PDA

View Full Version : Attack from Wilderssecurity.com ???


Perman
May 25th, 2006, 01:46 PM
Hi, folks., Very strange things have happened for the last few days. Each time when I visit wilderssecurity forum, BlackIce will block an attack,issuing a warning. I am able to trace back and have some details, perhaps someone at Wilders or some experts can solve this puzzle:
issue:HTML_Mshtml_overflow parameters: URL=/clientscript/vbulletin_quick_edit.js&server=wildrssecurity.com

LowWaterMark
May 25th, 2006, 05:45 PM
Looks like a false positive from BlackICE. I can't begin to explain it though since we use generic vBulletin forum software here, and I don't know what BlackICE is using as a signature (is that an IDS like alert?). You may need to ask the BlackICE people exactly what that message means and what triggers it. There is probably an exceptions or exclusions list to prevent the alerts, like a trusted site list of some such.

Is there more logged then just that one line?

LowWaterMark
May 25th, 2006, 05:54 PM
Ah, BlackICE, same error on other vBulletin forums (would seem to indicate a recent signature update is causing it):

http://www.the-scream.co.uk/forums/t21560.html

http://forum.pcwelt.de/forum/showthread.php?p=1071512

Perman
May 26th, 2006, 10:20 AM
{QUOTE-> Ah, BlackICE, same error on other vBulletin forums (would seem to indicate a recent signature update is causing it):

http://www.the-scream.co.uk/forums/t21560.html

http://forum.pcwelt.de/forum/showthread.php?p=1071512 <-QUOTE}
Hi, thank u for ur prompt reply. I will click the links and take a good look. BTW, I have not encountered the same problems for the last few hours. and FYI, the lateset signature update was done on May 11, 2006, and the problems did not occur until few days ago. Regards,???