Endpoint Protection

 View Only
  • 1.  SEP Error (OS Attack)

    Posted Sep 12, 2014 07:11 AM
      |   view attached

    Hi,

    One of my clients are getting the error (pop-up) OS Attack in SEP and that system is windows XP.

    Please find the attachment.



  • 2.  RE: SEP Error (OS Attack)

    Posted Sep 12, 2014 07:17 AM

    [SID: 23179] Intrusion Detection alerts received on a Symantec Endpoint Protection client for ntoskrnl.exe













    Article:TECH131438  | Created: 2010-01-02  | Updated: 2014-02-06  | Article URL http://www.symantec.com/docs/TECH131438



  • 3.  RE: SEP Error (OS Attack)

    Posted Sep 12, 2014 09:23 AM

    IPS (Intrusion Prevention) detected and prevented an attack on this client. Here is info for SID 23179: http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=23179

    Perhaps the client needs to be patched.



  • 4.  RE: SEP Error (OS Attack)

    Posted Sep 12, 2014 09:27 AM

    Check the resolution for it

    It's a vulnerability so require to update the patches

    OS Attack: MSRPC Server Service RPC CVE-2008-4250

    http://www.securityfocus.com/bid/31874

     

    https://www-secure.symantec.com/connect/forums/sid-23179-os-attack-msrpc-server-service-rpc-cve-2008-4250-attack-blocked-traffic-has-been--0

    How to Disable Client Intrusion Prevention Notifications in Symantec Endpoint Protection Manager (SEPM)

    Article:TECH105013  |  Created: 2008-01-28  |  Updated: 2010-01-11  |  Article URL http://www.symantec.com/docs/TECH105013


  • 5.  RE: SEP Error (OS Attack)

    Posted Sep 12, 2014 09:35 AM

    This is the Conficker worm. You have an infected system on your network tryingn to infect other machines. Check the remote source to swhich machine it is and get it off the network and patched.



  • 6.  RE: SEP Error (OS Attack)

    Posted Sep 12, 2014 12:48 PM

    This article will help:

    Killing Conficker: How to Eradicate W32.Downadup for Good
    https://www-secure.symantec.com/connect/articles/killing-conficker-how-eradicate-w32downadup-good



  • 7.  RE: SEP Error (OS Attack)

    Posted Sep 12, 2014 11:01 PM

    Ok...Thanks FYI.

    Regards,

    Malli.