cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1245
Views
0
Helpful
6
Replies

Microsoft Windows Information Disclosure Signature

Jhun Banzuela
Level 1
Level 1

Please evaluate if the signature (6322) Microsoft Windows Information Disclosure Signature is OK as it seems I am receiving lots of false positives alert.

6 Replies 6

mhanson2004
Level 1
Level 1

Same boat here, thousands of alerts all coming from either google or youtube. 

 

Will someone from Cisco please check on this and report back?

 

Thank you.

 

Mike

kevin.blackburn
Level 4
Level 4

I as well have received 1000+ alerts from this one. The majority of the "attacker" IP addresses point back to google as well. If you look at what is actually triggering the alert (in my case at least) it shows every user trying to download "GoogleUpdateSetup.exe". One of the common URL's I am seeing is below:

Got a response on my TAC case. Confirmed that they are receiving a lot of tickets on this one and it is "definitely" a false positive and can be disabled safely. Developers are looking into a fix \ new signature release at this point.

 

Hope that helps!

Thanks for the update Kevin. 

I wish the Cisco IPS group would responded more quickly to these type of issues. There can't be many of us still using their IPS, so their team is probably pretty lean.

Mike

IPS signature 869.0 has been pushed and the emails have stopped. This alert should no longer be an issue. Thanks

wgorman
Level 1
Level 1

In my case, the signature is 6332/0, same description, 3k+ alerts, majority of sources are from Google.

Is this a false positive?

Please respond.

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card