Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

SEP Custom IPS Policy to block Latest IE 0day attack (AKA Aurora exploit) - CVE-2010-0249

Updated: 25 Jan 2010 | 2 comments
Aaed Alqarta's picture
+3 3 Votes
Login to vote

I've built a custom IPS policy to block Aurora exploit and I've used Metasploit's IE_Aurora module to attack my virtual machine and guess what, SEP blocked the attack. Attached you'll have the policy file and a screenshot. Please Import, test and report any problems/comments.

The attached files are:

1. SEP custom IPS policy

2. Metasploit's IE_Aurora exploit VS SEP demo
 

Comments

Vikram Kumar-SAV to SEP's picture
26
Jan
2010
0 Votes 0
Login to vote
Mithun Sanghavi's picture
31
May
2011
0 Votes 0
Login to vote

Thanks for Sharing.

Hello,

Thanks for sharing this information.

Mithun Sanghavi
Symantec Technical Support Engineer, SEP
MIM | MCSA | SCTS | ITIL v3

Follow me on Twitter: @mithun_sanghavi

Don't forget to mark your thread as 'SOLVED' with the answer that best helped yo