republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
12571
Share Topic
Posting?
Post a:
Post a:
Links: ·Forum Rules ·Forum FAQ ·FTP Modes & Ports ·Linksys Home
page: 1 · 2 · 3 · 4 · 5
AuthorAll Replies


Jan Janowski

join:2000-06-18
Skokie, IL
Reviews:
·Comcast
·AT&T Midwest

1 edit

reply to Jan Janowski

Re: RVS 4000 Support email to Cisco

Good Going!
Most of my complaints are not complicated issues.

1. Turn on Logging.
2. Indicate in log which level (0-7) each entry is configured to, so you can easily deteremine which log level to enable/disable. At present, you can't determine which log level belongs with which entry...
3. Turn off (or make it switchable) IPS Update Reminder Nags. This works in conjunction with:
4. Update IPS in a timely fashion, and have it report correct date.
5. Turn off VPN restart updates to logs when VPN is not used.
6. Printing out Configuration Pages EATS BLUE INK! Go back to transparent B&W only, with a small neat Color Logo, and Have Each Configuration Page Print onto one sheet of paper (Presently it doesn't print out any text that is off screen) -- In other words, GO BACK to V1.2.11 style printout!

These are not earth shattering, but a bit annoying...
--
Looking for 1939 Indian Motocycle


Jan Janowski

join:2000-06-18
Skokie, IL
Reviews:
·Comcast
·AT&T Midwest

1 edit

reply to Jan Janowski

V1.41 IPS file Released!

Yesterday, it seems:

Version: 1.41 Total Rules: 1098

In this signature, we addressed the exploits/vulnerabilities and applications
as below:

-EXPLOIT MS Video ActiveX Control Stack Buffer Overflow
A buffer overflow vulnerability exists in Microsoft DirectShow.
The flaw is due to the way Microsoft Video ActiveX Control parses image files.
An attacker can persuade the target user to open a malicious web page to exploit
this vulnerability.

-EXPLOIT Oracle Database Workspace Manager SQL Injection
Multiple SQL injection vulnerabilities exist in Oracle Database Server product.
The vulnerabilities are due to insufficient sanitization of input parameters
in the Oracle Workspace Manager component. A remote attacker with valid user
credentials may leverage these vulnerabilities to inject and execute SQL code
with escalated privilegesof SYS or WMSYS account.

Support P2P application named uTorrent up to version 1.7.2.

Signature content for 1.41
========================================================================
New Added signature(s):
1053635 EXPLOIT MS Video ActiveX Control Stack Buffer Overflow -1
1053636 EXPLOIT MS Video ActiveX Control Stack Buffer Overflow -2
1053632 EXPLOIT Oracle Database Workspace Manager SQL Injection -1
1053633 EXPLOIT Oracle Database Workspace Manager SQL Injection -2
1053634 EXPLOIT Oracle Database Workspace Manager SQL Injection -3

Modified signature(s):
1051783 P2P Gnutella Connect
1051212 P2P Gnutella Get file
1051785 P2P Gnutella UDP PING 2
1051997 P2P Gnutella Bearshare file transfer with UDP
1052039 P2P Gnutella OK
1052637 P2P Foxy Get file

Deleted signature(s):
1050521 Worm.Klez.E1 - 1
1050522 Worm.Klez.E1 - 2
1050523 Worm.Klez.E1 - 3
1050524 Worm.Klez.E2 - 1
1050525 Worm.Klez.E2 - 2
1050526 Worm.Klez.E2 ¡V 3
1050536 Worm.Blaster.B - 1
1050537 Worm.Blaster.B - 2
1050538 Worm.Blaster.B - 3
1050539 Worm.Blaster.C - 1
1050540 Worm.Blaster.C - 2
1050541 Worm.Blaster.C - 3

Number of rules in each category:
========================================================================
DoS/DDoS 51
Buffer Overflow: 241
Access Control: 92
Scan: 41
Trojan Horse: 62
Misc: 3
P2P: 40
Instant Messenger: 121
Vrus/Worm: 410
Web Attacks: 37

And when loaded, the correct date of load was attached to it!!! No more IPS date of 1969!!! !
--
Looking for 1939 Indian Motocycle


ironwalker
World Renowned
Premium,MVM
join:2001-08-31
Keansburg, NJ

reply to Jan Janowski

Re: RVS 4000 Support email to Cisco

Hey guys, I lost the download page in bookmarks for firmware and ips signature downloads, can someone please post them or the page links?

