[Emerging-Sigs] New sigs

Matt Jonkman jonkman at jonkmans.com
Fri Mar 7 15:27:13 EST 2008


We've had a bunch of new sigs sent in by Akash Mahajan of stillsecure
the last couple weeks. I haven't had time to post them all here as they
went into the ruleset. But here's today's:

 2007931 - ET EXPLOIT IncrediMail IMMenuShellExt ActiveX Control Buffer
Overflow Vulnerability
 2007932 - ET EXPLOIT Symantec BackupExec Calendar Control
(PVCalendar.ocx) BoF Vulnerability
 2007933 - ET EXPLOIT Zilab Chat and Instant Messaging Heap Overflow
Vulnerability
 2007934 - ET EXPLOIT Zilab Chat and Instant Messaging User Info BoF
Vulnerability
 2007936 - ET WEB Netwin Webmail SurgeMail Mail Server Format String
Vulnerability
 2007937 - ET EXPLOIT Borland VisiBroker Smart Agent Heap Overflow

Good stuff, thanks Akash

You'll also probably notice a whole slew of new malware signatures. This
is a result of some great malware intel we're getting, and a vastly
upgraded sandboxing capability as a result of the grant funding. Your
Tax dollars at work! :)

Much more to come!

Matt

-- 
--------------------------------------------
Matthew Jonkman
Emerging Threats
Phone 765-429-0398
Fax 312-264-0205
http://www.emergingthreats.net
--------------------------------------------

PGP: http://www.jonkmans.com/mattjonkman.asc




More information about the Emerging-sigs mailing list