RealSecure Network, RealSecure Server Sensor, RealSecure Desktop Protector, BlackICE Agent for Server, RealSecure Guard, RealSecure Sentry, BlackICE PC Protection, BlackICE Server Protection, IBM Security Server Protection for Windows, Proventia Network MFS, Proventia-G 1.1 and earlier, Proventia Network IDS, Proventia Desktop, Proventia Network IPS, RealSecure Desktop Protector 3.6, Proventia Server IPS for Linux technology, Virtual Server Protection for Vmware:
This signature detects vulnerability assessments being made with the freely available version of Internet Scanner, or with the commercial version of the product made by Internet Security Systems (ISS).
This signature replaces ISS.
This signature detects vulnerability assessments being made with the freely available version of Internet Scanner, or with the commercial version of the product made by Internet Security Systems (ISS).
This signature replaces ISS.
Low
RealSecure Network: 7.0, RealSecure Server Sensor: 7.0, RealSecure Desktop Protector: 3.6, BlackICE Agent for Server: 3.6, RealSecure Guard: 3.6, RealSecure Sentry: 3.6, BlackICE PC Protection: 3.6.cbd, BlackICE Server Protection: 3.6.cbd, IBM Security Server Protection for Windows: 1.0.914.0, IBM Security Server Protection for Windows: 2.1.14.2400, Proventia Network MFS: 1.0, Proventia-G 1.1 and earlier: G Series, Proventia Network IDS: A Series, Proventia Desktop: 8.0.614.1, Proventia Network IPS: 2.0, RealSecure Desktop Protector 3.6: baseline, RealSecure Desktop: baseline, Proventia Server IPS for Linux technology: 1.0, Virtual Server Protection for Vmware: 1.0
Various vendors Any application
Pre-attack Probe
ISS vulnerability assessment products can identify weaknesses in networks connected to the Internet. By using ISS vulnerability assessment products, an attacker could gain information that would be useful in performing an attack.
Examine the source of the scan. If the scan comes from inside your organization or uses your own ISS vulnerability assessment product key, then you may not need to worry. If it comes from outside or uses a key you do not recognize or uses an earlier shareware version of an ISS vulnerability assessment product, then you should identify the scanning entity and determine the intent of the scan.
CERT Advisory CA-1993-14
Internet Security Scanner (ISS)
http://www.cert.org/advisories/CA-1993-14.html
ISS X-Force
ISS vulnerability assessment product scan detected
http://www.iss.net/security_center/static/632.php