Posts by Shane Feek

1) Message boards : BOINC client : Sonicwall Vulnerability Alert on BOINC traffic (Message 68085)
Posted 2 Mar 2016 by Shane Feek
Post:
I simply added an exception rule in the Intrusion Prevention Service and after a retry, the file uploaded properly. If other users of Sonicwall Appliances have this false positive and file blockage, that is the solution. I hope this can help other users!
2) Message boards : BOINC client : Sonicwall Vulnerability Alert on BOINC traffic (Message 68062)
Posted 1 Mar 2016 by Shane Feek
Post:
Recently our Sonicwall Firewall Appliance began flagging BOINC client communications with the following message:

03/01/2016 04:40:05 - 609 - Security Services - Alert - 208.68.240.119, 80, X1 - 10.10.1.100, 52637, X0 - IPS Prevention Alert: WEB-CLIENT Microsoft AntiXSS Information Disclosure (MS12-007), SID: 3357, Priority: Medium

This email was generated by: SonicOS Enhanced 5.9.0.4-127o (0017-C5C2-0B28)

Has there been a recent change to the client that has a vulnerability? Should I just allow the traffic? As far as I can see the BOINC client is still able to complete it's communication and I am still getting credit for jobs.


Looks like it does this when downloading from SETI@home
The file in question is: 11oc10ad.146832.18881.10.37.86




Copyright © 2024 University of California.
Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation License, Version 1.2 or any later version published by the Free Software Foundation.