<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Emerging Threats Pro</title>
	<atom:link href="http://www.emergingthreatspro.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.emergingthreatspro.com</link>
	<description>Full Coverage IDS/IPS Rulesets</description>
	<lastBuildDate>Fri, 18 May 2012 02:22:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Daily Ruleset Update Summary 5/17/2012</title>
		<link>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5172012/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=daily-ruleset-update-summary-5172012</link>
		<comments>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5172012/#comments</comments>
		<pubDate>Fri, 18 May 2012 02:22:19 +0000</pubDate>
		<dc:creator>wmetcalf</dc:creator>
				<category><![CDATA[Daily Ruleset Update Summary]]></category>

		<guid isPermaLink="false">http://www.emergingthreatspro.com/?p=2360</guid>
		<description><![CDATA[12 new Open rules. 15 new Pro rules. Enjoy! [+++] Added rules: [+++] Open: 2014751 &#8211; ET CURRENT_EVENTS Unknown &#8211; Java Exploit &#8211; 32char file name (current_events.rules) 2014752 &#8211; ET CURRENT_EVENTS Win32.HLLW.Autoruner USA_Load UA (current_events.rules) 2014753 &#8211; ET CURRENT_EVENTS probable malicious Glazunov Javascript injection (current_events.rules) 2014754 &#8211; ET TROJAN W32/Mepaow.Backdoor Initial Checkin to Intermediary Pre-CnC [...]]]></description>
			<content:encoded><![CDATA[<p>12 new Open rules. 15 new Pro rules. Enjoy!</p>
<p> [+++]          Added rules:          [+++]<br />
 Open:<br />
 2014751 &#8211; ET CURRENT_EVENTS Unknown &#8211; Java Exploit &#8211; 32char file name (current_events.rules)<br />
 2014752 &#8211; ET CURRENT_EVENTS Win32.HLLW.Autoruner USA_Load UA (current_events.rules)<br />
 2014753 &#8211; ET CURRENT_EVENTS probable malicious Glazunov Javascript injection (current_events.rules)<br />
 2014754 &#8211; ET TROJAN W32/Mepaow.Backdoor Initial Checkin to Intermediary Pre-CnC (trojan.rules)<br />
 2014755 &#8211; ET CURRENT_EVENTS W32/HupigonUser.Backdoor Agent RAbcLib (current_events.rules)<br />
 2014756 &#8211; ET POLICY Logmein.com SSL Remote Control Access (policy.rules)<br />
 2014757 &#8211; ET TROJAN Win32/Comrerop Checkin at FTP server (trojan.rules)<br />
 2014758 &#8211; ET TROJAN Trojan.BAT.Qhost &#8211; SET (trojan.rules)<br />
 2014759 &#8211; ET TROJAN Trojan.BAT.Qhost Response from Controller (trojan.rules)<br />
 2014760 &#8211; ET TROJAN W32/Votwup.Backdoor Checkin (trojan.rules)<br />
 2014761 &#8211; ET POLICY Internal Host Getting External IP Address &#8211; ip2city.asp (policy.rules)<br />
 2014762 &#8211; ET TROJAN W32/SpyBanker Infection Confirmation Email 2 (trojan.rules)</p>
<p> Pro:<br />
 2804934 &#8211; ETPRO TROJAN Dropper-FQE Checkin (trojan.rules)<br />
 2804937 &#8211; ETPRO TROJAN TrojanDownloader.Win32/Waledac.R Checkin (trojan.rules)<br />
 2804938 &#8211; ETPRO MALWARE Win32/Adware.1ClickDownload User-Agent (Inetc3 (Mozilla#-#- FW 4#-#-)) (malware.rules)<br />
 2804939 &#8211; ETPRO TROJAN Worm.Win32.Ainslot Checkin (trojan.rules)<br />
 2804940 &#8211; ETPRO TROJAN TrojanDownloader.Win32/Begger.A Checkin (trojan.rules)<br />
 2804941 &#8211; ETPRO TROJAN Win32/Karagany.E Checkin 1 (trojan.rules)<br />
 2804942 &#8211; ETPRO TROJAN Win32/Karagany.E Checkin 2 (trojan.rules)<br />
 2804943 &#8211; ETPRO TROJAN Backdoor/Buterat.abl Checkin (trojan.rules)<br />
 2804944 &#8211; ETPRO TROJAN Win32/Simda.A CnC Traffic (trojan.rules)<br />
 2804945 &#8211; ETPRO TROJAN W32/Banload.XPX!tr Checkin (trojan.rules)<br />
 2804946 &#8211; ETPRO TROJAN WinNT/Nagyo.C!rootkit Checkin (trojan.rules)<br />
 2804947 &#8211; ETPRO TROJAN Backdoor.VB.5 CnC Traffic (trojan.rules)<br />
 2804948 &#8211; ETPRO TROJAN TrojanDownloader.Win32/Pluzoks.A Checkin 2 (trojan.rules)<br />
 2804949 &#8211; ETPRO TROJAN RogueAntiSpyware.XPAntivirus Checkin (trojan.rules)<br />
 2804950 &#8211; ETPRO TROJAN Backdoor.Win32.Simda.kv/Proxyier Checkin (trojan.rules)</p>
<p> [///]     Modified active rules:     [///]</p>
<p> Open:<br />
 2008415 &#8211; ET SCAN Cisco Torch IOS HTTP Scan (scan.rules)<br />
 2008529 &#8211; ET SCAN Core-Project Scanning Bot UA Detected (scan.rules)<br />
 2014610 &#8211; ET TROJAN W32/Downvision.A Initial Checkin (trojan.rules)</p>
<p> Pro:<br />
 2803869 &#8211; ETPRO TROJAN Rootkit.ZAccess.cj Checkin (trojan.rules)</p>
<p> [---]         Removed rules:         [---]</p>
<p> 2800847 &#8211; ETPRO POLICY Logmein.com SSL Remote Control Access (policy.rules)<br />
 2804930 &#8211; ETPRO TROJAN Win32/Comrerop Checkin at FTP server (trojan.rules)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5172012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Daily Ruleset Update Summary 5/15/2012</title>
		<link>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5152012/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=daily-ruleset-update-summary-5152012</link>
		<comments>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5152012/#comments</comments>
		<pubDate>Wed, 16 May 2012 00:51:26 +0000</pubDate>
		<dc:creator>Matthew Jonkman</dc:creator>
				<category><![CDATA[Daily Ruleset Update Summary]]></category>

		<guid isPermaLink="false">http://www.emergingthreatspro.com/?p=2356</guid>
