<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sig 3334 Windows Workstation Service Overflow in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504050#M99335</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are researching this signature for modification in a future update.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 31 May 2005 11:20:29 GMT</pubDate>
    <dc:creator>craiwill</dc:creator>
    <dc:date>2005-05-31T11:20:29Z</dc:date>
    <item>
      <title>Sig 3334 Windows Workstation Service Overflow</title>
      <link>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504044#M99328</link>
      <description>&lt;P&gt;We are seeing a very large number of these signatures firing and I'm wondering if anyone has identified legitimate MS traffic as triggering this alert.....&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:28:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504044#M99328</guid>
      <dc:creator>asafayan</dc:creator>
      <dc:date>2019-03-10T09:28:13Z</dc:date>
    </item>
    <item>
      <title>Re: Sig 3334 Windows Workstation Service Overflow</title>
      <link>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504045#M99330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have not identified any benign triggers associated with this signature. Could you provide a traffic sample of the questionable traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 May 2005 12:04:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504045#M99330</guid>
      <dc:creator>craiwill</dc:creator>
      <dc:date>2005-05-27T12:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Sig 3334 Windows Workstation Service Overflow</title>
      <link>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504046#M99331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 May 2005 12:40:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504046#M99331</guid>
      <dc:creator />
      <dc:date>2005-05-27T12:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: Sig 3334 Windows Workstation Service Overflow</title>
      <link>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504047#M99332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have performed a packet capture and identified the alerts as a false positive.  How do I upload the capture?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 May 2005 22:39:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504047#M99332</guid>
      <dc:creator>asafayan</dc:creator>
      <dc:date>2005-05-27T22:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Sig 3334 Windows Workstation Service Overflow</title>
      <link>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504048#M99333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have identified a trend between multiple traces that are triggering the 3334 signature. It appears that RPC traffic to Lexmark printers are triggering this signature and creating false positives.  If this is the case on your network you will be able to see the Lexmark information later in the stream if you enable ip logging.  Please let me know if you are seeing the same type of traffic.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2005 06:45:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504048#M99333</guid>
      <dc:creator>nhoover</dc:creator>
      <dc:date>2005-05-30T06:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Sig 3334 Windows Workstation Service Overflow</title>
      <link>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504049#M99334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can upload your capture directly on Netpro. When you post an answer, you'll notice the "Add Attachments" link below the Post button.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2005 06:01:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504049#M99334</guid>
      <dc:creator>jdal</dc:creator>
      <dc:date>2005-05-31T06:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: Sig 3334 Windows Workstation Service Overflow</title>
      <link>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504050#M99335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are researching this signature for modification in a future update.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2005 11:20:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504050#M99335</guid>
      <dc:creator>craiwill</dc:creator>
      <dc:date>2005-05-31T11:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Sig 3334 Windows Workstation Service Overflow</title>
      <link>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504051#M99336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are seeing this as well.  In our environment it's on a Unisys printer attached with an external HP Jetdirect server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a log but cannot attach it here directly due to any information that is in it that may be confidential.  I'd be happy to upload it directly via another avenue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;Ron Russell&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2005 15:40:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504051#M99336</guid>
      <dc:creator>rrussell</dc:creator>
      <dc:date>2005-06-01T15:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sig 3334 Windows Workstation Service Overflow</title>
      <link>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504052#M99340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cisco MUST do a better job of tuning their signatures.  We implemented a Juniper IDP (inline and blocking) and I only rely on the Cisco IDSs for secondary / tertiary information b/c of this very reason.  I spent about 1 full day chasing down the false positives on this one siganture.  A hugh waste of my companies time and money and a another reminder that we made the right choice in implementing our Juniper IDP.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Contact me directly with any questions about our Juniper Intrusion Prevention and Detection appliance. It sits inline and filters our VPN, Internet and RAS segments coming into our network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2005 17:35:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sig-3334-windows-workstation-service-overflow/m-p/504052#M99340</guid>
      <dc:creator>asafayan</dc:creator>
      <dc:date>2005-06-01T17:35:57Z</dc:date>
    </item>
  </channel>
</rss>

