<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1898567896429290968</id><updated>2011-07-28T22:05:55.223+05:30</updated><category term='Activex'/><category term='IDS Rule'/><category term='snort'/><title type='text'>Intrusion Detection</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://intrusion-detection.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://intrusion-detection.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>xsy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>11</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1898567896429290968.post-7247334152339059837</id><published>2009-07-16T11:03:00.009+05:30</published><updated>2009-07-16T11:21:13.613+05:30</updated><title type='text'>AwingSoft Web3D Player (WindsPly.ocx) "SceneURL()" Remote Buffer Overflow</title><content type='html'>&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;Overview:&lt;/span&gt;&lt;br /&gt;A vulnerability has been reported in Awingsoft Winds3D Viewer, which can be exploited by malicious people to compromise a user's system.&lt;br /&gt;&lt;br /&gt;A boundary error in the handling of the "SceneUrl()" method can be exploited to cause a heap-based buffer overflow by supplying an overly long argument.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;Impact:&lt;/span&gt;&lt;br /&gt;Successful exploitation allows execution of arbitrary code.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;Affected Software:&lt;/span&gt;&lt;br /&gt;Awingsoft Winds3D Viewer 3.5.0.0 Beta&lt;br /&gt;Awingsoft Winds3D Viewer 3.0.0.5&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;Vulnerable Version:&lt;/span&gt;&lt;br /&gt;The Vulnerability is confirmed in Awingsoft Winds3D Viewer 3.5.0.0 Beta and Awingsoft Winds3D Viewer 3.0.0.5. Other versions may also be affected.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;Solution:&lt;/span&gt;&lt;br /&gt;Disable the plug-in.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;References:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://secunia.com/advisories/35764/"&gt;http://secunia.com/advisories/35764/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://milw0rm.com/exploits/9116"&gt;http://milw0rm.com/exploits/9116&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.shinnai.net/xplits/TXT_nsGUdeley3EHfKEV690p.html"&gt;http://www.shinnai.net/xplits/TXT_nsGUdeley3EHfKEV690p.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;IDS Rule:&lt;/span&gt;&lt;br /&gt;alert tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any (msg:"Awingsoft Web3D Player Remote Buffer Overflow"; flow:to_client,established; content:"clsid"; nocase; content:"17A54E7D-A9D4-11D8-9552-00E04CB09903"; nocase; distance:0; content:"SceneURL"; nocase; classtype:web-application-attack; reference:url,secunia.com/advisories/35764/; reference:url,milw0rm.com/exploits/9116; reference:url,shinnai.net/xplits/TXT_nsGUdeley3EHfKEV690p.html; sid:2009xxxx; rev:1;)&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;CVSS Base Score:&lt;/span&gt; 9.3&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;Risk factor:&lt;/span&gt; High&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1898567896429290968-7247334152339059837?l=intrusion-detection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://intrusion-detection.blogspot.com/feeds/7247334152339059837/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1898567896429290968&amp;postID=7247334152339059837' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/7247334152339059837'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/7247334152339059837'/><link rel='alternate' type='text/html' href='http://intrusion-detection.blogspot.com/2009/07/awingsoft-web3d-player-windsplyocx.html' title='AwingSoft Web3D Player (WindsPly.ocx) &quot;SceneURL()&quot; Remote Buffer Overflow'/><author><name>mayur</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1898567896429290968.post-9196560459600620616</id><published>2009-06-19T11:54:00.002+05:30</published><updated>2009-06-19T11:58:25.379+05:30</updated><title type='text'>EDraw PDF Viewer ActiveX Control "FtpDownloadFile()" Insecure Method</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: verdana; font-weight: bold; color: rgb(255, 153, 102);"&gt;Overview:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;A vulnerability has been reported in the EDraw PDF Viewer ActiveX control, which can be exploited by malicious people to compromise a user's system.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;The vulnerability is caused due to FtpConnect() function, which could download any file from remote FTP server and put on user's disk and an insecure "FtpDownloadFile()" method. This can be exploited to download files to arbitrary locations on a user's system when visiting a malicious website.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana; font-weight: bold; color: rgb(255, 153, 102);"&gt;Impact:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Successful exploitation allows execution of arbitrary code.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana; font-weight: bold; color: rgb(255, 153, 102);"&gt;Affected Software:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Edraw PDF Viewer Component 3.2.0.126.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana; font-weight: bold; color: rgb(255, 153, 102);"&gt;Vulnerability Version:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;The vulnerability has been reported in Edraw PDF Viewer Component 3.2.0.126. Other versions may also be affected.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana; font-weight: bold; color: rgb(255, 153, 102);"&gt;Solution:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Set the kill-bit for the affected ActiveX control.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana; font-weight: bold; color: rgb(255, 153, 102);"&gt;References:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;http://secunia.com/advisories/35509/&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;http://archives.neohapsis.com/archives/fulldisclosure/2009-06/0198.html&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana; font-weight: bold; color: rgb(255, 153, 102);"&gt;IDS Rule:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;alert tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any (msg:"EDraw PDF Viewer ActiveX Control Insecure Method"; flow:to_client,established; content:"clsid"; nocase; content:"44A8091F-8F01-43B7-8CF7-4BBA71E61E04"; nocase; distance:0; pcre:"/(FtpConnect|FtpDownloadFile)/i"; classtype:web-application-attack; reference:url,secunia.com/advisories/35509/; reference:url,archives.neohapsis.com/archives/fulldisclosure/2009-06/0198.html; sid:xxxxxxxx; rev:1;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt; CVSS Base Score:&lt;/span&gt; 9.3&lt;/span&gt;&lt;br /&gt; &lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Risk factor:&lt;/span&gt; High&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1898567896429290968-9196560459600620616?l=intrusion-detection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://intrusion-detection.blogspot.com/feeds/9196560459600620616/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1898567896429290968&amp;postID=9196560459600620616' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/9196560459600620616'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/9196560459600620616'/><link rel='alternate' type='text/html' href='http://intrusion-detection.blogspot.com/2009/06/edraw-pdf-viewer-activex-control.html' title='EDraw PDF Viewer ActiveX Control &quot;FtpDownloadFile()&quot; Insecure Method'/><author><name>Niranjan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='http://2.bp.blogspot.com/_1lYUwYbRqJs/ShPnuYKjreI/AAAAAAAAAAM/sLRjmr5ttcA/S220/xmen3poster.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1898567896429290968.post-270048269741745843</id><published>2009-06-19T11:21:00.002+05:30</published><updated>2009-06-19T11:48:29.186+05:30</updated><title type='text'>McAfee Policy Manager 'naPolicyManager.dll' Arbitrary File Overwrite Vulnerability</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: verdana; font-weight: bold; color: rgb(255, 153, 102);"&gt;Overview:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;McAfee Policy Manager is prone to a vulnerability that lets attackers overwrite files with arbitrary, attacker-controlled content system.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;A remote user can create specially crafted HTML that, when loaded by the target user, will invoke the WriteTaskDataToIniFile() method in the 'naPolicyManager.dll' ActiveX control and overwrite files on the target system with the privileges of the target user. A remote user can exploit this to cause arbitrary code to be executed on the target user's system.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana; font-weight: bold; color: rgb(255, 153, 102);"&gt;Impact:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;An attacker can exploit this issue to corrupt or overwrite arbitrary '.ini' files on a victim's computer in the context of the application using the ActiveX control (typically Internet Explorer). Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana; font-weight: bold; color: rgb(255, 153, 102);"&gt;Affected software:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;McAfee Policy Manager 0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana; font-weight: bold; color: rgb(255, 153, 102);"&gt;Solution:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Set the kill-bit for the affected ActiveX control.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana; font-weight: bold; color: rgb(255, 153, 102);"&gt;References:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;http://www.securityfocus.com/bid/35404/&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;http://securitytracker.com/alerts/2009/Jun/1022413.html&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;http://milw0rm.com/exploits/8970&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana; font-weight: bold; color: rgb(255, 153, 102);"&gt;IDS Rule:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;alert tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any (msg:"McAfee Policy Manager naPolicyManager.dll ActiveX Control Arbitrary File