Talos Rules 2024-10-17
This release adds and modifies rules in several categories.

Talos has added and modified multiple rules in the policy-other and server-webapp rule sets to provide coverage for emerging threats from these technologies.

For information about Snort Subscriber Rulesets available for purchase, please visit the Snort product page.

Change logs

2024-10-17 13:34:04 UTC

Snort Subscriber Rules Update

Date: 2024-10-17

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2092000.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:64131 <-> ENABLED <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt (server-webapp.rules)
 * 1:64132 <-> DISABLED <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt (server-webapp.rules)
 * 3:64133 <-> ENABLED <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt (server-webapp.rules)
 * 3:64134 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)
 * 3:64135 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)

Modified Rules:


 * 1:27125 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27122 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt (server-other.rules)
 * 1:27539 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt (server-other.rules)
 * 1:27170 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt (server-other.rules)
 * 1:27571 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt (server-other.rules)
 * 1:27769 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt (server-other.rules)
 * 1:27124 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt (server-other.rules)
 * 1:27770 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt (server-other.rules)
 * 1:27771 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt (server-other.rules)
 * 1:27772 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt (server-other.rules)
 * 1:27773 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt (server-other.rules)
 * 1:28227 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:63856 <-> ENABLED <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt (server-webapp.rules)

2024-10-17 13:34:04 UTC

Snort Subscriber Rules Update

Date: 2024-10-17

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091900.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:64131 <-> ENABLED <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt (server-webapp.rules)
 * 1:64132 <-> DISABLED <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt (server-webapp.rules)
 * 3:64133 <-> ENABLED <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt (server-webapp.rules)
 * 3:64134 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)
 * 3:64135 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)

Modified Rules:


 * 1:27170 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt (server-other.rules)
 * 1:27770 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt (server-other.rules)
 * 1:63856 <-> ENABLED <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt (server-webapp.rules)
 * 1:27122 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt (server-other.rules)
 * 1:28227 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27125 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27571 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt (server-other.rules)
 * 1:27769 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt (server-other.rules)
 * 1:27771 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt (server-other.rules)
 * 1:27772 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt (server-other.rules)
 * 1:27773 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt (server-other.rules)
 * 1:27539 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt (server-other.rules)
 * 1:27124 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt (server-other.rules)

2024-10-17 13:34:04 UTC

Snort Subscriber Rules Update

Date: 2024-10-17

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091801.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:64131 <-> ENABLED <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt (server-webapp.rules)
 * 1:64132 <-> DISABLED <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt (server-webapp.rules)
 * 3:64133 <-> ENABLED <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt (server-webapp.rules)
 * 3:64134 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)
 * 3:64135 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)

Modified Rules:


 * 1:28227 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27122 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt (server-other.rules)
 * 1:27773 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt (server-other.rules)
 * 1:27571 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt (server-other.rules)
 * 1:27769 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt (server-other.rules)
 * 1:27125 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27124 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt (server-other.rules)
 * 1:27770 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt (server-other.rules)
 * 1:27771 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt (server-other.rules)
 * 1:27539 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt (server-other.rules)
 * 1:27170 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt (server-other.rules)
 * 1:63856 <-> ENABLED <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt (server-webapp.rules)
 * 1:27772 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt (server-other.rules)

2024-10-17 13:34:04 UTC

Snort Subscriber Rules Update

Date: 2024-10-17

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091701.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:64132 <-> DISABLED <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt (server-webapp.rules)
 * 1:64131 <-> ENABLED <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt (server-webapp.rules)
 * 3:64135 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)
 * 3:64134 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)
 * 3:64133 <-> ENABLED <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt (server-webapp.rules)

Modified Rules:


 * 1:27772 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt (server-other.rules)
 * 1:27773 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt (server-other.rules)
 * 1:27122 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt (server-other.rules)
 * 1:27170 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt (server-other.rules)
 * 1:27125 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:63856 <-> ENABLED <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt (server-webapp.rules)
 * 1:27571 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt (server-other.rules)
 * 1:27539 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt (server-other.rules)
 * 1:27769 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt (server-other.rules)
 * 1:27124 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt (server-other.rules)
 * 1:27770 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt (server-other.rules)
 * 1:27771 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt (server-other.rules)
 * 1:28227 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)

