Download BlackICE 3.6.cpw

Spread the love

The developers of Internet Security Systems have released a new version of BlackICE with 3.6.cpw as the version designation. This update comes in two flavors viz BlackICE PC Protection and BlackICE Server Protection. The package is a versatile firewall with full intrusion detection. Both the incoming and outgoing network flows are checked and if there is a possible suspicion that something is wrong, the administrator is warned and the connection can be closed. The list of adjustments looks like this:

[break]New Security Content:

ProductCheckNameEvent TypeRisk Level
SIP_Invalid_URISuspicious activityLow
HTTP_Orion_JSP_SourceReadSuspicious activityLow
HTTP_MHTML_RedirectSuspicious activityMedium
Shellcode_DetectedUnauthorized Access AttemptHigh
HTML_ClassID_OverflowUnauthorized Access AttemptHigh
HTTP_AIMExpressSuspicious activityLow
FTP_Checksum_Cmd_BOUnauthorized Access AttemptHigh
HTML_IE_Render_Memory_CorruptionUnauthorized Access AttemptHigh
SMTP_MailEnable_NTLM_Type1_OverflowUnauthorized Access AttemptHigh
SMTP_MailEnable_NTLM_Type3_OverflowUnauthorized Access AttemptHigh
EPolicy_Orchestrator_Source_OverflowUnauthorized Access AttemptHigh
Sunrpc_BackupProduct_BOUnauthorized Access AttemptHigh
Sunrpc_BackupProduct_String_OverflowUnauthorized Access AttemptHigh
SIP_Invalid_Invite_AddressSuspicious activityLow
VPN_Hamachi_ClientSuspicious activityLow
Video_Flic_Color_BOUnauthorized Access AttemptHigh
Video_Flic_MalformedSuspicious activityLow
ACF_Mem_CorruptionUnauthorized Access AttemptHigh
MSRPC_WksSvc_Mgmnt_JoinDom_BoUnauthorized Access AttemptHigh
MSRPC_Netware_Change_Password_BOUnauthorized Access AttemptHigh
MSRPC_Netware_Get_User_DoSDenial of ServiceLow
DNS_Malformed_FloodDenial of ServiceMedium

Security Content Improvements:

  • Fixed an attacker vs. victim reporting error in SSH_Vulnerable_OpenSSH
  • The PAM tuning parameter, pam.email.executable.extension.blacklist, has been changed to report all of the default file extensions on one line in the pam log file.
  • Fixed memory leak in the processing of .url files.
  • The Compound File parser was optimized to reduce space.
  • The Flash file parser was updated to reduce the potential of a false positive in some circumstances.
  • Fixed a false positive in Email_HTML_File_URI wherein an IP address in the hostname portion of the URI was incorrectly detected.
  • Fixed a false positive for SIP_Long_Via_Host and SIP_Unknown_Via_Parameter that could occur in certain networking-relaying configurations.
  • The IRC parser was updated to more closely adhere to RFC 1459.
  • The report for URL_file_URI_overflow now displays the correct length value.
  • A false positive was corrected in HTTP_DotDotDot that occurred when using carefully constructed URLs.
  • False positives were removed for DPS_Magic_Number_DoS.

Version number3.6.cpw
Operating systemsWindows 9x, Windows 2000, Windows XP, Windows Server 2003
WebsiteInternet Security Systems
Download
License typeShareware
Facebook Notice for EU! You need to login to view and post FB Comments!
You might also like