Overwrite"; flow:to_client,established; content:"clsid"; nocase; content:"04D18721-749F-4140-AEB0-CAC099CA4741"; nocase; distance:0; content:"WriteTaskDataToIniFile"; nocase; classtype:web-application-attack; reference:url,securitytracker.com/alerts/2009/Jun/1022413.html; reference:bugtraq,35404; reference:url,milw0rm.com/exploits/8970; sid:xxxxxxx; rev:1;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: verdana; font-weight: bold; color: rgb(255, 153, 102);"&gt;CVSS Score Report:&lt;/span&gt;&lt;span style="font-family: verdana;"&gt; 9.3 &lt;/span&gt;&lt;br /&gt; &lt;span style="font-family: verdana;"&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Risk factor:&lt;/span&gt; High&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1898567896429290968-270048269741745843?l=intrusion-detection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://intrusion-detection.blogspot.com/feeds/270048269741745843/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1898567896429290968&amp;postID=270048269741745843' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/270048269741745843'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/270048269741745843'/><link rel='alternate' type='text/html' href='http://intrusion-detection.blogspot.com/2009/06/mcafee-policy-manager.html' title='McAfee Policy Manager &apos;naPolicyManager.dll&apos; Arbitrary File Overwrite Vulnerability'/><author><name>Niranjan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='http://2.bp.blogspot.com/_1lYUwYbRqJs/ShPnuYKjreI/AAAAAAAAAAM/sLRjmr5ttcA/S220/xmen3poster.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1898567896429290968.post-119953662626113153</id><published>2009-06-09T16:40:00.004+05:30</published><updated>2009-06-09T17:06:42.244+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='snort'/><category scheme='http://www.blogger.com/atom/ns#' term='IDS Rule'/><category scheme='http://www.blogger.com/atom/ns#' term='Activex'/><title type='text'>SAP AG SAPgui 'sapirrfc.dll' ActiveX Control Buffer Overflow Vulnerability</title><content type='html'>&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;span style="color: rgb(255, 153, 102); font-weight: bold;"&gt;Overview:&lt;/span&gt;&lt;br /&gt;SAP AG SAPgui (sapirrfc.dll) is vulnerable to a buffer overflow. By persuading a victim to visit a specially-crafted Web page that passes an overly long string to the Accept() method, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the victim or cause the victim's browser to crash.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Impact:&lt;/span&gt;&lt;br /&gt;Successfully exploiting these issues allows an attacker to to execute arbitrary code within the context of an application that uses the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in a denial-of-service condition.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Affected Software:&lt;/span&gt;&lt;br /&gt;SAP AG SAPgui 6.4&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Vulnerable version:&lt;/span&gt;&lt;br /&gt;SAPgui 6.4 is vulnerable; other versions may also be affected.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Solution:&lt;/span&gt;&lt;br /&gt;Set the kill-bit for the affected ActiveX control.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Reference:&lt;/span&gt;&lt;br /&gt;http://www.securityfocus.com/bid/35256/&lt;br /&gt;http://xforce.iss.net/xforce/xfdb/50977&lt;br /&gt;http://milw0rm.com/exploits/8899&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;IDS Rule:&lt;/span&gt;&lt;br /&gt;alert tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any (msg:"SAP AG SAPgui sapirrfc.dll ActiveX Control Buffer Overflow"; flow:to_client,established; content:"clsid"; nocase; content:"77F12F8A-F117-11D0-8CF1-00A0C91D9D87"; nocase; distance:0; content:"Accept"; nocase; classtype:web-application-attack; reference:url,xforce.iss.net/xforce/xfdb/50977; reference:bugtraq,35256; reference:url,milw0rm.com/exploits/8899; sid:20090320; rev:1;)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;CVSS Base Score:&lt;/span&gt; 9.3&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Risk factor:&lt;/span&gt; High&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1898567896429290968-119953662626113153?l=intrusion-detection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://intrusion-detection.blogspot.com/feeds/119953662626113153/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1898567896429290968&amp;postID=119953662626113153' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/119953662626113153'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/119953662626113153'/><link rel='alternate' type='text/html' href='http://intrusion-detection.blogspot.com/2009/06/sap-ag-sapgui-sapirrfcdll-activex.html' title='SAP AG SAPgui &apos;sapirrfc.dll&apos; ActiveX Control Buffer Overflow Vulnerability'/><author><name>Niranjan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='http://2.bp.blogspot.com/_1lYUwYbRqJs/ShPnuYKjreI/AAAAAAAAAAM/sLRjmr5ttcA/S220/xmen3poster.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1898567896429290968.post-9106427239892567296</id><published>2009-06-04T12:28:00.005+05:30</published><updated>2009-06-04T14:27:40.718+05:30</updated><title type='text'>What is the difference between offset, distance, depth and within of SNORT modifiers?