Guest

Hierarchical Navigation

Intrusion Detection System Solution

Cisco IDS Active Update Bulletin #105

http://www.cisco.com/go/ids
April 14, 2004

Greetings! This bulletin describes updates to the Cisco IDS product line. As always, please feel free to message us directly if you have any comments or questions (ids-news@cisco.com). We also encourage you to participate in the Cisco IDS User's Forum at http://www.cisco.com/discuss/security. If you'd like to unsubscribe from this bulletin click here.

1. Announcing the S85 Signature Update for Cisco IDS Version 4.1

2. Extended IDSM-1 Signature Support and Migration Program

3. Subscription Information

=====================

1. Cisco Signature S85 for Cisco IDS 4.1(3)

The S85 signature update contains the following new signatures:

SIGID SIGNAME SEVERITY ENABLED
3337.0 Windows RPC Race Condition Exploitation High Yes
3338.0 Windows LSASS RPC Overflow High Yes
5406.0  Illegal MHTML URL High Yes
5406.1 Illegal MHTML URL High Yes
5407.0 IIS PCT Overflow High Yes
5408.0 Windows HCP URL Parsing Command Exec High Yes
5408.1  Windows HCP URL Parsing Command Exec High Yes

The S85 signature update contains no modified signatures:

NOTE: All signature updates are cumulative. The S84 signature update contains all previously released signature updates.

The IDS-sig-4.1-3-S85.rpm.pkg signature update can be applied to version 4.1 sensors as follows:

You can only apply this signature update to IDS-42xx Cisco Intrusion Detection System (IDS) sensors, the WS-SVC-IDSM2 series Intrusion Detection System Module (IDSM2), and the NM-CIDS Intrusion Detection System Network Module.

It is not compatible with the NRS-xx series Intrusion Detection System (IDS) sensors or the
WS-X6381-IDS series Intrusion Detection System Module (IDSM).

IDS 4.1(3)S85 Sensor Software Update Files:

The files for the 4.1(3)S85 signature update can be downloaded from:

http://www.cisco.com/pcgi-bin/tablebuild.pl/ids4

NOTE: You must have a SMARTnet maintenance contract number to request
software upgrades from Cisco.com.

IDS MC Update

The IDS MC update and readme files can be downloaded at the following URL. Refer to the readme file for installation instructions.

http://www.cisco.com/pcgi-bin/tablebuild.pl/mgmt-ctr-ids-ids4updates

IEV Update

You can download the IEV signature update file IEV-sig-4.1-1-S85.exe and readme from the following website:

http://www.cisco.com/pcgi-bin/tablebuild.pl/ids-ev

2. Extended IDSM-1 Signature Support and Migration Program

The current end-of-signature support date for IDSM-1 has been extended until August 1, 2004; an extension of 3 months from the previous deadline of April 30, 2004.

In addition to extending the last signature support date, the IDSM-1 to IDSM-2 trade-in program will also be extended to July 31, 2004.

The IDSM-1 Trade-In Program allows customers to get $10,000 towards the purchase of an IDSM-2 by turning in their IDSM-1. This credit is applied after the discount on the IDSM-2 is taken. The list price of the IDSM-2 is $29,995 so this credit provides substantial value towards the purchase of the newer, and far more powerful IDSM-2. The program is administered by the Cisco Technology Migration Program (TMP) and can be located at:

http://www.cisco.com/en/US/partners/pr61/pr73/ctmp/index.shtml

This program cannot be combined with any other IDSM-2 promotion.

3. Subscription Information

We'd like to know what you think about this bulletin.
We're also interested in what you'd like to see
in future editions. Please take a moment to send us your comments.

If you wish to receive this bulletin, you can subscribe now.

If you no longer wish to receive this bulletin, you can unsubscribe now