Endpoint Protection

 View Only
  • 1.  [SID: 21960] MSRPC Spooler GetPrinterData DoS detected - False Positives with Updated IPS

    Posted Oct 26, 2009 04:58 PM
    The IPS definitions dated 2009-10-20 rev.001 introduced false positives with the following description: [SID: 20628] MSRPC Mutiple Headers detected. Symantec finally released an updated IPS definitions, dated 2009-10-26 rev.018, which resolved this specific problem, but now introduces an additional false positive with the following description: [SID: 21960] MSRPC Spooler GetPrinterData DoS detected. At this point, this new false positives is only affects Windows computers that aren’t joined to our domain that are trying to connect to our Windows Server 2003 R2 x64 printer server. At this point I am seriously considering rolling back to the September’s IPS definitions, which doesn’t contain any of these false positives. When will Symantec get this correct?


  • 2.  RE: [SID: 21960] MSRPC Spooler GetPrinterData DoS detected - False Positives with Updated IPS

    Posted Oct 26, 2009 05:14 PM
    Please open a support ticket with Symantec


  • 3.  RE: [SID: 21960] MSRPC Spooler GetPrinterData DoS detected - False Positives with Updated IPS

    Posted Oct 26, 2009 10:30 PM
    Kindly change the title of the thread if possible, since this is a different False positive.


  • 4.  RE: [SID: 21960] MSRPC Spooler GetPrinterData DoS detected - False Positives with Updated IPS



  • 5.  RE: [SID: 21960] MSRPC Spooler GetPrinterData DoS detected - False Positives with Updated IPS

    Posted Oct 27, 2009 08:39 PM
    The print spooler update was for Windows 2000.  This error is appearing on Windows Vista and 7 PCs.