</title><content type='html'>&lt;span style=";font-family:verdana;font-size:85%;"  &gt;All content matches and modifiers start from the first byte of the payload. None of them will look in the header, that's all parsed and can be matched using other directives.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Depth&lt;/span&gt; is how far to &lt;span style="font-weight: bold;"&gt;LOOK&lt;/span&gt; into the payload from the &lt;span style="font-weight: bold;"&gt;start of the payload&lt;/span&gt;.&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Distance&lt;/span&gt; is how far to &lt;span style="font-weight: bold;"&gt;SKIP&lt;/span&gt; from the&lt;span style="font-weight: bold;"&gt; LAST byte of the previous match&lt;/span&gt; before looking for the current match&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Offset&lt;/span&gt; is how far to &lt;span style="font-weight: bold;"&gt;SKIP&lt;/span&gt; into the packet from the &lt;span style="font-weight: bold;"&gt;beginning of the payload&lt;/span&gt; before looking for the current match&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Within&lt;/span&gt; says only look in the &lt;span style="font-weight: bold;"&gt;NEXT&lt;/span&gt; x bytes &lt;span style="font-weight: bold;"&gt;AFTER&lt;/span&gt; the &lt;span style="font-weight: bold;"&gt;last byte of the last content match&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;So offset and depth are from the start of payload and often used together, distance and within are similar but relevant to the last content match.&lt;br /&gt;&lt;br /&gt;Taken from Emerging Threats......... &lt;/span&gt;&lt;img src="file:///tmp/moz-screenshot-8.jpg" alt="" /&gt;&lt;img src="file:///tmp/moz-screenshot-9.jpg" alt="" /&gt;&lt;img src="file:///tmp/moz-screenshot.jpg" alt="" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1898567896429290968-9106427239892567296?l=intrusion-detection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://intrusion-detection.blogspot.com/feeds/9106427239892567296/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1898567896429290968&amp;postID=9106427239892567296' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/9106427239892567296'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/9106427239892567296'/><link rel='alternate' type='text/html' href='http://intrusion-detection.blogspot.com/2009/06/what-is-difference-between-offset.html' title='What is the difference between offset, distance, depth and within of SNORT modifiers?'/><author><name>Niranjan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='http://2.bp.blogspot.com/_1lYUwYbRqJs/ShPnuYKjreI/AAAAAAAAAAM/sLRjmr5ttcA/S220/xmen3poster.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1898567896429290968.post-4077498799534239794</id><published>2009-06-02T14:37:00.002+05:30</published><updated>2009-06-09T17:07:57.544+05:30</updated><category scheme='http://www.blogger.com/atom/ns#' term='snort'/><category scheme='http://www.blogger.com/atom/ns#' term='IDS Rule'/><category scheme='http://www.blogger.com/atom/ns#' term='Activex'/><title type='text'>Roxio CinePlayer IAManager.dll ActiveX control buffer overflow</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="color: rgb(255, 153, 102); font-weight: bold;font-family:verdana;" &gt;Overview:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Roxio CinePlayer ActiveX control (IAManager.dll) is vulnerable to a heap-based buffer overflow exploit. It persuades  a victim to visit a specially-crafted Web page that passes an overly long string to the SetIAPlayerName() method.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 102); font-weight: bold;font-family:verdana;" &gt;Impact:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;A Successful exploitation could overflow a buffer and execute arbitrary code on the system with the privileges of the victim or cause the victim's browser to crash.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);font-family:verdana;" &gt;Affected Software:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Roxio, CinePlayer 3.2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);font-family:verdana;" &gt;Solution:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Set the kill-bit for the affected ActiveX control.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);font-family:verdana;" &gt;References:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;http://xforce.iss.net/xforce/xfdb/50868&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;http://milw0rm.com/exploits/8835              &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);font-family:verdana;" &gt;IDS Rule:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;alert tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any (msg:"Roxio CinePlayer IAManager.dll ActiveX Control Buffer Overflow"; flow:to_client,established; content:"clsid"; nocase; content:"EE1BBA18-F0C8-477E-8AC8-C28B94F1B7DC"; nocase; distance:0; content:"SetIAPlayerName"; nocase; classtype:web-application-attack; reference:url,xforce.iss.net/xforce/xfdb/50868; reference:url,milw0rm.com/exploits/8835; sid:1000095; rev:1;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;CVSS