<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IDS Sig 4058 question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ids-sig-4058-question/m-p/400361#M98156</link>
    <description>&lt;P&gt;Sig 4058 subsig 1 (IDS Signature UPnP LOCATION Overflow) was triggered on one of our sensors as what appears to me to be a false positive. From what I understand, the sig fires on a payload of 116 characters or more to service port 5000 TCP.  The destination port was tcp 5000 and the context of the alert triggered was:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://64.4.18.250/cgi-bin/getmsg/IMG_0091.JPG?curmbox=F000000004&amp;amp;a=46c002caa67737093a99d6df1e381c77&amp;amp;msg=MSG1114736378.24&amp;amp;start=169086&amp;amp;len=7145246&amp;amp;mimepart=7&amp;amp;disk=64.4.18.31_d1261&amp;amp;login=m_dinino&amp;amp;domain=hotmail%2ecom&amp;amp;_lang=EN&amp;amp;count" target="_blank"&gt;http://64.4.18.250/cgi-bin/getmsg/IMG_0091.JPG?curmbox=F000000004&amp;amp;a=46c002caa67737093a99d6df1e381c77&amp;amp;msg=MSG1114736378.24&amp;amp;start=169086&amp;amp;len=7145246&amp;amp;mimepart=7&amp;amp;disk=64.4.18.31_d1261&amp;amp;login=m_dinino&amp;amp;domain=hotmail%2ecom&amp;amp;_lang=EN&amp;amp;count&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Is it just a long payload to port 5000 that alerted this or is there something that I am missing?&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 09:25:57 GMT</pubDate>
    <dc:creator>g-pfeiffer</dc:creator>
    <dc:date>2019-03-10T09:25:57Z</dc:date>
    <item>
      <title>IDS Sig 4058 question</title>
      <link>https://community.cisco.com/t5/network-security/ids-sig-4058-question/m-p/400361#M98156</link>
      <description>&lt;P&gt;Sig 4058 subsig 1 (IDS Signature UPnP LOCATION Overflow) was triggered on one of our sensors as what appears to me to be a false positive. From what I understand, the sig fires on a payload of 116 characters or more to service port 5000 TCP.  The destination port was tcp 5000 and the context of the alert triggered was:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://64.4.18.250/cgi-bin/getmsg/IMG_0091.JPG?curmbox=F000000004&amp;amp;a=46c002caa67737093a99d6df1e381c77&amp;amp;msg=MSG1114736378.24&amp;amp;start=169086&amp;amp;len=7145246&amp;amp;mimepart=7&amp;amp;disk=64.4.18.31_d1261&amp;amp;login=m_dinino&amp;amp;domain=hotmail%2ecom&amp;amp;_lang=EN&amp;amp;count" target="_blank"&gt;http://64.4.18.250/cgi-bin/getmsg/IMG_0091.JPG?curmbox=F000000004&amp;amp;a=46c002caa67737093a99d6df1e381c77&amp;amp;msg=MSG1114736378.24&amp;amp;start=169086&amp;amp;len=7145246&amp;amp;mimepart=7&amp;amp;disk=64.4.18.31_d1261&amp;amp;login=m_dinino&amp;amp;domain=hotmail%2ecom&amp;amp;_lang=EN&amp;amp;count&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Is it just a long payload to port 5000 that alerted this or is there something that I am missing?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:25:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-sig-4058-question/m-p/400361#M98156</guid>
      <dc:creator>g-pfeiffer</dc:creator>
      <dc:date>2019-03-10T09:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Sig 4058 question</title>
      <link>https://community.cisco.com/t5/network-security/ids-sig-4058-question/m-p/400362#M98158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Signature 4058.1 has hidden parameters and we can't disclose that information. As the signature description reads, 4058.1 triggers upon detecting a large location request sent to a UPnP device. This subsignature looks for requests to TCP port 5000.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I can say that what you have here from the context buffer would not have triggered the alarm by itself. There's something else in the stream that cause the alert to trigger - if you happen to have a pcap of the session, I'd be happy to take a look at it. If not, judging from the information you have here, this is most likely a false positive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 May 2005 01:14:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-sig-4058-question/m-p/400362#M98158</guid>
      <dc:creator>wsulym</dc:creator>
      <dc:date>2005-05-02T01:14:11Z</dc:date>
    </item>
  </channel>
</rss>

