Download BlackICE 3.6.coe
The developers of Internet Security Systems have released a new version of BlackICE with 3.6.coe as the version designation. This update is available in two flavors, namely BlackICE PC Protection and BlackICE Server Protection† The package is a versatile firewall with full intrusion detection. Both the incoming and outgoing network flows are checked and if there is a possible suspicion that something is wrong, the administrator is warned and the connection can be closed. The changelog includes the following list:
Security Content Updates in 3.6.coe
- A checksum calculation error which resulted in dropped packets under Linux was removed.
- A false positive with HTTP_Twiki_Search_CmdExec was removed.
- A false positive with HTML_IE_Table_Spoof was removed.
- A false positive with SMB_Malformed was removed.
- A false positive with FSP_Detected and FSP_Read_File was removed.
- A false positive with HTTP_PsaPhp_RevealSource was removed
- A false positive with RPC_Large_Fragmented was removed.
- A false positive with HTTP_IE_Status_Spoof was removed.
- A false positive with HTTP_Oracle_iSQL_Login_Overflow was removed.
- A false positive with SMTP_Routing_Overflow was removed.
- New checks have been added to ActiveX_Suspicious_Installer.
- A tuning parameter for HTTP_DotDot and HTTP_GET_DotDot_Data was added.
- HTTP access reporting is now more accurate.
- Pam.crashhook.enable tuning parameter is now set by default for Proventia A-Series and Linux network sensors.
- RTF files were removed from the Email_Executable_Extension algorithm.
Other updates
- The error rate for nfs_v3_dtree has been improved.
- Additional caching now improves the performance of the HTTP parser.
- Decompression support for HTTP requests has been added.
- Defense against a possible evasion method was added to the SSLv2 parser.
- Support for LHA level 0, 2, and 3 headers has been added.
- Unassigned file content is now handled more gracefully.
- SIP parser extended for more thorough coverage of SIP (Session Initiation Protocol) for better VOIP support.
- pam.activex.blacklist tunable parameter for user defined blacklists with Suspicious_ActiveX_Installer was added.
- Support in PAM for the UTF-7 character set was added.
[break]The following two downloads are ready:
BlackICE PC Protection 3.6.coe
BlackICE Server Protection 3.6.coe
Version number | 3.6.coe |
Operating systems | Windows 9x, Windows NT, Windows 2000, Windows XP |
Website | Internet Security Systems |
Download | |
License type | Shareware |