<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sig5813 Vector Markup Language Vulnerability - False Positives? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sig5813-vector-markup-language-vulnerability-false-positives/m-p/630391#M92257</link>
    <description>&lt;P&gt;Seeing alot of activity with regard to this new vulnerability.  The sensor is denying packets.  The html is usually in the "Context" of the packet.  Has anyone seen false positives for this signature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;html xmlns:v="urn:schemas-microsoft-com:vm&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 10:15:06 GMT</pubDate>
    <dc:creator>enelson</dc:creator>
    <dc:date>2019-03-10T10:15:06Z</dc:date>
    <item>
      <title>Sig5813 Vector Markup Language Vulnerability - False Positives?</title>
      <link>https://community.cisco.com/t5/network-security/sig5813-vector-markup-language-vulnerability-false-positives/m-p/630391#M92257</link>
      <description>&lt;P&gt;Seeing alot of activity with regard to this new vulnerability.  The sensor is denying packets.  The html is usually in the "Context" of the packet.  Has anyone seen false positives for this signature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;html xmlns:v="urn:schemas-microsoft-com:vm&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:15:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig5813-vector-markup-language-vulnerability-false-positives/m-p/630391#M92257</guid>
      <dc:creator>enelson</dc:creator>
      <dc:date>2019-03-10T10:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Sig5813 Vector Markup Language Vulnerability - False Positiv</title>
      <link>https://community.cisco.com/t5/network-security/sig5813-vector-markup-language-vulnerability-false-positives/m-p/630392#M92258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to confirm is this subsig 5813-0? Or another subsignature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you be able to provide the triggering packet through a produce verbose alert or even better a traffic sample?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 30 Sep 2006 00:35:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig5813-vector-markup-language-vulnerability-false-positives/m-p/630392#M92258</guid>
      <dc:creator>jlimbo</dc:creator>
      <dc:date>2006-09-30T00:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: Sig5813 Vector Markup Language Vulnerability - False Positiv</title>
      <link>https://community.cisco.com/t5/network-security/sig5813-vector-markup-language-vulnerability-false-positives/m-p/630393#M92259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Over 2200 alerts since the signature was intruduced.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are ALL subsig 0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use Security Monitor to display our events.&lt;/P&gt;&lt;P&gt;Will Verbose alerts show in Secmon under ALERT DETAILS after enabled for this signature?  (evIdsalert)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 30 Sep 2006 13:01:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig5813-vector-markup-language-vulnerability-false-positives/m-p/630393#M92259</guid>
      <dc:creator>enelson</dc:creator>
      <dc:date>2006-09-30T13:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: Sig5813 Vector Markup Language Vulnerability - False Positiv</title>
      <link>https://community.cisco.com/t5/network-security/sig5813-vector-markup-language-vulnerability-false-positives/m-p/630394#M92260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a bug in Ciscoworks VMS Security Monitor, Secmon will always display subsig 0. The bug does not show the proper subsig. To determine the correct subsig you will need to obtain the event from the sensor itself using "show events" command.&lt;/P&gt;&lt;P&gt;M&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 30 Sep 2006 20:04:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig5813-vector-markup-language-vulnerability-false-positives/m-p/630394#M92260</guid>
      <dc:creator>mkirbyii</dc:creator>
      <dc:date>2006-09-30T20:04:47Z</dc:date>
    </item>
  </channel>
</rss>