Thank you.


Jan Janowski

join:2000-06-18
Skokie, IL
Reviews:
·Comcast
·AT&T Midwest

reply to Jan Janowski
You'll have to have a login....

»tools.cisco.com/support/download···82414013
--
Looking for 1939 Indian Motocycle



Dustyn
Premium
join:2003-02-26
Ontario, CAN
kudos:7

reply to Jan Janowski

Re: V1.41 IPS file Released!

Wow.
How long now did it take to update the IPS?
I'm just glad a new one was finally released. Even if it did take an unacceptable amount of time.


Jan Janowski

join:2000-06-18
Skokie, IL
Reviews:
·Comcast
·AT&T Midwest

reply to Jan Janowski

Re: RVS 4000 Support email to Cisco

Dustyn.... I'd guestimate it took 30 seconds to update the IPS.... Did it without moving router.

Usually, because of the 'default to Factory specs' step prior to upgrading, I remove router to a stand alone system for firmware upgrading, but for IPS I just go to router, and point it at the update, and let it update itself...
--
Looking for 1939 Indian Motocycle


Dustyn
Premium
join:2003-02-26
Ontario, CAN
kudos:7

1 edit

You are correct.
IPS updating in about 30 seconds.
No reboot required either.
Firmware Version: V1.1.14



Link Logger
Premium,MVM
join:2001-03-29
Calgary, AB
kudos:3
Reviews:
·Shaw

reply to Jan Janowski
Bad news, logging still isn't fixed. Here is a clip of an email from one of our clients who was testing a new firmware for the RVS4000:

quote:
You were right to have doubts. It was not fixed. Same problem. I
installed the new firmware and still no incoming traffic. The people at
Cisco checking the new firmware upgrade had port forwarding setup in a
way that produced erroneous reports of incoming traffic. They are
discussing with their project engineer, and said they would get back to
me, but they also mentioned that it might be a "product limitation".
There are times when Linksys/Cisco drives me crazy and I swear they don't have a QA group or product managers who know much about routers/firewalls (about logging at least).

Blake
--
Vendor: Author of Link Logger which is a traffic analysis and firewall logging tool


ironwalker
World Renowned
Premium,MVM
join:2001-08-31
Keansburg, NJ

Thanks, I will pass on this since I do not use the email function and the logging itself does not work correctly still.

Thanks.



Dustyn
Premium
join:2003-02-26
Ontario, CAN
kudos:7
Reviews:
·Rogers Hi-Speed

reply to Jan Janowski

said by Jan Janowski:

Has anyone done in depth testing on this version yet?
I'm also waiting for user info on the latest firmware release and how it's performing.


Jan Janowski

join:2000-06-18
Skokie, IL
Reviews:
·Comcast
·AT&T Midwest

3 edits

reply to Jan Janowski
With New V1.41 (Not New, most recent) IPS, and New Firmware 1.3.0.5
I'm still getting random:

Your Signature Version is beyond ____ days. Please Update it!

and the other one that seems to be connected to VPN (And I'm Not doing VPN!! )

-IPSEC EVENT: KLIPS device ipsec0 shut down

I've not encountered any operational issues, but I'm doing plain vanilla operations. and I haven't encountered anything unusual or worse than the prior version of the firmware/IPS.
Basically -- Reason why I'm using RVS4000 to provide Gigabit file sharing between a couple computers..... It seems to work that way..

However, I believe Blake has coommented it is as broken as the previous version was...

--
Looking for 1939 Indian Motocycle


Saturday, 02-Jun 07:29:43 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics