1 Reply Latest reply on Jul 16, 2013 3:15 AM by Peacekeeper

    Unable to import Snort Signature cleanly

      Hi Mcafee,

       

      I am having trouble with importing Snort signatures into Mcafee NSM Version 7.1.3.5. I really need advice here. here's an example of a snort signature:

       

      alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SERVER Microsoft SharePoint Server 2007 _layouts/help.aspx Cross Site Scripting Attempt"; flow:established,to_server; content:"/_layouts/help.aspx"; nocase; http_uri; content:"cid0="; nocase; http_uri; pcre:"/cid0\x3d.+(script|alert|onmouse[a-z]+|onkey[a-z]+|onload|onunload|ondrag drop|onblur|onfocus|onclick|ondblclick|onsubmit|onreset|onselect|onchange)/Ui"; reference:url,www.htbridge.ch/advisory/xss_in_microsoft_sharepoint_server_2007. html; reference:url,tools.cisco.com/security/center/viewAlert.x?alertId=20415; reference:url,www.microsoft.com/technet/security/Bulletin/MS10-039.mspx; reference:url,tools.cisco.com/security/center/viewAlert.x?alertId=20610; reference:cve,2010-0817; reference:url,doc.emergingthreats.net/2011073; classtype:web-application-attack; sid:2011073; rev:5;)

       

      The highlighted red portion are the ones i'm having problem with. I can change the traffic setting to any any but the Classtype, it doesn't seem to recognize even when i change to a Mcafee type like "Trojan-Activity.

       

      Thank you for reading this and i hope to hear from anyone.

       

      Regards,

      Ian