<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS Prevent with wrong signature in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IPS-Prevent-with-wrong-signature/m-p/82249#M16630</link>
    <description>Hi Timthy_Hall&lt;BR /&gt;&lt;BR /&gt;Thank you for sharing.&lt;BR /&gt;&lt;BR /&gt;I appreciate your comment.</description>
    <pubDate>Fri, 17 Apr 2020 14:48:51 GMT</pubDate>
    <dc:creator>Sarm_Chanatip</dc:creator>
    <dc:date>2020-04-17T14:48:51Z</dc:date>
    <item>
      <title>IPS Prevent with wrong signature</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-Prevent-with-wrong-signature/m-p/81410#M16442</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had a chance to test IPS functional with detecting or preventing in R80.30 version, so my experiment is to use the Metasploit tool in kali with Exploit Eternalblue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After exploited successfully, found that the security gateway was able to block some malicious code with IPS module but the signature is being shown on the screenshot below is MS10-012 ( Microsoft SMB server race condition denial of service)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="cp-1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5472iA29A3BB4EDB5ACFA/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp-1.png" alt="cp-1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually it should be prevented with MS17-010 (SMB Remote Code Execution)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="cp-2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5473iAE5B8DD9C403EA53/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp-2.png" alt="cp-2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone here explain to me regarding this behavior?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sarm&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2020 07:56:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-Prevent-with-wrong-signature/m-p/81410#M16442</guid>
      <dc:creator>Sarm_Chanatip</dc:creator>
      <dc:date>2020-04-09T07:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Prevent with wrong signature</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-Prevent-with-wrong-signature/m-p/81529#M16470</link>
      <description>Does anyone know?</description>
      <pubDate>Fri, 10 Apr 2020 07:49:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-Prevent-with-wrong-signature/m-p/81529#M16470</guid>
      <dc:creator>Sarm_Chanatip</dc:creator>
      <dc:date>2020-04-10T07:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Prevent with wrong signature</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-Prevent-with-wrong-signature/m-p/81545#M16476</link>
      <description>&lt;P&gt;First off, the firewall blocked it correctly so it doesn't really matter which IPS signature got matched.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But to answer your question if I am reading the CVEs correctly, MS10-012 (Microsoft SMB server race condition denial of service- CVE-2010-0021) was the ability to corrupt and crash the system (DoS) through a vulnerability in the SMB v1 server and was revealed in 2010.&amp;nbsp; MS17-010 (SMB Remote Code Execution - CVE-2017-0143) appears to be very similar in that it is the weaponization of that earlier vulnerability in 2017 that can execute arbitrary code via SMB v1, instead of just cause a DoS.&amp;nbsp; So to me it looks like the same vulnerability with just different outcomes (DoS in 2010 vs. running arbitrary code in 2017).&amp;nbsp; In that case it would make sense that the 2010 IPS signature would get triggered, even though your kit was attempting the 2017 code exploit as they are basically the same thing, just different outcomes.&amp;nbsp; I don't think your exploit got far enough to inject the arbitrary code before the 2010 IPS signature was triggered and stopped it.&lt;/P&gt;
&lt;P&gt;Check out this other CheckMates thread which is very similar to your situation:&lt;/P&gt;
&lt;H2 class="message-subject"&gt;&lt;SPAN class="lia-message-read"&gt;&lt;A id="link_12" class="page-link lia-link-navigation lia-custom-event" href="https://community.checkpoint.com/t5/IPS-Anti-Virus-Anti-Bot-Anti/IPS-signature-does-not-match-with-attack-type/m-p/56354?search-action-id=14198697978&amp;amp;search-result-uid=56354" target="_blank"&gt;IPS &lt;SPAN class="lia-search-match-lithium"&gt;signature&lt;/SPAN&gt; &lt;SPAN class="lia-search-match-lithium"&gt;does&lt;/SPAN&gt; &lt;SPAN class="lia-search-match-lithium"&gt;not&lt;/SPAN&gt; &lt;SPAN class="lia-search-match-lithium"&gt;match&lt;/SPAN&gt; &lt;SPAN class="lia-search-match-lithium"&gt;with&lt;/SPAN&gt; &lt;SPAN class="lia-search-match-lithium"&gt;attack&lt;/SPAN&gt; &lt;SPAN class="lia-search-match-lithium"&gt;type&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2020 12:38:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-Prevent-with-wrong-signature/m-p/81545#M16476</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-04-10T12:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Prevent with wrong signature</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPS-Prevent-with-wrong-signature/m-p/82249#M16630</link>
      <description>Hi Timthy_Hall&lt;BR /&gt;&lt;BR /&gt;Thank you for sharing.&lt;BR /&gt;&lt;BR /&gt;I appreciate your comment.</description>
      <pubDate>Fri, 17 Apr 2020 14:48:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPS-Prevent-with-wrong-signature/m-p/82249#M16630</guid>
      <dc:creator>Sarm_Chanatip</dc:creator>
      <dc:date>2020-04-17T14:48:51Z</dc:date>
    </item>
  </channel>
</rss>