		<description><![CDATA[&#160; &#160; 6 new rules today.  A few little fixes and tweaks. &#160; [+++]          Added rules:          [+++] &#160; 2804928 &#8211; ETPRO TROJAN W32.Philis.Q Checkin (trojan.rules) 2804929 &#8211; ETPRO TROJAN TrojanDownloader.Win32/Banload.ACI Checkin 2 (trojan.rules) 2804930 &#8211; ETPRO TROJAN Win32/Comrerop Checkin at FTP server (trojan.rules) 2804931 &#8211; ETPRO TROJAN W32.Colowned.A Checkin 1 (trojan.rules) 2804932 &#8211; ETPRO TROJAN [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p>&nbsp;</p>
<p>6 new rules today.  A few little fixes and tweaks.</p>
<p>&nbsp;</p>
<p>[+++]          Added rules:          [+++]</p>
<p>&nbsp;</p>
<p>2804928 &#8211; ETPRO TROJAN W32.Philis.Q Checkin (trojan.rules)</p>
<p>2804929 &#8211; ETPRO TROJAN TrojanDownloader.Win32/Banload.ACI Checkin 2 (trojan.rules)</p>
<p>2804930 &#8211; ETPRO TROJAN Win32/Comrerop Checkin at FTP server (trojan.rules)</p>
<p>2804931 &#8211; ETPRO TROJAN W32.Colowned.A Checkin 1 (trojan.rules)</p>
<p>2804932 &#8211; ETPRO TROJAN W32.Colowned.A Checkin 2 (trojan.rules)</p>
<p>2804933 &#8211; ETPRO TROJAN Win32/Virut.BN Checkin 2 (trojan.rules)</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>[///]     Modified active rules:     [///]</p>
<p>&nbsp;</p>
<p>2014730 &#8211; ET CURRENT_EVENTS Potential FAKEAV Download .info a-f0-9 x16 setup download (current_events.rules)</p>
<p>2402000 &#8211; ET DROP Dshield Block Listed Source (dshield.rules)</p>
<p>2803188 &#8211; ETPRO TROJAN Cnaddare.A/Fednu.c/Adware Checkin to Server flowbit set (trojan.rules)</p>
<p>2804317 &#8211; ETPRO TROJAN TrojanDownloader.Win32/Banload.ACI Checkin (trojan.rules)</p>
<p>2804900 &#8211; ETPRO TROJAN Win32/Lybsus.A CnC Traffic (trojan.rules)</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>[///]    Modified inactive rules:    [///]</p>
<p>&nbsp;</p>
<p>2014015 &#8211; ET TROJAN TROJAN LDPinch Loader Binary Request (trojan.rules)</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>[---]  Disabled and modified rules:  [---]</p>
<p>&nbsp;</p>
<p>2014748 &#8211; ET CURRENT_EVENTS RedKit Repeated Exploit Request Pattern (current_events.rules)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5152012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Daily Ruleset Update Summary 5/14/2012</title>
		<link>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5142012/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=daily-ruleset-update-summary-5142012</link>
		<comments>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5142012/#comments</comments>
		<pubDate>Mon, 14 May 2012 19:55:20 +0000</pubDate>
		<dc:creator>wmetcalf</dc:creator>
				<category><![CDATA[Daily Ruleset Update Summary]]></category>

		<guid isPermaLink="false">http://www.emergingthreatspro.com/?p=2354</guid>
		<description><![CDATA[5 new Open rules 1 new Pro rule. A couple of tweaks. [+++] Added rules: [+++] Open: 2014746 &#8211; ET CURRENT_EVENTS Blackhole Java Exploit request to /Set.jar (current_events.rules) 2014747 &#8211; ET CURRENT_EVENTS Blackhole Try Prototype Catch May 14 2012 (current_events.rules) 2014748 &#8211; ET CURRENT_EVENTS RedKit Repeated Exploit Request Pattern (current_events.rules) 2014749 &#8211; ET CURRENT_EVENTS Redkit [...]]]></description>
			<content:encoded><![CDATA[<p>5 new Open rules 1 new Pro rule. A couple of tweaks.</p>
<p> [+++]          Added rules:          [+++]</p>
<p> Open:<br />
 2014746 &#8211; ET CURRENT_EVENTS Blackhole Java Exploit request to /Set.jar (current_events.rules)<br />
 2014747 &#8211; ET CURRENT_EVENTS Blackhole Try Prototype Catch May 14 2012 (current_events.rules)<br />
 2014748 &#8211; ET CURRENT_EVENTS RedKit Repeated Exploit Request Pattern (current_events.rules)<br />
 2014749 &#8211; ET CURRENT_EVENTS Redkit Java Exploit request to /24842.jar (current_events.rules)<br />
 2014750 &#8211; ET CURRENT_EVENTS Incognito/RedKit Exploit Kit vulnerable Java payload request to /1.html (current_events.rules)</p>
<p> Pro:<br />
 2804927 &#8211; ETPRO WEB_CLIENT Microsoft Excell with Regular SERIES Record with a malformed stdy value (web_client.rules)</p>
<p> [///]     Modified active rules:     [///]<br />
 2802960 &#8211; ETPRO TROJAN Win32.SpyEye.cuk Checkin flowbit SET (trojan.rules)<br />
 2804876 &#8211; ETPRO TROJAN Win32/Coswid.A Checkin (trojan.rules)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5142012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Daily Ruleset Update Summary 5/11/2012</title>
		<link>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5112012/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=daily-ruleset-update-summary-5112012</link>
		<comments>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5112012/#comments</comments>
		<pubDate>Fri, 11 May 2012 21:13:10 +0000</pubDate>
		<dc:creator>wmetcalf</dc:creator>
				<category><![CDATA[Daily Ruleset Update Summary]]></category>

		<guid isPermaLink="false">http://www.emergingthreatspro.com/?p=2351</guid>
		<description><![CDATA[11 new rules. Enjoy! [+++] Added rules: [+++] 2014735 &#8211; ET MALWARE Malicious file bitdefender_isecurity.exe download (malware.rules) 2014736 &#8211; ET WEB_SPECIFIC_APPS Andromeda Streaming MP3 Server andromeda.php Cross-Site Scripting Attempt (web_specific_apps.rules) 2014737 &#8211; ET ACTIVEX Potential ThreeDify Designer ActiveX Control cmdSave Method Access Buffer Overflow (activex.rules) 2014738 &#8211; ET ACTIVEX Potential ThreeDify Designer ActiveX Control cmdSave [...]]]></description>
