socalgal
06-12-2000, 03:18 PM
Late posting, but here's the release description:
http://www.networkice.com/html/blackice_defender_update.html
What: This is BlackICE Defender release 2.1.
Why: This release provides the following fixes/changes:
Support for Windows 2000. BlackICE is now supported to run on Windows 2000 Pro.
Improved user interface and functions:
Configurable severity levels to trigger visual and (new) audible attack notification.
Configurable Attacks and Intruders tab columns; you can view all of the data previously hidden in attack-list.csv.
Visible menu.
Attacks and Intruders tabs now have indication of an attacker's or intruder's blocked state.
Copy to clipboard (via Ctrl-C) capability on Attacks and Intruders tabs.
Graphical LED lights that provide visual indication of network activity.
Auto-checking for new BlackICE updates
Auto-port blocking response. BlackICE will now do an automatic port block on certain critical attacks (e.g. Trojan horse attacks like Back Orifice)
New Detections:
FTP file exec exploit
FTP compress exec exploit
POP3 RETR argument very long
Empty fragment
ICMP flood
Twinge attack
Zero length
TCP option
TCP small segment size
TCP SYN with URG flag
TCP Invalid
Urgent offset
UDP short header
DNS BIND version request
DNS null
PrettyPark worm
ILOVEYOU virus
NetSphere HTTP activity
HTTP asp with \ appended
CGI finger.cgi
WebSpeed admin URL
UBB suspicious posting
SubSeven ICQ pager URL
Oracle batch file URL
sojourn.cgi argument contains %00
Index Server null.htw exploit
FrontPage extension backdoor URL
FrontPage htimage.exe URL
InfoSearch CGI exploit
Cart32 Clientlist URL
Cart32 ChangeAdminPassword URL
Listserv CGI exploit
HTTP URL contains %00
HTTP User Agent field overflow
SMB startup file
SMB autoexec.bat file
SOCKS login failed
SOCKS connect
SOCKS over SOCKS
SNTP malformed
RPC bad credentials
RPC suspicious credentials
RPC getport probe
rpc.sadmind overflow
Mstream agent activity
Mstream handler activity
Applicability: This update is applicable to all BlackICE Defender releases.
Content: BlackICE Defender Release 2.1
blackice.exe version 2.1
blackd.exe version 2.1
blackdll.dll version 2.1
blackdrv.vxd version 2.1 (for Win 95/98)
blackdrv.sys version 2.1 (for Win NT) 1
http://www.networkice.com/html/blackice_defender_update.html
What: This is BlackICE Defender release 2.1.
Why: This release provides the following fixes/changes:
Support for Windows 2000. BlackICE is now supported to run on Windows 2000 Pro.
Improved user interface and functions:
Configurable severity levels to trigger visual and (new) audible attack notification.
Configurable Attacks and Intruders tab columns; you can view all of the data previously hidden in attack-list.csv.
Visible menu.
Attacks and Intruders tabs now have indication of an attacker's or intruder's blocked state.
Copy to clipboard (via Ctrl-C) capability on Attacks and Intruders tabs.
Graphical LED lights that provide visual indication of network activity.
Auto-checking for new BlackICE updates
Auto-port blocking response. BlackICE will now do an automatic port block on certain critical attacks (e.g. Trojan horse attacks like Back Orifice)
New Detections:
FTP file exec exploit
FTP compress exec exploit
POP3 RETR argument very long
Empty fragment
ICMP flood
Twinge attack
Zero length
TCP option
TCP small segment size
TCP SYN with URG flag
TCP Invalid
Urgent offset
UDP short header
DNS BIND version request
DNS null
PrettyPark worm
ILOVEYOU virus
NetSphere HTTP activity
HTTP asp with \ appended
CGI finger.cgi
WebSpeed admin URL
UBB suspicious posting
SubSeven ICQ pager URL
Oracle batch file URL
sojourn.cgi argument contains %00
Index Server null.htw exploit
FrontPage extension backdoor URL
FrontPage htimage.exe URL
InfoSearch CGI exploit
Cart32 Clientlist URL
Cart32 ChangeAdminPassword URL
Listserv CGI exploit
HTTP URL contains %00
HTTP User Agent field overflow
SMB startup file
SMB autoexec.bat file
SOCKS login failed
SOCKS connect
SOCKS over SOCKS
SNTP malformed
RPC bad credentials
RPC suspicious credentials
RPC getport probe
rpc.sadmind overflow
Mstream agent activity
Mstream handler activity
Applicability: This update is applicable to all BlackICE Defender releases.
Content: BlackICE Defender Release 2.1
blackice.exe version 2.1
blackd.exe version 2.1
blackdll.dll version 2.1
blackdrv.vxd version 2.1 (for Win 95/98)
blackdrv.sys version 2.1 (for Win NT) 1