I am getting the following hourly all of a sudden:
Intrusion Protection Pattern Up2Date: New Intrusion Protection patterns installed.
-- Last WebAdmin login: admin at Sat Sep 3 10:08:34 from 192.168.0.20 System Uptime : 2 days 18 hours 13 minutes System Load : 0.07 System Version : Astaro Security Linux 6.002 License : unlimited Please refer to the manual for detailed instructions.
Intrusion Protection Ruleset Update
-----------------------------------
This file contains the changes in the latest ruleset.
General information
-------------------
-
New rules
---------
4126 - EXPLOIT Veritas Backup Exec root connection attempt using default password hash (exploit.rules)
4127 - EXPLOIT Novell eDirectory Server iMonitor overflow attempt (exploit.rules)
4128 - WEB-CGI 4DWebstar ShellExample.cgi information disclosure (web-cgi.rules)
4129 - EXPLOIT Novell ZenWorks Remote Management Agent large login packet DoS attempt (exploit.rules)
4130 - EXPLOIT Novell ZenWorks Remote Management Agent Buffer Overflow Attempt (exploit.rules)
4131 - EXPLOIT SHOUTcast URI format string attempt (exploit.rules)
4132 - WEB-CLIENT msdds clsid attempt (web-client.rules)
4133 - WEB-CLIENT devenum clsid attempt (web-client.rules)
4134 - WEB-CLIENT blnmgr clsid attempt (web-client.rules)
4135 - WEB-CLIENT IE JPEG heap overflow single packet attempt (web-client.rules)
4136 - WEB-CLIENT IE JPEG heap overflow multipacket attempt (web-client.rules)
Updated rules
-------------
472 - ICMP redirect host (icmp.rules)
473 - ICMP redirect net (icmp.rules)
1652 - WEB-CGI campas attempt (web-cgi.rules)
2671 - WEB-CLIENT bitmap BitmapOffset integer overflow attempt (web-client.rules)
3192 - WEB-CLIENT Windows Media Player directory traversal via Content-Disposition attempt (web-client.rules)
3685 - WEB-CLIENT bitmap BitmapOffset multipacket integer overflow attempt (web-client.rules)
Deleted rules
-------------
However in webadmin the rules say the sigs are dated june? When i run a manual up2date i see the following:
018 Checking Up2Date Servers ...
019 1 Up2Date Server: 80.237.220.201
020 2 Up2Date Server: 216.167.31.83
021 3 Up2Date Server: 212.126.210.201
022 Checking new Pattern for Intrusion Protection Pattern
023 Downloaded: snortrules.tar.gpg
024 snortrules-2.3.ini
025 gpg: Signature made Fri Aug 19 07:38:10 2005 EDT using DSA key ID 1E14F571
026 gpg: Good signature from "Astaro Up2Date Sign "
029 Primary key fingerprint: 564D E5C3 7701 70F2 3133 9D28 03AA 698C 1E14 F571
030 ruleset_changes.txt
031 Intrusion Protection Pattern Up2Date succeeded: New patterns installed
032 Installing Kaspersky Virus Protection Pattern
033 Virus Pattern Up2Date: No pattern installation for Virus pattern needed
The patterns are not actually installing. Any ideas?
This thread was automatically locked due to age.