05-14-2015 11:56 PM - edited 03-10-2019 06:22 AM
Please evaluate if the signature (6322) Microsoft Windows Information Disclosure Signature is OK as it seems I am receiving lots of false positives alert.
05-15-2015 07:44 AM
Same boat here, thousands of alerts all coming from either google or youtube.
Will someone from Cisco please check on this and report back?
Thank you.
Mike
05-15-2015 08:21 AM
I as well have received 1000+ alerts from this one. The majority of the "attacker" IP addresses point back to google as well. If you look at what is actually triggering the alert (in my case at least) it shows every user trying to download "GoogleUpdateSetup.exe". One of the common URL's I am seeing is below:
05-19-2015 03:57 AM
Got a response on my TAC case. Confirmed that they are receiving a lot of tickets on this one and it is "definitely" a false positive and can be disabled safely. Developers are looking into a fix \ new signature release at this point.
Hope that helps!
05-19-2015 06:39 AM
Thanks for the update Kevin.
I wish the Cisco IPS group would responded more quickly to these type of issues. There can't be many of us still using their IPS, so their team is probably pretty lean.
Mike
05-22-2015 08:39 AM
IPS signature 869.0 has been pushed and the emails have stopped. This alert should no longer be an issue. Thanks
05-15-2015 11:42 AM
In my case, the signature is 6332/0, same description, 3k+ alerts, majority of sources are from Google.
Is this a false positive?
Please respond.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide