IDP Signatures for Microsoft Internet Explorer Zero-day vulnerability CVE-2010-0249
Recently a zero day vulnerability in Microsoft Internet Explorer was made public. How do I configure IDP signatures to protect the network against this vulnerability?
We have received many inquiries on the ability of IDP and IDP enabled devices to protect against the Microsoft Internet Explorer Zero-day vulnerability CVE-2010-0249. (For more details on this vulnerability please refer to the following URL http://www.microsoft.com/technet/security/advisory/979352.mspx ) IDP has two signatures that can currently detect the exploitation of this vulnerability but not the specific vulnerability itself:
Signature Short name : HTTP:STC:SCRIPT:UNI-SHELLCODE Long name: HTTP: Encoded Shellcode in Javascript Severity: Major Recommended Attack: Yes Recommended Action: Drop Signature Short name : HTTP:STC:SCRIPT:FUNC-REASSIGN Long name: HTTP: Script Evasion Function Reassignment Severity: Minor Recommended Attack : Not a Recommended Attack Recommended Action: None
"All Attacks" - Response - Response_HTTP - Response_HTTP-Major and Response_HTTP-Minor.
#set security idp idp-policy <policyname> rulebase-ips rule <aurora-attack> match attacks predefined-attacks “ HTTP:STC:SCRIPT:FUNC-REASSIGN” #set security idp idp-policy <policyname> rulebase-ips rule <aurora-attack> match attacks predefined-attacks “ HTTP:STC:SCRIPT:UNI-SHELLCODE”