Snort mailing list archives

Question regarding SNORT Rule


From: "Filice II, Anthony via Snort-sigs" <snort-sigs () lists snort org>
Date: Tue, 14 Jan 2020 20:03:01 +0000

All,

Question regarding Microsoft Vulnerability CVE-2020-0601: A coding deficiency exists in Microsoft Windows CryptoAPI 
that may lead to spoofing.

Why is this disabled in the new rules

1:52596 <-> DISABLED <-> OS-WINDOWS Microsoft Windows CryptoAPI signed binary with spoofed certificate attempt 
(os-windows.rules)
* 1:52595 <-> DISABLED <-> OS-WINDOWS Microsoft Windows CryptoAPI signed binary with spoofed certificate attempt 
(os-windows.rules)
* 1:52594 <-> DISABLED <-> OS-WINDOWS Microsoft Windows CryptoAPI signed binary with spoofed certificate attempt 
(os-windows.rules)
* 1:52593 <-> DISABLED <-> OS-WINDOWS Microsoft Windows CryptoAPI signed binary with spoofed certificate attempt 
(os-windows.rules)



Anthony C Filice II
IPS/NAC Engineer
IPR-IPR-SEC-F1840
313-656-3472 desk
702-287-6732 cell

_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a 
href=" https://snort.org/downloads/#rule-downloads";>emerging threats</a>!

Current thread: