<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Snort ET MALWARE User-Agent (Internet Explorer)]]></title><description><![CDATA[<p dir="auto">:( i have alot of this alret in snort  SID 1:2008052</p>
<p dir="auto">ET MALWARE User-Agent (Internet Explorer) on wan with no clue on lan</p>
]]></description><link>https://forum.netgate.com/topic/76613/snort-et-malware-user-agent-internet-explorer</link><generator>RSS for Node</generator><lastBuildDate>Thu, 14 May 2026 01:30:59 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/76613.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 05 Dec 2014 18:33:17 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Snort ET MALWARE User-Agent (Internet Explorer) on Sat, 06 Dec 2014 02:15:10 GMT]]></title><description><![CDATA[<p dir="auto">Oh nevermind, maybe they are not realted after all… when i saw IE User-Agent thought it was the CVE-2014-6332...</p>
<p dir="auto">Still... packet capture some of those and we will check if its FP or what it is...</p>
<p dir="auto">F.</p>
]]></description><link>https://forum.netgate.com/post/499677</link><guid isPermaLink="true">https://forum.netgate.com/post/499677</guid><dc:creator><![CDATA[fsansfil]]></dc:creator><pubDate>Sat, 06 Dec 2014 02:15:10 GMT</pubDate></item><item><title><![CDATA[Reply to Snort ET MALWARE User-Agent (Internet Explorer) on Sat, 06 Dec 2014 02:06:37 GMT]]></title><description><![CDATA[<p dir="auto">CVE-2014-6332 is pretty big right now, and for a vulnerability that affects ALL Internet Explorer, be sure there will be many exploits out there….</p>
<p dir="auto">https://isc.sans.edu/forums/diary/How+bad+is+the+SCHANNEL+vulnerability+CVE-2014-6321+patched+in+MS14-066/18947/</p>
<p dir="auto">https://github.com/rapid7/metasploit-framework/pull/4255</p>
<p dir="auto">There are a couple of ET CURRENT EVENT rules covering those vulnerabilities...might want to run them on all interfaces</p>
<p dir="auto">Otherwise sniff the traffic with packet capture and lets see whats in those packets.</p>
<p dir="auto">F.</p>
]]></description><link>https://forum.netgate.com/post/499676</link><guid isPermaLink="true">https://forum.netgate.com/post/499676</guid><dc:creator><![CDATA[fsansfil]]></dc:creator><pubDate>Sat, 06 Dec 2014 02:06:37 GMT</pubDate></item></channel></rss>