Base Score:&lt;/span&gt; 9.3 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Risk factor:&lt;/span&gt; High&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1898567896429290968-4077498799534239794?l=intrusion-detection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://intrusion-detection.blogspot.com/feeds/4077498799534239794/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1898567896429290968&amp;postID=4077498799534239794' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/4077498799534239794'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/4077498799534239794'/><link rel='alternate' type='text/html' href='http://intrusion-detection.blogspot.com/2009/06/roxio-cineplayer-iamanagerdll-activex.html' title='Roxio CinePlayer IAManager.dll ActiveX control buffer overflow'/><author><name>Niranjan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='http://2.bp.blogspot.com/_1lYUwYbRqJs/ShPnuYKjreI/AAAAAAAAAAM/sLRjmr5ttcA/S220/xmen3poster.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1898567896429290968.post-3934193273706567220</id><published>2009-06-02T14:21:00.002+05:30</published><updated>2009-06-02T14:27:36.285+05:30</updated><title type='text'>Roxio CinePlayer SonicDVDDashVRNav.DLL ActiveX Control Remote Buffer Overflow Vulnerability</title><content type='html'>&lt;span style="font-family: verdana;font-size:85%;" &gt;&lt;span style="color: rgb(255, 153, 102); font-weight: bold;"&gt;Overview:&lt;/span&gt;&lt;br /&gt;Roxio CinePlayer is prone to a stack-based buffer-overflow vulnerability because it fails to sufficiently check boundaries of user-supplied input before copying it to an insufficiently sized memory buffer.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Impact:&lt;/span&gt;&lt;br /&gt;Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of applications using the affected ActiveX control and to compromise affected computers. Failed attempts will likely result in denial-of-service conditions.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Affected Software:&lt;/span&gt;&lt;br /&gt;Roxio CinePlayer 3.2&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Vulnerable version:&lt;/span&gt;&lt;br /&gt;Roxio CinePlayer 3.2 is vulnerable to this issue; other versions may also be affected.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Solution:&lt;/span&gt;&lt;br /&gt;Remove or Set the kill-bit for the affected ActiveX control.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Reference:&lt;/span&gt;&lt;br /&gt;http://www.securityfocus.com/bid/23412/&lt;br /&gt;http://milw0rm.com/exploits/8824&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;IDS Rule:&lt;/span&gt;&lt;br /&gt;alert tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any (msg:"WEB-ATTACKS Roxio CinePlayer SonicDVDDashVRNav.DLL ActiveX Control Remote Buffer Overflow"; flow:to_client,established; content:"clsid"; nocase; content:"9F1363DA-0220-462E-B923-9E3C9038896F"; nocase; distance:0; content:"DiskType"; nocase; classtype:web-application-attack; reference:url,milw0rm.com/exploits/8824;reference:bugtraq,23412; sid:20090263; rev:1;)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;CVSS Base Score:&lt;/span&gt; 9.3&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt;Risk factor :&lt;/span&gt; High&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1898567896429290968-3934193273706567220?l=intrusion-detection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://intrusion-detection.blogspot.com/feeds/3934193273706567220/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1898567896429290968&amp;postID=3934193273706567220' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/3934193273706567220'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/3934193273706567220'/><link rel='alternate' type='text/html' href='http://intrusion-detection.blogspot.com/2009/06/roxio-cineplayer-sonicdvddashvrnavdll.html' title='Roxio CinePlayer SonicDVDDashVRNav.DLL ActiveX Control Remote Buffer Overflow Vulnerability'/><author><name>Niranjan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='http://2.bp.blogspot.com/_1lYUwYbRqJs/ShPnuYKjreI/AAAAAAAAAAM/sLRjmr5ttcA/S220/xmen3poster.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1898567896429290968.post-7840668048050235313</id><published>2009-05-27T15:14:00.006+05:30</published><updated>2009-05-27T15:43:02.026+05:30</updated><title type='text'>Sun Java Runtime Environment ActiveX Control Multiple Remote Buffer Overflow Vulnerabilities</title><content type='html'>&lt;span style="color: rgb(255, 153, 102); font-weight: bold;"&gt;Overview:&lt;/span&gt; Sun Java Runtime Environment is prone to multiple remote buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied data.&lt;br /&gt;&lt;br /&gt;By persuading a victim to visit a specially-crafted Web page that passes an overly long string to the setInstallerType, setAdditionalPackages, installLatestJRE, compareVersion, installJRE, getStaticCLSID and launch methods, a remote attacker could overflow a buffer and execute arbitrary code on the system with the privileges of the victim or cause the victim's browser to crash.