Message 1 of 3
Application Manager updates
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report
Have any others had issues with your firewall telling you that a user has initated a DDOS attack by recieving an update via the Autodesk Application manager?
My firewall is reporting the following.
| disposition | source_ip | destination | protocol | policy_name | severity | signature_id | signature_name | signature_cat | timezone | count |
| Denied | [email protected] | 23.54.77.121:443 | https/tcp | HTTPS-proxy-00 | 4 | 1130226 | SSL OpenSSL Invalid Session Ticket Denial of Service -1 (CVE-20 | DoS/DDoS | 11/12/2015 11:16 | 6 |
| Denied | [email protected] | 23.54.77.121:443 | https/tcp | HTTPS-proxy-00 | 4 | 1130226 | SSL OpenSSL Invalid Session Ticket Denial of Service -1 (CVE-20 | DoS/DDoS | 11/12/2015 11:48 | 5 |
| Denied | [email protected] | 23.54.77.121:443 | https/tcp | HTTPS-proxy-00 | 4 | 1130226 | SSL OpenSSL Invalid Session Ticket Denial of Service -1 (CVE-20 | DoS/DDoS | 11/12/2015 14:49 | 5 |
| Denied | [email protected] | 23.54.77.121:443 | https/tcp | HTTPS-proxy-00 | 4 | 1130226 | SSL OpenSSL Invalid Session Ticket Denial of Service -1 (CVE-20 | DoS/DDoS | 11/12/2015 16:15 | 7 |
When I look them up on the Watchguard security portal I get the following information.
Intrusion Prevention Service
| Signature Version: 4.030 |
| ![]() | ||||||||
| Description: It is due to a memory leak when OpenSSL processes invalid session tickets to verify their integrity | |||||||||
| Impact: Denial of service | |||||||||
| Recommendation: Update vendor's patch | |||||||||
| False Positive: None | |||||||||
| False Negative: None | |||||||||
| Additional Information (Links open in new window): | |||||||||
| |||||||||
| Reference(s): CVE-2014-3567 |