			<content:encoded><![CDATA[<p>11 new rules. Enjoy!</p>
<p>[+++]          Added rules:          [+++]</p>
<p> 2014735 &#8211; ET MALWARE Malicious file bitdefender_isecurity.exe download (malware.rules)<br />
 2014736 &#8211; ET WEB_SPECIFIC_APPS Andromeda Streaming MP3 Server andromeda.php Cross-Site Scripting Attempt (web_specific_apps.rules)<br />
 2014737 &#8211; ET ACTIVEX Potential ThreeDify Designer ActiveX Control cmdSave Method Access Buffer Overflow (activex.rules)<br />
 2014738 &#8211; ET ACTIVEX Potential ThreeDify Designer ActiveX Control cmdSave Method Access Buffer Overflow 2 (activex.rules)<br />
 2014739 &#8211; ET ACTIVEX Potential ThreeDify Designer ActiveX Control cmdExport Method Access Buffer Overflow (activex.rules)<br />
 2014740 &#8211; ET ACTIVEX Potential ThreeDify Designer ActiveX Control cmdExport Method Access Buffer Overflow 2 (activex.rules)<br />
 2014741 &#8211; ET ACTIVEX Potential ThreeDify Designer ActiveX Control cmdImport Method Access Buffer Overflow (activex.rules)<br />
 2014742 &#8211; ET ACTIVEX Potential ThreeDify Designer ActiveX Control cmdImport Method Access Buffer Overflow 2 (activex.rules)<br />
 2014743 &#8211; ET ACTIVEX Potential ThreeDify Designer ActiveX Control cmdOpen Method Access Buffer Overflow (activex.rules)<br />
 2014744 &#8211; ET ACTIVEX Potential ThreeDify Designer ActiveX Control cmdOpen Method Access Buffer Overflow 2 (activex.rules)<br />
 2014745 &#8211; ET CURRENT_EVENTS Blackhole Try Prototype Catch May 11 2012 (current_events.rules)</p>
<p> [///]     Modified active rules:     [///]</p>
<p> Open:<br />
 2014154 &#8211; ET CURRENT_EVENTS DRIVEBY PDF Containing Subform with JavaScript (current_events.rules)</p>
<p> Pro:<br />
 2804921 &#8211; ETPRO WEB_CLIENT Microsoft Excel file download &#8211; SET 1 (web_client.rules)<br />
 2804922 &#8211; ETPRO WEB_CLIENT Microsoft Excel file download &#8211; SET 2 (web_client.rules)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5112012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Daily Ruleset Update Summary 5/10/2012</title>
		<link>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5102012/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=daily-ruleset-update-summary-5102012</link>
		<comments>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5102012/#comments</comments>
		<pubDate>Fri, 11 May 2012 00:10:03 +0000</pubDate>
		<dc:creator>wmetcalf</dc:creator>
				<category><![CDATA[Daily Ruleset Update Summary]]></category>

		<guid isPermaLink="false">http://www.emergingthreatspro.com/?p=2348</guid>
		<description><![CDATA[6 new Open rules 6 new Pro rules. Quite a few fixes and tweaks on the Pro side. [+++] Added rules: [+++] Open: 2014729 &#8211; ET CURRENT_EVENTS FakeAV Landing Page &#8211; Viruses were found (current_events.rules) 2014730 &#8211; ET CURRENT_EVENTS Potential FAKEAV Download .info /[a-f0-9]{16}/ setup download (current_events.rules) 2014731 &#8211; ET TROJAN Snap Bot Checkin (trojan.rules) [...]]]></description>
			<content:encoded><![CDATA[<p>6 new Open rules 6 new Pro rules.  Quite a few fixes and tweaks on the Pro side.</p>
<p>[+++]          Added rules:          [+++]</p>
<p> Open:<br />
 2014729 &#8211; ET CURRENT_EVENTS FakeAV Landing Page &#8211; Viruses were found (current_events.rules)<br />
 2014730 &#8211; ET CURRENT_EVENTS Potential FAKEAV Download .info /[a-f0-9]{16}/ setup download (current_events.rules)<br />
 2014731 &#8211; ET TROJAN Snap Bot Checkin (trojan.rules)<br />
 2014732 &#8211; ET TROJAN Snap Bot Receiving Download Command (trojan.rules)<br />
 2014733 &#8211; ET TROJAN Snap Bot Receiving DDoS Command (trojan.rules)<br />
 2014734 &#8211; ET POLICY BitTorrent &#8211; Torrent File Downloaded (policy.rules)</p>
<p> Pro:<br />
 2804921 &#8211; ETPRO WEB_CLIENT Microsoft Excell file download &#8211; SET 1 (web_client.rules)<br />
 2804922 &#8211; ETPRO WEB_CLIENT Microsoft Excell file download &#8211; SET 2 (web_client.rules)<br />
 2804923 &#8211; ETPRO TROJAN Rootkit.Win32.Bootkor.ha CnC Traffic (trojan.rules)<br />
 2804924 &#8211; ETPRO TROJAN Trojan-Downloader.Win32.Banload.buij Checkin (trojan.rules)<br />
 2804925 &#8211; ETPRO TROJAN Trojan/Banker.Agent.bof Checkin (trojan.rules)<br />
 2804926 &#8211; ETPRO TROJAN Win32/Autorun.GN Checkin (trojan.rules)</p>
<p> [+++]  Enabled and modified rules:   [+++]</p>
<p> 2804910 &#8211; ETPRO WEB_CLIENT Microsoft Excel corrupted/hostile file invalid SXLI BIFF record (web_client.rules)<br />
 2804911 &#8211; ETPRO WEB_CLIENT Microsoft Excel corrupted/hostile file invalid MergeCells.rgref.ref8.colLast value (web_client.rules)</p>
<p> [///]     Modified active rules:     [///]</p>
<p> 2800064 &#8211; ETPRO WEB_CLIENT Microsoft Excel BIFF File Format Named Graph Record Parsing Stack Overflow (web_client.rules)<br />
 2800065 &#8211; ETPRO WEB_CLIENT Microsoft Excel Set Font Handling Code Execution (web_client.rules)<br />
 2800695 &#8211; ETPRO EXPLOIT Microsoft Excel Embedded Shockwave Flash Object Code Execution within xls (exploit.rules)<br />
