08-31-2006 06:24 AM - edited 03-10-2019 03:11 AM
Has anyone else recently been getting Alerts on the below signatures while accessing Cisco sites?
Windows Shell External Handler
Apache mod_proxy Buffer Overflow
3340:0
3883:0
The above two alerts listed ftp-sj.cisco.com as the attacker and my CS-Manager as the victim. I assume this is during IPS signature file downloads.
While searching the Cisco forums about the above issue, I received an alert on sig 3440 with tools.cisco.com as the attacker and my personal PC as the victim.
Thanks for any info.
08-31-2006 06:53 AM
It appears the alert that fired on 3440 with tools.cisco.com as the attacker occured while I was looking up the 3440 signature on MySDN. I believe the signature description contains the trigger for this alert "=shell".
08-31-2006 07:37 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide