This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IPS rule 852 wreaking havoc

Hello AUBB

I updated my V8's firmware to 8.309 two nights ago, and the next day I started getting IPS alert emails for CRIT 852.  This is strange because I have 852 disabled in Network Security > Intrusion Prevention > Advanced > Modifed rules.

Can anybody tell me what the heck is going on with that?

I'm getting alerts for embedded files in email attachments, and the emails are not being delivered.

Here are some examples of what I'm getting in various alerts.

"FILE-PDF EmbeddedFile contained within a PDF"
"FILE-OFFICE Microsoft Office Excel Malformed Record Code Execution attempt"
"FILE-OFFICE Microsoft Office Excel colinfo XF record overflow attempt"

Right now I have to run with IPS disabled so I know email is getting through.

Please help!  Thanks.


This thread was automatically locked due to age.