Re: TCP reassembly does not appear to be working properly

Al Lewis via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CAFS=A8sco68u_EeA3JkLnRZnHzO5knxty6OGt_V3aG3t899NzQ@mail.gmail.com>
Do you have stream reassembly enabled? Can you show your configuration? ..
Have you tried placing the pcap in a password protected/encrypted zip?

On Mon, Jan 31, 2022, 8:15 PM kobajin via Snort-users <
[email protected]> wrote:

> Hello, everyone.
> I am a beginner and I am currently working on an experiment to detect
> exploit packets collected in an experimental environment using Snort.
>
> I am currently facing a problem in that I cannot detect HTTP requests
> correctly when they are sent in multiple TCP segments. I believe that such
> requests should be reassembled by Snort before being detected, but the
> output from the show_rebuilt_packets option doesn't seem to indicate that.
> How can I make it reassemble correctly? Since Wireshark and Zeek
> correctly reassembled the segments, I believe that there is no problem with
> the packets. I'm sorry, but I couldn't share the pcap file itself because
> it was caught by Gmail's virus detection.
>
> Here is debug output by show_rebuilt_packets.
>
>> ## This is  first segment
>> 12/27-00:37:24.591336 TCP 192.168.32.18:44875 -> 192.168.32.116:80
>> <http://192.168.32.116/>http_inspect.stream_tcp[8243]:
>> - - - - - - - - - - - -  - - - - - - - - - - - -  - - - - - - - - -
>> 47 45 54 20 2F 57 65 62 49 44 2F 49 49 53 57 65  GET /Web ID/IISWe
>> 62 41 67 65 6E 74 49 46  2E 64 6C 6C 3F 52 65 64  bAgentIF .dll?Red
>> ----------------------------------- very large data
>> ----------------------------------------
>> 6B 50 62 74 48 61 6A 62  59 77 20 48 54 54 50 2F  kPbtHajb Yw HTTP/
>> 31 2E 31
>>   1.1
>> - - - - - - - - - - - -  - - - - - - - - - - - -  - - - - - - - - -
>>
>> ## I want this segment reassembled with the first segment
>> 12/27-00:37:24.591361 TCP 192.168.32.18:44875 -> 192.168.32.116:80
>> <http://192.168.32.116/>http_inspect.stream_tcp[83]:
>> - - - - - - - - - - - -  - - - - - - - - - - - -  - - - - - - - - -
>> 48 6F 73 74 3A 20 76 69  63 74 69 6D 2D 39 2D 35  Host: vi ctim-9-5
>> 2D 39 35 0D 0A 55 73 65  72 2D 41 67 65 6E 74 3A  -95..Use r-Agent:
>> 20 4D 6F 7A 69 6C 6C 61  2F 34 2E 30 20 28 63 6F   Mozilla /4.0 (co
>> 6D 70 61 74 69 62 6C 65  3B 20 4D 53 49 45 20 36  mpatible ; MSIE 6
>> 2E 30 3B 20 57 69 6E 64  6F 77 73 20 4E 54 20 35  .0; Wind ows NT 5
>> 2E 31 29
>>    .1)
>
>
> Here is the command I used.
>
>> snort -R <rule file> -r <pcap file> -c <config file> -k none --snaplen
>> 65535 -z 8
>
>
> The attached screenshot is the reassembled HTTP request by Wireshark.
> Thank you!
>
> _______________________________________________
> Snort-users mailing list
> [email protected]
> Go to this URL to change user options or unsubscribe:
> https://lists.snort.org/mailman/listinfo/snort-users
>
>         To unsubscribe, send an email to:
>         [email protected]
>
> Please visit http://blog.snort.org to stay current on all the latest
> Snort news!
>
> Please follow these rules:
> https://snort.org/faq/what-is-the-mailing-list-etiquette
>

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.