 2801906 &#8211; ETPRO WEB_CLIENT Microsoft Office Excel ADO Object Parsing Code Execution &#8211; SET (web_client.rules)<br />
 2801929 &#8211; ETPRO WEB_CLIENT Microsoft Office Excel Pivot Item Index Boundary Error Memory Corruption 1 (web_client.rules)<br />
 2801930 &#8211; ETPRO WEB_CLIENT Microsoft Office Excel Pivot Item Index Boundary Error Memory Corruption 2 (web_client.rules)<br />
 2801931 &#8211; ETPRO WEB_CLIENT Microsoft Office Excel Pivot Item Index Boundary Error Memory Corruption 3 (web_client.rules)<br />
 2802020 &#8211; ETPRO WEB_CLIENT Excel File Containing Integer Overrun Vulnerability BIFF v6 Record ToolBarDef (web_client.rules)<br />
 2802021 &#8211; ETPRO WEB_CLIENT Excel File Containing Integer Overrun Vulnerability BIFF v5 Record ToolBarDef (web_client.rules)<br />
 2802022 &#8211; ETPRO WEB_CLIENT Excel File Malformed Label recType BIFF5 record (web_client.rules)<br />
 2802033 &#8211; ETPRO WEB_CLIENT Microsoft Excel Malformed CatSerRange Record Vulnerability (web_client.rules)<br />
 2802034 &#8211; ETPRO WEB_CLIENT Microsoft Excel Malformed SupBook Record Vulnerability (web_client.rules)<br />
 2802035 &#8211; ETPRO WEB_CLIENT Microsoft Excel OBJ Records Vulnerability (web_client.rules)<br />
 2802067 &#8211; ETPRO WEB_CLIENT Microsoft Excel Office Drawing Layer Remote Code Execution (web_client.rules)<br />
 2802987 &#8211; ETPRO WEB_CLIENT Microsoft Excel Insufficient Record Validation (web_client.rules)<br />
 2802991 &#8211; ETPRO WEB_CLIENT Microsoft Excel corrupted SerAuxTrend BIFF Record (web_client.rules)<br />
 2802992 &#8211; ETPRO WEB_CLIENT Microsoft Excel Corrupted SerAuxTrend BIFF Record Attack 1 (web_client.rules)<br />
 2802993 &#8211; ETPRO WEB_CLIENT Microsoft Excel Excel Improper Record Parsing Vulnerability Flowbit SET (web_client.rules)<br />
 2802995 &#8211; ETPRO WEB_CLIENT Microsoft Excel WriteAV Vulnerability Attack (web_client.rules)<br />
 2803027 &#8211; ETPRO WEB_CLIENT Microsoft Excel malformed Selection (type 0x1D) BIFF record (web_client.rules)<br />
 2803653 &#8211; ETPRO WEB_CLIENT Microsoft Excel DataFormat Record Parsing Vulnerability (web_client.rules)<br />
 2803657 &#8211; ETPRO WEB_CLIENT Microsoft Excel SHRFMLA Biff Record Vulnerability Attempt (web_client.rules)<br />
 2803659 &#8211; ETPRO WEB_CLIENT Microsoft Excel Possible AXISPARENT Biff Record Vulnerability Attempt (web_client.rules)<br />
 2803660 &#8211; ETPRO WEB_CLIENT Microsoft Excel Biff Record Vulnerability Attempt (web_client.rules)<br />
 2804141 &#8211; ETPRO WEB_CLIENT Microsoft Excell corrupted file download invalid Lel BIFF records (web_client.rules)<br />
 2804906 &#8211; ETPRO WEB_CLIENT Microsoft Excel corrupted/hostile file with invalid ObjectLink BIFF record (web_client.rules)<br />
 2804907 &#8211; ETPRO WEB_CLIENT Microsoft Excel corrupted/hostile file download invalid Window2 BIFF record (web_client.rules)<br />
 2804912 &#8211; ETPRO WEB_CLIENT RTMPmsg Traffic (web_client.rules)<br />
 2804913 &#8211; ETPRO WEB_CLIENT RTMPmsg Traffic 2 (web_client.rules)<br />
 2804914 &#8211; ETPRO TROJAN Potential Adobe Flash type confusion exploit attempt 1 (trojan.rules)<br />
 2804915 &#8211; ETPRO TROJAN Potential Adobe Flash type confusion exploit attempt 2 (trojan.rules)<br />
 2804916 &#8211; ETPRO TROJAN Potential Adobe Flash type confusion exploit attempt 3 (trojan.rules)<br />
 2804917 &#8211; ETPRO TROJAN Potential Adobe Flash type confusion exploit attempt 4 (trojan.rules)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-5102012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Daily Ruleset Update Summary 5/9/2012</title>
		<link>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-592012/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=daily-ruleset-update-summary-592012</link>
		<comments>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-592012/#comments</comments>
		<pubDate>Wed, 09 May 2012 22:31:04 +0000</pubDate>
		<dc:creator>Matthew Jonkman</dc:creator>
				<category><![CDATA[Daily Ruleset Update Summary]]></category>

		<guid isPermaLink="false">http://www.emergingthreatspro.com/?p=2345</guid>
		<description><![CDATA[&#160; 5 new open rules, 3 new Pro. &#160; Enjoy! &#160; [+++]          Added rules:          [+++] &#160; 2014724 &#8211; ET CURRENT_EVENTS Blackhole Java Exploit request to /Cal.jar (current_events.rules) 2014725 &#8211; ET CURRENT_EVENTS Possible Request for Blackhole Exploit Kit Landing Page &#8211; src.php?case= (current_events.rules) &#160; Please report issues with [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p>5 new open rules, 3 new Pro.</p>
<p>&nbsp;</p>
<p>Enjoy!</p>
<p>&nbsp;</p>
<p>[+++]          Added rules:          [+++]</p>
<p>&nbsp;</p>
<p>2014724 &#8211; ET CURRENT_EVENTS Blackhole Java Exploit request to /Cal.jar (current_events.rules)</p>
<p>2014725 &#8211; ET CURRENT_EVENTS Possible Request for Blackhole Exploit Kit Landing Page &#8211; src.php?case= (current_events.rules)</p>
<p>&nbsp;</p>
<p>Please report issues with these. disable if you haven&#8217;t control of the versions on your net of course!</p>
<p>2014726 &#8211; ET POLICY Outdated Windows Flash Version IE (policy.rules)</p>
<p>2014727 &#8211; ET POLICY Outdated Mac Flash Version (policy.rules)</p>
<p>&nbsp;</p>
<p>2014728 &#8211; ET TROJAN Smoke Loader Checkin r=gate (trojan.rules)</p>
