cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
549
Views
0
Helpful
2
Replies

Signature Update S161 Missing Signatures

lbhoang
Level 1
Level 1

The following signatures are mentioned in the release notes but do not show up in VMS:

4703.0 MSSQL Resolution Service Stack Overflow STRING.TCP Info True

4704.0 MSSQL Resolution Service Stack Overflow STRING.TCP Info True

2 Replies 2

craiwill
Cisco Employee
Cisco Employee

These are 5.x only signatures; they replace 4701 and 4702 which have been retired in 5.x. Thank you for bringing this to our attention, we are posting an updated version of the readme.

What I have noticed already in former updates is that there is a difference in grouping of the new signatures in the CiscoWorks VMS/IDS MC and on the ids device itself(via IDM). For example, in S161, there is the new signature 3347 which is added to the attack signatures group under 'command execution' on the ids device, but in CW VMS I don't find this signature in the same category. For us this is however important to find this signature in the proper group in CW VMS, because we do additional modifications on those signatures.

Review Cisco Networking for a $25 gift card