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;Impact:&lt;/span&gt; Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in denial-of-service conditions.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;Affected Software:&lt;/span&gt;&lt;br /&gt;Sun JRE 6.0 Update 7&lt;br /&gt;Sun JRE 6.0 Update 6&lt;br /&gt;Sun JRE 6.0 Update 5&lt;br /&gt;Sun JRE 6.0 Update 4&lt;br /&gt;Sun JRE 6.0 Update 3&lt;br /&gt;Sun JRE 6.0 Update 2&lt;br /&gt;Sun JRE 6.0 Update 13&lt;br /&gt;Sun JRE 6.0 Update 12&lt;br /&gt;Sun JRE 6.0 Update 11&lt;br /&gt;Sun JRE 6.0 Update 10&lt;br /&gt;Sun JRE 6.0 Update 1&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;Vulnerable Version:&lt;/span&gt; Java Runtime Environment 6 Update 13 is vulnerable; other versions may also be affected.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;Solution:&lt;/span&gt; Remove or set the killbit for the affected control.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;IDS rule:&lt;/span&gt;&lt;br /&gt;alert tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any (msg:"WEB-ATTACKS Sun Java Runtime Environment ActiveX Control Multiple Remote Buffer Overflow"; flow:to_client,established; content:"clsid"; nocase; content:"CAFEEFAC-DEC7-0000-0000-ABCDEFFEDCBA"; nocase; distance:0; pcre:"/(setInstallerType|setAdditionalPackages|installLatestJRE|compareVersion|installJRE|getStaticCLSID|launch)/i"; classtype:web-application-attack; reference:url,xforce.iss.net/xforce/xfdb/50508; reference:bugtraq,34931; reference:url,milw0rm.com/exploits/8665; sid:1000092; rev:1;)&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;References:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://xforce.iss.net/xforce/xfdb/50508"&gt;http://xforce.iss.net/xforce/xfdb/50508&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/34931/"&gt;http://www.securityfocus.com/bid/34931&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.milw0rm.com/exploits/8665"&gt;http://www.milw0rm.com/exploits/8665&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;CVSS Base Score:&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt; &lt;/span&gt;9.3&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0); font-weight: bold;"&gt;Risk factor:&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 102, 0);"&gt; &lt;/span&gt;High&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1898567896429290968-7840668048050235313?l=intrusion-detection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://intrusion-detection.blogspot.com/feeds/7840668048050235313/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1898567896429290968&amp;postID=7840668048050235313' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/7840668048050235313'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/7840668048050235313'/><link rel='alternate' type='text/html' href='http://intrusion-detection.blogspot.com/2009/05/sun-java-runtime-environment-activex.html' title='Sun Java Runtime Environment ActiveX Control Multiple Remote Buffer Overflow Vulnerabilities'/><author><name>mayur</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1898567896429290968.post-7374783442650425905</id><published>2009-05-23T17:18:00.007+05:30</published><updated>2009-05-23T18:33:00.596+05:30</updated><title type='text'>Chinagames ActiveX Control 'CreateChinagames()' Buffer Overflow Vulnerability</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 0);font-family:verdana;" &gt;Overview:&lt;/span&gt;&lt;span style="font-family:verdana;"&gt; Chinagames ActiveX control is prone to a stack-based buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;br /&gt;The vulnerability is caused due to a boundary error in the bundled CGAgent ActiveX control (CGAgent.dll). This can be exploited to cause a stack-based buffer overflow by passing an overly long argument to the "CreateChinagames()" method.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 0);font-family:verdana;" &gt;&lt;br /&gt;Impact:&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;Successfully exploiting these issues allows an attacker to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 0);font-family:verdana;" &gt; Affected Software:&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;Chinagames 2009&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 0);font-family:verdana;" &gt;Solution:&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;Set the kill-bit for the affected ActiveX control.&lt;/span&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" class="moz-txt-link-freetext" href="http://secunia.com/advisories/35005/"&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 102);"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 0);"&gt;IDS Rule:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;alert tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any (msg:"Chinagames ActiveX Control CreateChinagames Method Buffer Overflow"; flow:to_client,established; content:"clsid"; nocase; content:"75108B29-202F-493C-86C5-1C182A485C4C"; nocase; distance:0; content:"CreateChinagames"; nocase; classtype:web-application-attack; reference:bugtraq,34871; reference:url,milw0rm.com/exploits/8758; sid:200900053; rev:1;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 0);font-family:verdana;" &gt;Reference:&lt;br /&gt;&lt;/span&gt;&lt;a style="font-family: verdana;" class="moz-txt-link-freetext" href="http://www.securityfocus.com/bid/34871/"&gt;http://www.securityfocus.com/bid/34871/&lt;/a&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" class="moz-txt-link-freetext" href="http://milw0rm.com/exploits/8758"&gt;http://milw0rm.com/exploits/8758&lt;/a&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" class="moz-txt-link-freetext" href="http://secunia.com/advisories/35005/"&gt;http://secunia.com/advisories/35005/&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 0);"&gt;CVSS Base Score:&lt;/span&gt;  9.3 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 0);"&gt;Risk factor:&lt;/span&gt;  High &lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1898567896429290968-7374783442650425905?l=intrusion-detection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://intrusion-detection.blogspot.com/feeds/7374783442650425905/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1898567896429290968&amp;postID=7374783442650425905' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/7374783442650425905'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/7374783442650425905'/><link rel='alternate' type='text/html' href='http://intrusion-detection.blogspot.com/2009/05/chinagames-activex-control.html' title='Chinagames ActiveX Control &apos;CreateChinagames()&apos; Buffer Overflow Vulnerability'/><author><name>Niranjan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='http://2.bp.blogspot.com/_1lYUwYbRqJs/ShPnuYKjreI/AAAAAAAAAAM/sLRjmr5ttcA/S220/xmen3poster.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1898567896429290968.post-4390927677885501915</id><published>2009-05-23T16:35:00.011+05:30</published><updated>2009-05-23T18:34:03.309+05:30</updated><title type='text'>BaoFeng Storm ActiveX Control 'SetAttributeValue()' Buffer Overflow Vulnerability</title><content type='html'>&lt;b style="font-weight: bold;"&gt;&lt;span class="title"&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span class="title"&gt;&lt;span style="color: rgb(255, 102, 0);"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 0);"&gt;Overview&lt;/span&gt;:&lt;/span&gt; &lt;/span&gt;BaoFeng Storm ActiveX control is prone to a buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input.&lt;br /&gt;&lt;br /&gt;The issue affects the 'SetAttributeValue()' function of the 'Config.dll' control identified by CLSID:&lt;br /&gt;BD103B2B-30FB-4F1E-8C17-D8F6AADBCC05.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 102, 0);"&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 0);"&gt;Impact&lt;/span&gt;:&lt;/span&gt; An attacker can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 0);"&gt;Affected software:&lt;/span&gt;&lt;br /&gt;BaoFeng Storm 2.7.9.10&lt;br /&gt;BaoFeng Storm 2.7.9.8&lt;br /&gt;BaoFeng Storm 2.8&lt;br /&gt;BaoFeng Storm 2.8&lt;br /&gt;BaoFeng Storm 2.9&lt;br /&gt;BaoFeng Storm 3.09.03.25&lt;br /&gt;BaoFeng Storm 3.09.03.30&lt;br /&gt;BaoFeng Storm 3.09.04.17&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 0);"&gt;Solution:&lt;/span&gt; Set the kill-bit for the affected ActiveX control.&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color: rgb(255, 153, 0);"&gt;IDS Rule:&lt;/span&gt;&lt;/strong&gt; alert tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any (msg:"BaoFeng Storm ActiveX Control SetAttributeValue Method Buffer Overflow"; flow:to_client,established; content:"clsid"; nocase; content:"BD103B2B-30FB-4F1E-8C17-D8F6AADBCC05"; nocase; distance:0; content:"SetAttributeValue"; nocase; classtype:web-application-attack; reference:bugtraq,34869; reference:url,juniper.net/security/auto/vulnerabilities/vuln34869.html; reference:url,vupen.com/english/advisories/2009/1392; reference:url,milw0rm.com/exploits/8757; sid:900001; rev:1;)&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="color: rgb(255, 153, 0);"&gt;&lt;span style="font-weight: bold;"&gt;References&lt;/span&gt;:&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;a class="moz-txt-link-freetext" style="font-family: verdana;" href="http://www.securityfocus.com/bid/34869/"&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;http://www.securityfocus.com/bid/34869/&lt;/span&gt;&lt;/a&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt; ; &lt;/span&gt;&lt;a class="moz-txt-link-freetext" style="font-family: verdana;" href="http://vupen.com/english/advisories/2009/1392"&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;http://vupen.com/english/advisories/2009/1392&lt;/span&gt;&lt;/a&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt; ; &lt;/span&gt;&lt;a class="moz-txt-link-freetext" style="font-family: verdana;" href="http://www.juniper.net/security/auto/vulnerabilities/vuln34869.html"&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;http://www.juniper.net/security/auto/vulnerabilities/vuln34869.html&lt;/span&gt;&lt;/a&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt; ; &lt;/span&gt;&lt;a class="moz-txt-link-freetext" style="font-family: verdana;" href="http://milw0rm.com/exploits/8757"&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;http://milw0rm.com/exploits/8757&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 0);"&gt;CVSS