<p>&nbsp;</p>
<p>Pro subscriber rules:</p>
<p>2804918 &#8211; ETPRO TROJAN Backdoor/MSIL.adv Checkin (trojan.rules)</p>
<p>2804919 &#8211; ETPRO TROJAN Trojan.Win32.Swisyn.cioi Checkin (trojan.rules)</p>
<p>2804920 &#8211; ETPRO TROJAN Win32/Rlsloup.gen!A Checkin (trojan.rules)</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>[///]     Modified active rules:     [///]</p>
<p>&nbsp;</p>
<p>Just renamed, thanks Eoin:</p>
<p>2014701 &#8211; ET DNS Non-DNS or Non-Compliant DNS traffic on DNS port Opcode 6 or 7 set (dns.rules)</p>
<p>2014702 &#8211; ET DNS Non-DNS or Non-Compliant DNS traffic on DNS port Opcode 8 through 15 set (dns.rules)</p>
<p>2014703 &#8211; ET DNS Non-DNS or Non-Compliant DNS traffic on DNS port Reserved Bit Set (dns.rules)</p>
<p>&nbsp;</p>
<p>2014641 &#8211; ET CURRENT_EVENTS Incognito Exploit Kit landing page request to images.php?t=4xxxxxxx (current_events.rules)</p>
<p>2014722 &#8211; ET TROJAN Medfos/Midhos Checkin (trojan.rules)</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>[---]         Removed rules:         [---]</p>
<p>&nbsp;</p>
<p>2014701 &#8211; ET TROJAN DNS Protocol Violation Opcode 6 or 7 set Possible CnC (trojan.rules)</p>
<p>2014702 &#8211; ET TROJAN DNS Protocol Violation Opcode 8 through 15 set Possible CnC (trojan.rules)</p>
<p>2014703 &#8211; ET TROJAN DNS Protocol Violation Reserved Bit Set Possible CnC (trojan.rules)</p>
<p>2803431 &#8211; ETPRO TROJAN Win32.Banbra or Related Checkin (trojan.rules)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-592012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Daily Ruleset Update Summary 5/8/2012</title>
		<link>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-582012/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=daily-ruleset-update-summary-582012</link>
		<comments>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-582012/#comments</comments>
		<pubDate>Tue, 08 May 2012 20:47:00 +0000</pubDate>
		<dc:creator>Matthew Jonkman</dc:creator>
				<category><![CDATA[Daily Ruleset Update Summary]]></category>

		<guid isPermaLink="false">http://www.emergingthreatspro.com/?p=2340</guid>
		<description><![CDATA[&#160; &#160; Happy Patch Tuesday! 12 new Pro rules, and Patch Tuesday coverage details here: &#160; Enjoy! &#160; [+++]          Added rules:          [+++] &#160; 2804906 &#8211; ETPRO WEB_CLIENT Microsoft Excel corrupted/hostile file with invalid ObjectLink BIFF record (web_client.rules) 2804907 &#8211; ETPRO WEB_CLIENT Microsoft Excel corrupted/hostile file download invalid [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Happy Patch Tuesday! 12 new Pro rules, and <a href="http://www.emergingthreatspro.com/daily-ruleset-update-summary/may-2012-patch-tuesday-coverage/" target="_blank">Patch Tuesday coverage details here</a>:</p>
<p>&nbsp;</p>
<p>Enjoy!</p>
<p>&nbsp;</p>
<p>[+++]          Added rules:          [+++]</p>
<p>&nbsp;</p>
<p>2804906 &#8211; ETPRO WEB_CLIENT Microsoft Excel corrupted/hostile file with invalid ObjectLink BIFF record (web_client.rules)</p>
<p>2804907 &#8211; ETPRO WEB_CLIENT Microsoft Excel corrupted/hostile file download invalid Window2 BIFF record (web_client.rules)</p>
<p>2804908 &#8211; ETPRO WEB_CLIENT TrueType Font Parsing Attack (web_client.rules)</p>
<p>2804909 &#8211; ETPRO WEB_CLIENT Hostile Microsoft Rich Text File (RTF) with corrupted listoverride (web_client.rules)</p>
<p>2804910 &#8211; ETPRO WEB_CLIENT Microsoft Excel corrupted/hostile file invalid SXLI BIFF record (web_client.rules)</p>
<p>2804911 &#8211; ETPRO WEB_CLIENT Microsoft Excel corrupted/hostile file invalid MergeCells.rgref.ref8.colLast value (web_client.rules)</p>
<p>2804912 &#8211; ETPRO WEB_CLIENT RTMPmsg Traffic (web_client.rules)</p>
<p>2804913 &#8211; ETPRO WEB_CLIENT RTMPmsg Traffic 2 (web_client.rules)</p>
<p>2804914 &#8211; ETPRO TROJAN Potential Adobe Flash type confusion exploit attempt 1 (trojan.rules)</p>
<p>2804915 &#8211; ETPRO TROJAN Potential Adobe Flash type confusion exploit attempt 2 (trojan.rules)</p>
<p>2804916 &#8211; ETPRO TROJAN Potential Adobe Flash type confusion exploit attempt 3 (trojan.rules)</p>
<p>2804917 &#8211; ETPRO TROJAN Potential Adobe Flash type confusion exploit attempt 4 (trojan.rules)</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>[///]     Modified active rules:     [///]</p>
<p>&nbsp;</p>
<p>2014561 &#8211; ET CURRENT_EVENTS landing page with malicious Java applet (current_events.rules)</p>
<p>2402000 &#8211; ET DROP Dshield Block Listed Source (dshield.rules)</p>
<p>2800871 &#8211; ETPRO WEB_CLIENT Microsoft Office RTF Stack Buffer Overflow (web_client.rules)</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-582012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May 2012 Patch Tuesday Coverage</title>
		<link>http://www.emergingthreatspro.com/daily-ruleset-update-summary/may-2012-patch-tuesday-coverage/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=may-2012-patch-tuesday-coverage</link>
		<comments>http://www.emergingthreatspro.com/daily-ruleset-update-summary/may-2012-patch-tuesday-coverage/#comments</comments>
		<pubDate>Tue, 08 May 2012 20:29:36 +0000</pubDate>
		<dc:creator>Matthew Jonkman</dc:creator>
				<category><![CDATA[Daily Ruleset Update Summary]]></category>
