De ontwikkelaars van Internet Security Systems hebben een nieuwe versie uitgebracht van BlackICE met 3.6.coe als de versieaanduiding. Deze update is in twee smaken verkrijgbaar, namelijk BlackICE PC Protection en BlackICE Server Protection. Het pakket is een veelzijdige firewall met daarbij een volledige intrusiondetectie. Zowel de inkomende als uitgaande netwerkstromen worden gecontroleerd en bij een mogelijk vermoeden dat er iets niet klopt wordt de beheerder gewaarschuwd en kan de verbinding gesloten worden. Het changelog bevat onder andere het volgende lijstje:
Security Content Updates in 3.6.coeOther updates
- A checksum calculation error which resulted in dropped packets under Linux was removed.
- A false positive with HTTP_Twiki_Search_CmdExec was removed.
- A false positive with HTML_IE_Table_Spoof was removed.
- A false positive with SMB_Malformed was removed.
- A false positive with FSP_Detected and FSP_Read_File was removed.
- A false positive with HTTP_PsaPhp_RevealSource was removed
- A false positive with RPC_Large_Fragmented was removed.
- A false positive with HTTP_IE_Status_Spoof was removed.
- A false positive with HTTP_Oracle_iSQL_Login_Overflow was removed.
- A false positive with SMTP_Routing_Overflow was removed.
- New checks have been added to ActiveX_Suspicious_Installer.
- A tuning parameter for HTTP_DotDot and HTTP_GET_DotDot_Data was added.
- HTTP access reporting is now more accurate.
- Pam.crashhook.enable tuning parameter is now set by default for Proventia A-Series and Linux network sensors.
- RTF files were removed from the Email_Executable_Extension algorithm.
[break]De volgende twee downloads staan klaar:
- The error rate for nfs_v3_dtree has been improved.
- Additional caching now improves the performance of the HTTP parser.
- Decompression support for HTTP requests has been added.
- Defense against a possible evasion method was added to the SSLv2 parser.
- Support for LHA level 0, 2, and 3 headers has been added.
- Unassigned file content is now handled more gracefully.
- SIP parser extended for more thorough coverage of SIP (Session Initiation Protocol) for better VOIP support.
- pam.activex.blacklist tunable parameter for user defined blacklists with Suspicious_ActiveX_Installer was added.
- Support in PAM for the UTF-7 character set was added.
BlackICE PC Protection 3.6.coe
BlackICE Server Protection 3.6.coe