This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

https://www.snort.org/search?query=8068

Hallo zusammen,

ich erhalte seit einiger Zeit täglich folgende Meldung von meiner UTM und werde daraus wirklich nicht schlau. Die Snort Beschreibung hilft mir leider auch nicht weiter. Vielleicht hat hier ja einer eine Idee was die Ursache sein könnte und was man dagegen tun kann!? :)

An intrusion has been detected. The packet has been dropped automatically.

You can toggle this rule between "drop" and "alert only" in WebAdmin.

Details about the intrusion alert:

Message........: BROWSER-PLUGINS Microsoft Windows Scripting Host Shell ActiveX function call access

Details........: https://www.snort.org/search?query=8068

Time...........: 2016-09-13 04:26:58

Packet dropped.: yes

Priority.......: high

Classification.: Attempted User Privilege Gain IP protocol....: 6 (TCP)

 

Source IP address: 104.84.154.160 (IP Adresse wechselt immer)

Source port: 80 (http)

Destination IP address: 172.16.20.222 (Laptop, Windows 10) Destination port: 1678 (Port wechselt immer)  

--

System Version     : Sophos UTM 9.405-5

Danke und Gruß

Ronny



This thread was automatically locked due to age.
Parents
  • (Sorry, my German-speaking brain isn't creating thoughts at the moment. [:(])

    Hi, Ronny, and welcome to the UTM Community!

    If you follow that link and then look at SID 8068, you see that the vulnerability is for Internet Explorer 6 and older.  You probably just want to disable this rule on the 'Advanced' tab.  It's also likely that you can disable rules based on age - whether that's 6, 12 or 24 months depends on your internal policies and systems.

    MfG - Bob (Bitte auf Deutsch weiterhin.)

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • (Sorry, my German-speaking brain isn't creating thoughts at the moment. [:(])

    Hi, Ronny, and welcome to the UTM Community!

    If you follow that link and then look at SID 8068, you see that the vulnerability is for Internet Explorer 6 and older.  You probably just want to disable this rule on the 'Advanced' tab.  It's also likely that you can disable rules based on age - whether that's 6, 12 or 24 months depends on your internal policies and systems.

    MfG - Bob (Bitte auf Deutsch weiterhin.)

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data