		<category><![CDATA[Microsoft Patch Tuesday]]></category>

		<guid isPermaLink="false">http://www.emergingthreatspro.com/?p=2334</guid>
		<description><![CDATA[Bulletin CVE Title Notes ET Pro Coverage MS12-029 2012-0183 RTF Mismatch Vulnerability Exploit Code Likely  2804909 MS12-030 2012-0141 xcel File Format Memory Corruption Vulnerability Difficult to Exploit  Not Reliably Sigable MS12-030 2012-0142 Excel File Format Memory Corruption in OBJECTLINK Record Vulnerability Difficult to Exploit  2804906 MS12-030 2012-0143 Excel Memory Corruption Using Various Modified Bytes Vulnerability [...]]]></description>
			<content:encoded><![CDATA[<table width="100%" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td style="height: 36.4px; width: 10%; text-align: center; border-width: 1px; border-color: #000000; border-style: solid;" align="center" valign="middle"><strong>Bulletin</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px; width: 10%;" align="center" valign="middle"><strong>CVE</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px; width: 40%;" align="center" valign="middle"><strong>Title</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px; width: 20%;" align="center" valign="middle"><strong>Notes</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px; width: 20%;" align="center" valign="middle"><strong>ET Pro Coverage</strong></td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-029">MS12-029</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0183">2012-0183</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>RTF Mismatch Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Exploit Code Likely</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"> <strong>2804909</strong></td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-030">MS12-030</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0141">2012-0141</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>xcel File Format Memory Corruption Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Difficult to Exploit</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"> Not Reliably Sigable</td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-030">MS12-030</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0142">2012-0142</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>Excel File Format Memory Corruption in OBJECTLINK Record Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Difficult to Exploit</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"> <strong>2804906</strong></td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-030">MS12-030</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0143">2012-0143</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>Excel Memory Corruption Using Various Modified Bytes Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Exploit Code Likely</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>2804907</strong></td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-030">MS12-030</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0184">2012-0184</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>Excel SXLI Record Memory Corruption Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Exploit Code Likely</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>2804910</strong></td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-030">MS12-030</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0185">2012-0185</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>Excel MergeCells Record Heap Overflow Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Difficult to Exploit</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>2804911</strong></td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-030">MS12-030</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1847">2012-1847</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>Excel Series Record Parsing Type Mismatch Could Result in Remote Code Execution Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Exploit Code Likely</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Continuing research</td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-031">MS12-031</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0018">2012-0018</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>VSD File Format Memory Corruption Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Exploit Code Likely</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Continuing research</td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-032">MS12-032</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0174">2012-0174</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>Windows Firewall Bypass Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Local Bypass Only</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">n/a</td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-032">MS12-032</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0179">2012-0179</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>TCP/IP Double Free Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Local Only</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">n/a</td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-033">MS12-033</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0178">2012-0178</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>Plug and Play (PnP) Configuration Manager Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Local Only</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"> n/a</td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-034">MS12-034</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0159">2012-0159</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>TrueType Font Parsing Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Exploit Code Likely</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>2804908</strong></td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-034">MS12-034</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0162">2012-0162</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>.NET Framework Buffer Allocation Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Exploit Code Likely</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"> Not Reliably Sigable</td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-034">MS12-034</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0165">2012-0165</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>GDI+ Record Type Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Exploit Code Likely</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Continuing Research</td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-034">MS12-034</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0167">2012-0167</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>GDI+ Heap Overflow Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Exploit Code Likely</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Continuing Research</td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-034">MS12-034</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0176">2012-0176</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>Silverlight Double-Free Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Local Only</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"> n/a</td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-034">MS12-034</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0180">2012-0180</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>Windows and Messages Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Local Only</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">n/a</td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-034">MS12-034</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0181">2012-0181</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>Keyboard Layout File Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Local Only</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">n/a</td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-034">MS12-034</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1848">2012-1848</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>Scrollbar Calculation Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Local Only</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">n/a</td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-035">MS12-035</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0160">2012-0160</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>.NET Framework Serialization Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Exploit Code Likely</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Not Reliably Sigable</td>
</tr>
<tr>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-035">MS12-035</a></strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0161">2012-0161</a></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle"><strong>.NET Framework Serialization Vulnerability</strong></td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Exploit Code Likely</td>
<td style="border-color: #000000 #000000 #000000 #000000; border-style: solid; border-width: 1.0px; height: 36.4px;" align="center" valign="middle">Not Reliably Sigable</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.emergingthreatspro.com/daily-ruleset-update-summary/may-2012-patch-tuesday-coverage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Daily Ruleset Update Summary 5/7/2012</title>
		<link>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-572012/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=daily-ruleset-update-summary-572012</link>
		<comments>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-572012/#comments</comments>
		<pubDate>Tue, 08 May 2012 01:34:32 +0000</pubDate>
		<dc:creator>Matthew Jonkman</dc:creator>
				<category><![CDATA[Daily Ruleset Update Summary]]></category>

		<guid isPermaLink="false">http://www.emergingthreatspro.com/?p=2332</guid>
		<description><![CDATA[&#160; Light update today. 7 new open rules, 4 Pro. &#160; We&#8217;re getting your patch tuesday ruleset ready, see you tomorrow! &#160; [+++]          Added rules:          [+++] &#160; Moved from malware to Policy: 2014342 &#8211; ET POLICY Snadboy.com Products User-Agent (policy.rules) &#160; 2014718 &#8211; ET GAMES Nintedo Wii User-Agent (games.rules) [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p>Light update today. 7 new open rules, 4 Pro.</p>
<p>&nbsp;</p>
<p>We&#8217;re getting your patch tuesday ruleset ready, see you tomorrow!</p>
<p>&nbsp;</p>
<p>[+++]          Added rules:          [+++]</p>
<p>&nbsp;</p>
<p>Moved from malware to Policy:</p>
<p>2014342 &#8211; ET POLICY Snadboy.com Products User-Agent (policy.rules)</p>
<p>&nbsp;</p>
<p>2014718 &#8211; ET GAMES Nintedo Wii User-Agent (games.rules)</p>
<p>2014719 &#8211; ET TROJAN W32/Simbot.Backdoor Checkin (trojan.rules)</p>
<p>2014720 &#8211; ET TROJAN W32/Downloader/Agent.dxh.1 Reporting to CnC (trojan.rules)</p>
<p>&nbsp;</p>
<p>Based on leaked bot code, interesting case. See references:</p>
<p>2014721 &#8211; ET TROJAN Boatz Checkin (trojan.rules)</p>
<p>&nbsp;</p>
<p>2014722 &#8211; ET TROJAN Medfos/Midhos Checkin (trojan.rules)</p>
<p>2014723 &#8211; ET TROJAN Suspicious lcon http header in response seen with Medfos/Midhos downloader (trojan.rules)</p>
<p>&nbsp;</p>
<p>Pro Subscriber rules:</p>
<p>2804903 &#8211; ETPRO TROJAN W32/Troj_Generic.BNJME Checkin (trojan.rules)</p>
<p>2804904 &#8211; ETPRO TROJAN Trojan.Autoit-124 Checkin (trojan.rules)</p>
<p>2804905 &#8211; ETPRO TROJAN Win32/Horst.gen!C Checkin (trojan.rules)</p>
<p>&nbsp;</p>
<p>Moved from Malware to Policy:</p>
<p>2803915 &#8211; ETPRO POLICY OpenInstall.com Install (policy.rules)</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>[///]     Modified active rules:     [///]</p>
<p>&nbsp;</p>
<p>Perf tweak, thanks Eoin:</p>
<p>2014285 &#8211; ET DNS DNS Query for Suspicious .ch.vu Domain (dns.rules)</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>[---]  Disabled and modified rules:  [---]</p>
<p>&nbsp;</p>
<p>Getting FPs on some legit-&#8221;ish&#8221; games as well as the trojan. Researching:</p>
<p>2801402 &#8211; ETPRO TROJAN Generic Gui Trojan Hacker Tool Request to Controller (trojan.rules)</p>
<p>2801403 &#8211; ETPRO TROJAN Generic Gui Trojan Hacker Tool Response from Controller Execute File (trojan.rules)</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-572012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Daily Ruleset Update Summary 5/4/2012</title>
		<link>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-542012/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=daily-ruleset-update-summary-542012</link>
		<comments>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-542012/#comments</comments>
		<pubDate>Sat, 05 May 2012 00:18:06 +0000</pubDate>
		<dc:creator>Matthew Jonkman</dc:creator>
				<category><![CDATA[Daily Ruleset Update Summary]]></category>

		<guid isPermaLink="false">http://www.emergingthreatspro.com/?p=2329</guid>
		<description><![CDATA[11 new rules today. 1 Pro and 10 open sigs. &#160; Note the changes to teh BotCC RUles, which sholdn&#8217;t affect configs. &#160; Have a great weekend! &#160; &#160; [+++]          Added rules:          [+++] &#160; 2014708 &#8211; ET ACTIVEX Possible McAfee Virtual Technician MVT.MVTControl.6300 ActiveX Control GetObject method [...]]]></description>
			<content:encoded><![CDATA[<p>11 new rules today. 1 Pro and 10 open sigs.</p>
<p>&nbsp;</p>
<p>Note the changes to teh BotCC RUles, which sholdn&#8217;t affect configs.</p>
<p>&nbsp;</p>
<p>Have a great weekend!</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>[+++]          Added rules:          [+++]</p>
<p>&nbsp;</p>
<p>2014708 &#8211; ET ACTIVEX Possible McAfee Virtual Technician MVT.MVTControl.6300 ActiveX Control GetObject method Remote Code Execution (activex.rules)</p>
<p>2014709 &#8211; ET ACTIVEX Possible McAfee Virtual Technician MVT.MVTControl.6300 ActiveX Control GetObject method Remote Code Execution 2 (activex.rules)</p>
<p>2014710 &#8211; ET ACTIVEX Possible Samsung NET-i Viewer Active-X SEH Overwrite (activex.rules)</p>
<p>2014711 &#8211; ET WEB_SPECIFIC_APPS maxxweb Cms kategorie parameter Cross-Site Scripting Attempt (web_specific_apps.rules)</p>
<p>2014712 &#8211; ET WEB_SPECIFIC_APPS WordPress WPsc-MijnPress plugin rwflush parameter Cross-Site Scripting Attempt (web_specific_apps.rules)</p>
<p>2014713 &#8211; ET ACTIVEX Possible WebEx UCF atucfobj.dll ActiveX NewObject Method Buffer Overflow (activex.rules)</p>
<p>2014714 &#8211; ET ACTIVEX Possible WebEx UCF atucfobj.dll ActiveX NewObject Method Buffer Overflow 2 (activex.rules)</p>
<p>2014715 &#8211; ET WEB_SPECIFIC_APPS Joomla com_obsuggest controller parameter Local File Inclusion Attempt (web_specific_apps.rules)</p>
<p>2014716 &#8211; ET WEB_SPECIFIC_APPS Joomla com_joomtouch controller parameter Local File Inclusion Attempt (web_specific_apps.rules)</p>
<p>2014717 &#8211; ET WEB_SPECIFIC_APPS WordPress WP Custom Pages url parameter Local File Inclusion Attempt (web_specific_apps.rules)</p>
<p>&nbsp;</p>
<p>Pro:</p>
<p>2804902 &#8211; ETPRO MALWARE Adware.Downware.23 Install 2 (malware.rules)</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>[///]     Modified active rules:     [///]</p>
<p>&nbsp;</p>
<p>2014704 &#8211; ET WEB_SPECIFIC_APPS PHP-CGI query string parameter vulnerability (web_specific_apps.rules)</p>
<p>2402000 &#8211; ET DROP Dshield Block Listed Source (dshield.rules)</p>
<p>2804883 &#8211; ETPRO CURRENT_EVENTS mass SQL Injection campaigns targeting Microsoft IIS web server (ASP/ASP.Net/CFM/MS-SQL) sites (current_events.rules)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.emergingthreatspro.com/daily-ruleset-update-summary/daily-ruleset-update-summary-542012/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

