisco.com/t5/network-security/need-solution/m-p/861074#M85017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank q for ur response.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jan 2008 11:51:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-solution/m-p/861074#M85017</guid>
      <dc:creator>sureshkum</dc:creator>
      <dc:date>2008-01-01T11:51:21Z</dc:date>
    </item>
  </channel>
</rss>

