Network Sensor 22.21 contains 27 new events to provide protection against multiple backdoor threats, ePolicy Orchestrator, and one new event for the Sasser Worm to compliment our preemptive protection coverage of that issue. 22.21 is the next in the series after 22.19.
Checks:
| Risk | VulnID | Check Name | Category |
| High | 2389 | BackDoor_TCP_Response | Unauthorized Access Attempt |
| Low | 10627 | Edonkey_Connect | Suspicious Activity |
| Low | 10627 | Edonkey_Download | Suspicious Activity |
| High | 14166 | EPolicy_Orchestrator_Vulnerable_Server | Unauthorized Access Attempt |
| High | 15053 | TheFlu_TCP_Request | Unauthorized Access Attempt |
| High | 15110 | VoodooDoll_TCP_Request | Unauthorized Access Attempt |
| High | 15114 | Mantis_TCP_Response | Unauthorized Access Attempt |
| High | 15116 | MicroSpy_TCP_Response | Unauthorized Access Attempt |
| High | 15118 | Oblivion_TCP_Response | Unauthorized Access Attempt |
| High | 15148 | Balistix_Request | Unauthorized Access Attempt |
| High | 15148 | Balistix_Response | Unauthorized Access Attempt |
| High | 15150 | BasicHell_TCP_Response | Unauthorized Access Attempt |
| High | 15151 | BDDT_TCP_Response | Unauthorized Access Attempt |
| High | 15153 | Bigorna_TCP_Response | Unauthorized Access Attempt |
| High | 15156 | Bla_Request | Unauthorized Access Attempt |
| High | 15157 | DigitalRootBeer_TCP_Request | Unauthorized Access Attempt |
| Medium | 15646 | HTTP_Connect_Proxy_Bypass_SMTP | Suspicious Activity |
| High | 15767 | HTTP_POST_Content_Length_Negative | Unauthorized Access Attempt |
| High | 15792 | Celine_TCP_Response | Unauthorized Access Attempt |
| High | 15793 | DFchGrisch_TCP_Response | Unauthorized Access Attempt |
| High | 15944 | BladeRunner_TCP_Request | Unauthorized Access Attempt |
| High | 15944 | BladeRunner_TCP_Response | Unauthorized Access Attempt |
| High | 15947 | Cafeini_TCP_Response | Unauthorized Access Attempt |
| Medium | 15952 | HTTP_Connect | Suspicious Activity |
| High | 15961 | CrackDown_TCP_Response | Unauthorized Access Attempt |
| Low | 16007 | DirectConnect_Connect | Protocol Signature |
| High | 16045 | Sasser_Propagation | Unauthorized Access Attempt |
If you are an existing customer or partner, and you wish to download X-Press Updates from our download center, click here.
