×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

new engineering release 3.1.3 for service-over-host sweeps

Unanswered Question
May 30th, 2002
User Badges:

We have created the engrel2 bundle to address the problems noted with the host sweeps,

particulary the Sig 3030 false negative on SQL Spyda sweeps on port 1433. (We were only

looking at low ports, so port 1433 was never counted).


Now, we have changed the behavior of the signatures 3030-3037 to be service sweeps

instead of a regular host sweeps. (See the README with the bundle on ftp-eng).


You can find the files on 'ftp-eng.cisco.com'.

The path is: /ftp/pub/titanium


Download the files:

CSIDS-313-engrel2.tar.Z and README

in ftp BINARY mode.


The README has installation instructions and a full description of the changes in this version.


-JK

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
jakasper Wed, 06/05/2002 - 21:13
User Badges:

The sigs.xml.313eng.s24 file is not a replacement "Sig Update" file. It is the engine parameter and signature default descriptions for the Director platform.


This file is not needed to make the new 3.1.3 sensor function properly. The only need for the file is if you want to use the "PortOfInterest" parameter for the Engine SWEEP.HOST.TCP. This parameter is not needed because of the new functionality of the engine. It is there for special applications where you want to create a port XYZ custom host sweep signature. The default behavior of the engine now gives you good coverage for port ANY host sweeps so you probally won't need the PortOfInterest parameter.


We included the .xml file with the bundle so we would have the file ready if needed. I should have explicitly stated in the instructions to ignore this file.


When there is a customer need for the above mentioned capability, we will publish offical "install" instructions for this .xml file.


Sorry for this tardy response, I was out of the office for a couple days.


-JK

jakasper Sun, 07/07/2002 - 19:37
User Badges:

CSIDS-313-engrel2 fixes the sweep problem noted in this forum's July 5th posts.


The SWEEP.HOST.TCP engine has been changed so that the default behavior is that of a "Service Sweep" instead of a "Host Sweep" and it

looks at all ports instead of just the low ports.

(affects SIGIDs 3030-3037).


I just checked the ftp-eng site and the files are still intact. Ignore the sigs.xml

file -- its not needed for the eng2 bundle. (See May 30 post on this thread.)


I do not know of a date for an "official" 3.1(3) release that would include this fix.

Someone else will have to elaborate on that topic.


Until then, the eng2 bundle solves this problem.


-JK



Actions

This Discussion