*** EX RELS 03313 Release *** Total number of signatures: 6034 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 15 rule(s): --------------- 1058966 NTP Network Time Protocol Amplification Distributed Denial of Service (CVE-2013-5211) 1133455 WEB Axis Communications MPQT/PACS 5.20.x SSI Daemon Remote Format String 1133456 FTP Brute Force Login -1 1133457 FTP Brute Force Login -2 1133458 WEB HTTP Invalid Content Type 1133459 WEB PHP exception toString Denial of Service (CVE-2016-7478) 1133462 SNMP Simple Network Management Protocol GETBULK Reflection Denial of Service Vulnerability 1133463 SSDP Simple Service Discovery Protocol Reflection Denial of Service Vulnerability 1133464 WEB Netgear WNDR1000v4 Router Remote Authentication Bypass 1133465 WEB OpenBSD http server Denial of Service Vulnerability (CVE-2017-5850) 1160110 MEDIA Dailymotion access via SSL -4 1160111 MEDIA Hulu media via SSL -1 1160112 MEDIA Pandora media via SSL -1 1160113 MEDIA Pandora media via SSL -2 1160114 MEDIA Pandora access via SSL -1 Modified 17 rule(s): --------------- 1052848 NETBIOS SMB username brute force attempt 1056496 EXPLOIT Avaya WinPDM Unite Host Router Service Stack Buffer Overflow (BID-47947) 1057137 DB Microsoft SQL SA Password Brute Force 1059418 SSH Brute Force Login 1059667 WEB Hikvision DVR Devices Multiple Vulnerabilities -1 1059668 WEB Hikvision DVR Devices Multiple Vulnerabilities -2 1059803 RDP Brute Force Login 1066300 MEDIA Dailymotion access via SSL -2 1130118 SSL OpenSSL SSLv3 POODLE Padding Brute Force (CVE-2014-3566) 1130172 DNS DNS Amplification Attacks -1 1130173 DNS DNS Amplification Attacks -2 1130588 POP3 Brute Force Login 1131643 SMTP Brute Force Login 1132591 TELNET Brute Force Login 1133407 WEB Brute Force Login -1 1133408 WEB Brute Force Login -2 1133449 SMB Microsoft SMBv2/SMBv3 Null Dereference Denial of Service Vulnerability (CVE-2017-0016) Deleted 30 rule(s): --------------- 1052093 VOIP NetMeeting whiteboard service access via TCP -1 (old rule) 1052726 IM POPO login via TCP -1 (old rule) 1052728 IM POPO login via TCP -2 (old rule) 1052732 IM POPO transfer via TCP -1 (old rule) 1053193 IM RenRen login via TCP -1 (old rule) 1053196 IM Wlt login via TCP -1 (old rule) 1053342 IM POPO login via TCP -3 (old rule) 1053592 IM POPO transfer via UDP -1 (old rule) 1060928 VOIP Inter-Asterisk eXchange access via TCP -1 (old rule) 1061618 VOIP Net2Phone login via TCP -1 (old rule) 1061619 VOIP Net2Phone communicate via TCP -1 (old rule) 1061620 VOIP Net2Phone communicate via TCP -2 (old rule) 1063152 VOIP NetMeeting communicate via TCP -1 (old rule) 1063378 MEDIA Photobucket login via SSL -1 (old rule) 1063592 IM POPO login via TCP -4 (old rule) 1063668 TUNNEL Kproxy connect via SSL -1 (old rule) 1064006 VOIP Fring login via TCP -2 (old rule) 1064016 IM Tlen login via SSL-1 (old rule) 1064122 VOIP Fring login via TCP -1 (old rule) 1064376 IM POPO transfer via TCP -2 (old rule) 1064410 MEDIA Photobucket access via TCP -1 (old rule) 1065483 MEDIA Photobucket media via TCP -1 (old rule) 1066207 MEDIA Photobucket transfer-upload via TCP -1 (old rule) 1066208 MEDIA Photobucket transfer-download via TCP -1 (old rule) 1066209 MEDIA Photobucket access via TCP -2 (old rule) 1068112 TUNNEL Kproxy access via TCP -1 (old rule) 1068118 TUNNEL Kproxy login via TCP -1 (old rule) 1068630 VOIP Fring login via TCP -3 (old rule) 1068631 VOIP Fring access via TCP -1 (old rule) 1068632 VOIP Fring access via TCP -2 (old rule)