cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1802
Views
0
Helpful
16
Replies

S256 sig 5170 -- *thousands* of FPs

jkell
Level 1
Level 1

Thousands and thousands... apparently firing on nulls outside of uricontent. ASA5540/AIP-SSM20s. 5.1(3)S256.0.

16 Replies 16

DFiore
Level 1
Level 1

I'm seeing "dozens" of "Null Byte in HTTP Requests" when certain users access their web-based email.

Have you heard from Cisco regarding?

attmidsteam
Level 1
Level 1

Is anybody else seeing crashes related to this sig update? S256 crashed several of our sensors just after updating. P.O.S.

Also forgot to mention that we saw upwards of 14 thousand hits on this signature in under an hour from about 8 sensors. We couldn't disable it fast enough...

No crashes - yet. Our load is low on our 4240. If I do crash, I'll post it.

No crashes yet. But we did have a problem with a number of sensors after they received S255. It looks like the default signature set is getting too big - I now have to tune and disable a number of signatures just so the hardware can cope.

Several of our sensors hung during the S256 upgrade too. Actually we aborted the update due to it.

Last line in /usr/cids/idsRoot/var/updates/logs/install.log was:

Sending signature edc.

Same for you?

wsulym
Cisco Employee
Cisco Employee

I'll assume its the -1 subsig. Can you flip verbose alert on for that sig, and provide us some of the alerts w/ verbose output. Thanks.

Sent you several in offline email.

Did Cisco ever figure this out? At least in our case, it seems to be caused by binary data in a HTTP POST. See attached for a snippet (sorry, that's all I feel comfortable giving).

swimmer116
Level 1
Level 1

Is there any update to this thread? We are also seeing thousands of events that appear to be false positives.

99% of the false positives I saw were from yahoo messengar notifications.

I would just do what we did; disable it across the board since it is obviously bogus.

Got alerts from CSM stating that "the sensor reports that it is running low on resources." Measure of resource utilization on the virtual sensor was 22. After disabling 5170 it's down to 0.

I just picked the last in this thread to respond too. 5170-1 is very much like 5171-0, it's looking for the exact same thing except in the arguments instead of the URI. We are still working with the engine developers, but you can turn the sig off until the new version is released, or edit the signature and set de-obfuscate to "false". The change to the signature in the upcoming release will be the deobfuscation change. Even with the change, this signature will still fire on BitTorrent traffic, as it normally has nulls embedded in the arguments, however in this case it would be a benign trigger and not a false positive since the signature only looks for the embedded null, and that occurs "naturally" in BitTorrent traffic.

Review Cisco Networking for a $25 gift card