cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
700
Views
0
Helpful
3
Replies

Anyone come up with a custom sig for WMF Exploit?

mmoulder16
Level 1
Level 1

Based on bleeding snort sid, this is what I've got, but it doesn't seem to be working:

wmf exploit file:

\x01\x00\x09\x00\x00\x03.{10}\x00\x00.{0, 5000}\x26\x06\x09\x00

3 Replies 3

craiwill
Cisco Employee
Cisco Employee

Signature 5693-1 which was released in S210 addresses this vulnerability.

I installed release S211 (modified 5693-1 signature) and attempted to download an WMF file across the sensor, but the signature did not fire. What causes the WMF signature to fire?

This signature fires upon detecting a malicious wmf file downloaded from a web server running on a port specified in the #WEBPORTS variable.

Review Cisco Networking for a $25 gift card