<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 5610-0 false positives in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/5610-0-false-positives/m-p/489234#M98822</link>
    <description>&lt;P&gt;I don't understand why this is firing. It looks like it should only fire if there is a non-numeric value for the query parameter graph_start...which there isn't. Here are the details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Arg Name Regex: [Gg][Rr][Aa][Pp][Hh][_][Ss][Tt][Aa][Rr][Tt][=]&lt;/P&gt;&lt;P&gt;Arg Value Regex: [^0-9]+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And here is the context:&lt;/P&gt;&lt;P&gt;    fromAttacker: &lt;/P&gt;&lt;P&gt;000000  47 45 54 20 2F 63 61 63  74 69 2F 67 72 61 70 68  GET /cacti/graph&lt;/P&gt;&lt;P&gt;000010  5F 69 6D 61 67 65 2E 70  68 70 3F 6C 6F 63 61 6C  _image.php?local&lt;/P&gt;&lt;P&gt;000020  5F 67 72 61 70 68 5F 69  64 3D 31 36 31 26 72 72  _graph_id=161&amp;amp;rr&lt;/P&gt;&lt;P&gt;000030  61 5F 69 64 3D 30 26 67  72 61 70 68 5F 68 65 69  a_id=0&amp;amp;graph_hei&lt;/P&gt;&lt;P&gt;000040  67 68 74 3D 31 30 30 26  67 72 61 70 68 5F 77 69  ght=100&amp;amp;graph_wi&lt;/P&gt;&lt;P&gt;000050  64 74 68 3D 33 30 30 26  67 72 61 70 68 5F 6E 6F  dth=300&amp;amp;graph_no&lt;/P&gt;&lt;P&gt;000060  6C 65 67 65 6E 64 3D 74  72 75 65 26 76 69 65 77  legend=true&amp;amp;view&lt;/P&gt;&lt;P&gt;000070  5F 74 79 70 65 3D 74 72  65 65 26 67 72 61 70 68  _type=tree&amp;amp;graph&lt;/P&gt;&lt;P&gt;000080  5F 73 74 61 72 74 3D 31  31 33 38 31 33 31 39 39  _start=113813199&lt;/P&gt;&lt;P&gt;000090  36 26 67 72 61 70 68 5F  65 6E 64 3D 31 31 33 38  6&amp;amp;graph_end=1138&lt;/P&gt;&lt;P&gt;0000A0  32 31 38 33 39 36 20 48  54 54 50 2F 31 2E 31 0D  218396 HTTP/1.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  riskRatingValue: 65  &lt;/P&gt;&lt;P&gt;  interface: ge0_0  &lt;/P&gt;&lt;P&gt;  protocol: tcp  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 09:51:39 GMT</pubDate>
    <dc:creator>mhellman</dc:creator>
    <dc:date>2019-03-10T09:51:39Z</dc:date>
    <item>
      <title>5610-0 false positives</title>
      <link>https://community.cisco.com/t5/network-security/5610-0-false-positives/m-p/489234#M98822</link>
      <description>&lt;P&gt;I don't understand why this is firing. It looks like it should only fire if there is a non-numeric value for the query parameter graph_start...which there isn't. Here are the details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Arg Name Regex: [Gg][Rr][Aa][Pp][Hh][_][Ss][Tt][Aa][Rr][Tt][=]&lt;/P&gt;&lt;P&gt;Arg Value Regex: [^0-9]+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And here is the context:&lt;/P&gt;&lt;P&gt;    fromAttacker: &lt;/P&gt;&lt;P&gt;000000  47 45 54 20 2F 63 61 63  74 69 2F 67 72 61 70 68  GET /cacti/graph&lt;/P&gt;&lt;P&gt;000010  5F 69 6D 61 67 65 2E 70  68 70 3F 6C 6F 63 61 6C  _image.php?local&lt;/P&gt;&lt;P&gt;000020  5F 67 72 61 70 68 5F 69  64 3D 31 36 31 26 72 72  _graph_id=161&amp;amp;rr&lt;/P&gt;&lt;P&gt;000030  61 5F 69 64 3D 30 26 67  72 61 70 68 5F 68 65 69  a_id=0&amp;amp;graph_hei&lt;/P&gt;&lt;P&gt;000040  67 68 74 3D 31 30 30 26  67 72 61 70 68 5F 77 69  ght=100&amp;amp;graph_wi&lt;/P&gt;&lt;P&gt;000050  64 74 68 3D 33 30 30 26  67 72 61 70 68 5F 6E 6F  dth=300&amp;amp;graph_no&lt;/P&gt;&lt;P&gt;000060  6C 65 67 65 6E 64 3D 74  72 75 65 26 76 69 65 77  legend=true&amp;amp;view&lt;/P&gt;&lt;P&gt;000070  5F 74 79 70 65 3D 74 72  65 65 26 67 72 61 70 68  _type=tree&amp;amp;graph&lt;/P&gt;&lt;P&gt;000080  5F 73 74 61 72 74 3D 31  31 33 38 31 33 31 39 39  _start=113813199&lt;/P&gt;&lt;P&gt;000090  36 26 67 72 61 70 68 5F  65 6E 64 3D 31 31 33 38  6&amp;amp;graph_end=1138&lt;/P&gt;&lt;P&gt;0000A0  32 31 38 33 39 36 20 48  54 54 50 2F 31 2E 31 0D  218396 HTTP/1.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  riskRatingValue: 65  &lt;/P&gt;&lt;P&gt;  interface: ge0_0  &lt;/P&gt;&lt;P&gt;  protocol: tcp  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:51:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5610-0-false-positives/m-p/489234#M98822</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2019-03-10T09:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: 5610-0 false positives</title>
      <link>https://community.cisco.com/t5/network-security/5610-0-false-positives/m-p/489235#M98824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thankyou for bringing this to our attention, it is indeed a false positive. This has been assigned bug id CSCsd16754 and will be addressed in the S215 release.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2006 01:29:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5610-0-false-positives/m-p/489235#M98824</guid>
      <dc:creator>wsulym</dc:creator>
      <dc:date>2006-01-26T01:29:57Z</dc:date>
    </item>
  </channel>
</rss>

