7-21
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter7 Defining Signatures
Configuring Signatures
For More Information
For the procedure for enabling signatures, see Configuring the Status of Signatures, page 7-13.
AIC MIME Define Content Type Signatures
There are two policies associat ed with MIME types:
Define content type—Associates specific actions for the following cases (Define Content Type):
Deny a specific MIME type, such as an image/jpeg
Message size violation
MIME-type mentioned in header and body do not match
Recognized content type (Recognized Content Type)
Tabl e 7-2 lists the predefined define content type signatures. Enable the signatures that have the
predefined content type you need. You can also create custom define content type signatures.
12704 Define Request Method REVLABEL
12705 Define Request Method REVLOG
12706 Define Request Method REVADD
12707 Define Request Method REVNUM
12708 Define Request Method SETATTRIBUTE
12709 Define Request Method GETATTRIBUTENAME
12710 Define Request Method GETPROPERTIES
12711 Define Request Method STARTENV
12712 Define Request Method STOPREV
Table7-1 Request Method Signatures (continued)
Signature ID Define Request Method
Table7-2 Define Content Type Signatures
Signature ID Signature Description
12621 Content Type image/gif Invalid Message Length
12622 2 Content Type image/png Verification Failed
12623 0
12623 1
12623 2
Content Type image/tiff Header Check
Content Type image/tiff Invalid Message Length
Content Type image/tiff Verification Failed
12624 0
12624 1
12624 2
Content Type image/x-3ds Header Check
Content Type image/x-3ds Invalid Message Length
Content Type image/x-3ds Verification Failed
12626 0
12626 1
12626 2
Content Type image/x-portable-bitmap Header Check
Content Type image/x-portable-bitmap Invalid Message Length
Content Type image/x-portable-bitmap Verification Failed