2024-10-17 13:34:04 UTC

Snort Subscriber Rules Update

Date: 2024-10-17

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091700.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:64131 <-> ENABLED <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt (server-webapp.rules)
 * 1:64132 <-> DISABLED <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt (server-webapp.rules)
 * 3:64133 <-> ENABLED <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt (server-webapp.rules)
 * 3:64135 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)
 * 3:64134 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)

Modified Rules:


 * 1:28227 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27125 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:63856 <-> ENABLED <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt (server-webapp.rules)
 * 1:27122 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt (server-other.rules)
 * 1:27773 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt (server-other.rules)
 * 1:27539 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt (server-other.rules)
 * 1:27771 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt (server-other.rules)
 * 1:27170 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt (server-other.rules)
 * 1:27769 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt (server-other.rules)
 * 1:27124 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt (server-other.rules)
 * 1:27770 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt (server-other.rules)
 * 1:27772 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt (server-other.rules)
 * 1:27571 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt (server-other.rules)

2024-10-17 13:34:04 UTC

Snort Subscriber Rules Update

Date: 2024-10-17

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091601.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:64132 <-> DISABLED <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt (server-webapp.rules)
 * 1:64131 <-> ENABLED <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt (server-webapp.rules)
 * 3:64133 <-> ENABLED <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt (server-webapp.rules)
 * 3:64134 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)
 * 3:64135 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)

Modified Rules:


 * 1:27772 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt (server-other.rules)
 * 1:27771 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt (server-other.rules)
 * 1:63856 <-> ENABLED <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt (server-webapp.rules)
 * 1:27124 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt (server-other.rules)
 * 1:27122 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt (server-other.rules)
 * 1:27773 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt (server-other.rules)
 * 1:27539 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt (server-other.rules)
 * 1:27125 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27571 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt (server-other.rules)
 * 1:27170 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt (server-other.rules)
 * 1:27770 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt (server-other.rules)
 * 1:27769 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt (server-other.rules)
 * 1:28227 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)

2024-10-17 13:34:04 UTC

Snort Subscriber Rules Update

Date: 2024-10-17

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091600.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:64131 <-> ENABLED <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt (server-webapp.rules)
 * 1:64132 <-> DISABLED <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt (server-webapp.rules)
 * 3:64134 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)
 * 3:64135 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)
 * 3:64133 <-> ENABLED <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt (server-webapp.rules)

Modified Rules:


 * 1:27770 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt (server-other.rules)
 * 1:27125 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27771 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt (server-other.rules)
 * 1:27539 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt (server-other.rules)
 * 1:27772 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt (server-other.rules)
 * 1:27170 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt (server-other.rules)
 * 1:63856 <-> ENABLED <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt (server-webapp.rules)
 * 1:27122 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt (server-other.rules)
 * 1:27769 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt (server-other.rules)
 * 1:28227 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27773 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt (server-other.rules)
 * 1:27571 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt (server-other.rules)
 * 1:27124 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt (server-other.rules)

2024-10-17 13:34:04 UTC

Snort Subscriber Rules Update

Date: 2024-10-17

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091501.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:64131 <-> ENABLED <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt (server-webapp.rules)
 * 1:64132 <-> DISABLED <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt (server-webapp.rules)
 * 3:64133 <-> ENABLED <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt (server-webapp.rules)
 * 3:64135 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)
 * 3:64134 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)

Modified Rules:


 * 1:63856 <-> ENABLED <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt (server-webapp.rules)
 * 1:27539 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt (server-other.rules)
 * 1:27122 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt (server-other.rules)
 * 1:27124 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt (server-other.rules)
 * 1:27170 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt (server-other.rules)
 * 1:27769 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt (server-other.rules)
 * 1:28227 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27772 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt (server-other.rules)
 * 1:27771 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt (server-other.rules)
 * 1:27770 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt (server-other.rules)
 * 1:27125 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27571 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt (server-other.rules)
 * 1:27773 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt (server-other.rules)

2024-10-17 13:34:04 UTC

Snort Subscriber Rules Update

Date: 2024-10-17

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091401.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:64131 <-> ENABLED <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt (server-webapp.rules)
 * 1:64132 <-> DISABLED <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt (server-webapp.rules)
 * 3:64134 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)
 * 3:64133 <-> ENABLED <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt (server-webapp.rules)
 * 3:64135 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)

Modified Rules:


 * 1:28227 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27125 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27773 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt (server-other.rules)
 * 1:27771 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt (server-other.rules)
 * 1:27772 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt (server-other.rules)
 * 1:27170 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt (server-other.rules)
 * 1:63856 <-> ENABLED <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt (server-webapp.rules)
 * 1:27122 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt (server-other.rules)
 * 1:27124 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt (server-other.rules)
 * 1:27571 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt (server-other.rules)
 * 1:27539 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt (server-other.rules)
 * 1:27770 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt (server-other.rules)
 * 1:27769 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt (server-other.rules)

2024-10-17 13:34:04 UTC

Snort Subscriber Rules Update

Date: 2024-10-17

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091300.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:64131 <-> ENABLED <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt (server-webapp.rules)
 * 1:64132 <-> DISABLED <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt (server-webapp.rules)
 * 3:64134 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)
 * 3:64133 <-> ENABLED <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt (server-webapp.rules)
 * 3:64135 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)

Modified Rules:


 * 1:27122 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt (server-other.rules)
 * 1:63856 <-> ENABLED <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt (server-webapp.rules)
 * 1:27571 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt (server-other.rules)
 * 1:27125 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27539 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt (server-other.rules)
 * 1:27770 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt (server-other.rules)
 * 1:28227 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27771 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt (server-other.rules)
 * 1:27769 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt (server-other.rules)
 * 1:27170 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt (server-other.rules)
 * 1:27124 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt (server-other.rules)
 * 1:27772 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt (server-other.rules)
 * 1:27773 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt (server-other.rules)

2024-10-17 13:34:04 UTC

Snort Subscriber Rules Update

Date: 2024-10-17

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091101.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:64132 <-> DISABLED <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt (server-webapp.rules)
 * 1:64131 <-> ENABLED <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt (server-webapp.rules)
 * 3:64134 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)
 * 3:64135 <-> ENABLED <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected (policy-other.rules)
 * 3:64133 <-> ENABLED <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt (server-webapp.rules)

Modified Rules:


 * 1:27170 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt (server-other.rules)
 * 1:27773 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt (server-other.rules)
 * 1:63856 <-> ENABLED <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt (server-webapp.rules)
 * 1:27772 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt (server-other.rules)
 * 1:27770 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt (server-other.rules)
 * 1:27122 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt (server-other.rules)
 * 1:27124 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt (server-other.rules)
 * 1:27539 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt (server-other.rules)
 * 1:28227 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27771 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt (server-other.rules)
 * 1:27769 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt (server-other.rules)
 * 1:27125 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt (server-other.rules)
 * 1:27571 <-> DISABLED <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt (server-other.rules)

2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.0.0.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.0.3.1.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.0.3.4.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.0.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.0.1.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.1.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.3.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.4.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.5.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.7.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.9.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.2.0.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.11.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.15.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.18.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.20.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.21.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:18 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.35.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:19 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.44.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt


2024-10-17 13:37:19 UTC

Snort Subscriber Rules Update

Date: 2024-10-16-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.47.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:64131 <-> SERVER-WEBAPP Ivanti Cloud Services Appliance path traversal attempt
* 1:64132 <-> SERVER-WEBAPP Sourcegraph gitserver core.sshCommand command injection attempt
* 3:64133 <-> SERVER-WEBAPP Cisco Analog Telephone Adapter cross site request forgery attempt
* 3:64134 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected
* 3:64135 <-> POLICY-OTHER Cisco Analog Telephone Adapter configuration download request detected

Modified Rules:

* 1:27122 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 305 buffer overflow attempt
* 1:27124 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1092 buffer overflow attempt
* 1:27125 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:27170 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 1091 buffer overflow attempt
* 1:27539 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 234 buffer overflow attempt
* 1:27571 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 235 buffer overflow attempt
* 1:27769 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 207 buffer overflow attempt
* 1:27770 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 210 buffer overflow attempt
* 1:27771 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 236 buffer overflow attempt
* 1:27772 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 243 buffer overflow attempt
* 1:27773 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 265 buffer overflow attempt
* 1:28227 <-> SERVER-OTHER HP OpenView Storage Data Protector CRS opcode 211 buffer overflow attempt
* 1:63856 <-> SERVER-WEBAPP Adobe Commerce and Magento Open Source XML external entity injection attempt