Base Score:&lt;/span&gt; 9.3&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 153, 0);"&gt;Risk factor:&lt;/span&gt; High &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1898567896429290968-4390927677885501915?l=intrusion-detection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://intrusion-detection.blogspot.com/feeds/4390927677885501915/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1898567896429290968&amp;postID=4390927677885501915' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/4390927677885501915'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/4390927677885501915'/><link rel='alternate' type='text/html' href='http://intrusion-detection.blogspot.com/2009/05/baofeng-storm-activex-control.html' title='BaoFeng Storm ActiveX Control &apos;SetAttributeValue()&apos; Buffer Overflow Vulnerability'/><author><name>Niranjan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='22' height='32' src='http://2.bp.blogspot.com/_1lYUwYbRqJs/ShPnuYKjreI/AAAAAAAAAAM/sLRjmr5ttcA/S220/xmen3poster.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1898567896429290968.post-7722503141336059277</id><published>2009-05-20T17:14:00.011+05:30</published><updated>2009-05-23T16:58:41.781+05:30</updated><title type='text'>AOL Radio AmpX ActiveX Control 'ConvertFile()' Buffer Overflow Vulnerability</title><content type='html'>&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;&lt;span style="font-family:verdana;font-size:85%;color:#ff9900;"&gt;Overview:&lt;/span&gt;&lt;/strong&gt; &lt;span style="font-size:85%;"&gt;AOL Radio AmpX ActiveX control is prone to a stack-based buffer-overflow vulnerability because the application fails to adequately check boundaries on user-supplied input.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Verdana;font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;&lt;span style="font-size:85%;color:#ff9900;"&gt;Impact:&lt;/span&gt;&lt;/strong&gt; &lt;span style="font-size:85%;"&gt;Successfully exploiting these issues allows an attacker to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Verdana;font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family:verdana;font-size:85%;color:#ff9900;"&gt;Affected Software:&lt;/span&gt;&lt;/strong&gt; &lt;span style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;AOL AmpX.dll 2.4 6&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;&lt;span style="font-size:85%;color:#ff9900;"&gt;Vulnerable version:&lt;/span&gt;&lt;/strong&gt; &lt;span style="font-size:85%;"&gt;AmpX.dll 2.4.0.6 is vulnerable, other versions may also be affected.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;&lt;span style="font-size:85%;color:#ff9900;"&gt;Solution:&lt;/span&gt;&lt;/strong&gt; &lt;span style="font-size:85%;"&gt;Set the kill-bit for the affected ActiveX control.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Verdana;font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;&lt;span style="font-size:85%;color:#ff9900;"&gt;IDS Rule:&lt;/span&gt;&lt;/strong&gt; &lt;span style="font-size:85%;"&gt;alert tcp $EXTERNAL_NET $HTTP_PORTS -&amp;gt; $HOME_NET any (msg:"AOL Radio AmpX ActiveX Control ConvertFile Method Buffer Overflow"; flow:to_client,established; content:"clsid"; nocase; content:"FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6"; nocase; distance:0; content:"ConvertFile"; nocase; classtype:web-application-attack; reference:url,milw0rm.com/exploits/8733; reference:bugtraq,35028; sid:900000; rev:1;) &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Verdana;font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;&lt;span style="font-family:verdana;color:#ff9900;"&gt;Reference:&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-family:verdana;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.securityfocus.com/bid/35028"&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;http://www.securityfocus.com/bid/35028&lt;/span&gt;&lt;/a&gt; ;&lt;span style="font-family:verdana;font-size:85%;"&gt; &lt;/span&gt;&lt;a href="http://milw0rm.com/exploits/8733"&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;http://milw0rm.com/exploits/8733&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="color:#ff9900;"&gt;&lt;strong&gt;CVSS Base Score:&lt;/strong&gt;&lt;/span&gt; 9.3 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="color:#ff9900;"&gt;&lt;strong&gt;Risk factor:&lt;/strong&gt;&lt;/span&gt; High&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1898567896429290968-7722503141336059277?l=intrusion-detection.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://intrusion-detection.blogspot.com/feeds/7722503141336059277/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1898567896429290968&amp;postID=7722503141336059277' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/7722503141336059277'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1898567896429290968/posts/default/7722503141336059277'/><link rel='alternate' type='text/html' href='http://intrusion-detection.blogspot.com/2009/05/aol-radio-ampx-activex-control.html' title='AOL Radio AmpX ActiveX Control &apos;ConvertFile()&apos; Buffer Overflow Vulnerability'/><author><name>xsy</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
