07-18-2003 07:30 AM - edited 03-09-2019 04:06 AM
Is the Microsoft's Remote Procedure Call (RPC) reference in the current signature database?
If not, is there a custom string that can be put in place.
07-23-2003 01:28 PM
No not yet. ISS RealSecure Network and Proventia provided protection about a week ago.
07-28-2003 09:01 AM
A number of exploits for this vulnerability are now available in the wild. Has Cisco released any custom signatures for detection yet?
07-30-2003 08:14 AM
A signature for this vulnerability has been released in S49. You can retrieve it from:
07-31-2003 06:53 AM
Yeah and I get false positives up the wazoo.
I'm sorry but unless you release the details of how your signature works, I turn them off and correlate home-made, my proventias and snort.
Visibility in to your signatures provides better tuning than relying on your blackbox approach.
07-31-2003 08:21 AM
Which signature is giving false positives? and on which port?
SC
07-31-2003 10:16 AM
If you are runnning 4.X then you have full access to the details of the signature. All you have to do is open the signature up in IDM as if you were going to edit it and the complete signature details are there for your perusal.
If you are having an issue with a signature that is false positiving, then please bring it to our attention so that we can get to the root cause of the problem. We are constantly trying to improve the fidelity of our signatures, however or visibility is only as good as the feedback that we are receiving.
Please contact me directly at klwiley@cisco.com and I will try to help you with your problems.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide