*** EX RELS 03342 Release *** Total number of signatures: 6014 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 12 rule(s): --------------- 1133908 EXPLOIT QNAP Transcode Server Command Execution 1133909 WEB Neo Coolcam IP Camera and Gateway Remote Code Execution -1 1133911 RTSP Neo Coolcam IP Camera and Gateway Remote Code Execution 1133918 DOS WireX DDoS Botnet Distributed Denial Of Service -1 1133919 WEB Nginx ngx_http_range_filter_module Integer Overflow (CVE-2017-7529) 1133920 DOS WireX DDoS Botnet Distributed Denial Of Service -2 1133926 SSL GnuTLS status_request Extension Null Pointer Dereference (CVE-2017-7507) 1133931 SCADA Schneider Electric U.motion Builder track_import_export.php SQL Injection - 1.1 (CVE-2017-7973) 1160613 NETWORK SMB access via UDP -1 1160614 NETWORK SMB access via TCP -1 1160615 NETWORK SMB2 access via TCP -1 1160616 NETWORK SMB2 access via TCP -2 Modified 6 rule(s): --------------- 1058077 WEB SQL injection attempt -1.b 1058468 WEB SQL injection attempt -25.a 1058981 WEB Directory Traversal -21 1130403 WEB McAfee ePolicy Orchestrator XML Entity Injection -1 (CVE-2015-0921) 1133678 SSL OpenSSL ChaCha20-Poly1305 and RC4-MD5 Integer Underflow -1 (CVE-2017-3731) 1133844 WEB-CLIENT Microsoft Internet Explorer CWigglyShape Information Disclosure -2 (CVE-2016-7283) Deleted 22 rule(s): --------------- 1052727 GAME POPO access via TCP -1 (old rule) 1053572 NETWORK NETBIOS SMB access via TCP -1 (old rule) 1053663 GAME PKGame login via TCP -1 (old rule) 1060044 GAME Pogo login via SSL -1 (old rule) 1063371 GAME POPO login via TCP -1 (old rule) 1064482 GAME PKGame login via TCP -2 (old rule) 1064774 SOCIAL Path login via SSL -1 (old rule) 1064775 SOCIAL WeHeartIt login via SSL -1 (old rule) 1065023 WEB 163.com access via TCP -1 (old rule) 1065075 WEB Adcash access via SSL -1 (old rule) 1065089 WEB 163.com login via SSL -1 (old rule) 1065097 WEB HuffingtonPost login via TCP -1 (old rule) 1065100 WEB HuffingtonPost access via TCP -2 (old rule) 1065101 WEB HuffingtonPost access via TCP -3 (old rule) 1066050 SOCIAL WeHeartIt access via TCP -1 (old rule) 1066051 SOCIAL WeHeartIt access via TCP -2 (old rule) 1066052 SOCIAL WeHeartIt access via TCP -3 (old rule) 1068858 GAME POPO access via TCP -2 (old rule) 1068977 SOCIAL WeHeartIt access via TCP -4 (old rule) 1068989 WEB 163.com access via TCP -2 (old rule) 1068990 WEB 163.com access via TCP -3 (old rule) 1068991 WEB 163.com access via TCP -4 (old rule)