Home page logo

snort logo Snort mailing list archives

Re: Question about xls trigger
From: James Lay <jlay () slave-tothe-box net>
Date: Fri, 28 Mar 2014 11:18:22 -0600

On 2014-03-28 10:44, SnortFan wrote:
Hi All,

I'm seeing a lot of false positives with Excel files and I think the
problem has to do with the way flowbits sets .xls files. Both SID
15463 and 19166 set 'file.xls', however it seems that 15463 is
unnecessary considering 19166. Under what circumstances would 15463 
effective while 19166 fails? Are there any reasons to keep both rules
active rather than suppressing 15463?

SID 15463
Microsoft Office Excel file download request";
flow:to_server,established; content:".xls"; fast_pattern:only;
http_uri; pcre:"/x2exls([?x5cx2f]|$)/smiU"; flowbits:set,file.xls;
flowbits:noalert; metadata:service http;
reference:url,en.wikipedia.org/wiki/.xlsFile_formats [1];
classtype:misc-activity; sid:15463; rev:16;)

SID 19166
(msg:"FILE-IDENTIFY Microsoft Office Excel file magic detected";
flow:to_client,established; file_data; content:"|D0 CF 11 E0|";
depth:4; content:"W|00|o|00|r|00|k|00|b|00|o|00|o|00|k|00|";
fast_pattern:only; flowbits:set,file.xls; flowbits:noalert;
metadata:service ftp-data, service http, service imap, service pop3;
classtype:misc-activity; sid:19166; rev:13;)

I'm using ips_policy=security in my pulledpork.


Are these actual Excel files?  If so, then these should file...these 
rules aren't saying they are malicious, just they are Excel files.


Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

Please visit http://blog.snort.org to stay current on all the latest Snort news!

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]