SG-1.IMS.IDEAS.GD-AIS.COM 08/24/04:21.00 system check (fwd)
Merton Campbell Crockett <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
I spotted this set of entries in my "hourly" log file synopsis and thought it might be of interest. I use the BSD/OS IPFW Facility, a firewall toolkit developed by BSDi. The items of interest are the packet fragments with "Don't Fragment" set that were rejected by pre-input rule 02. Since developing the IPFW rules three years ago, this is the first instance of detecting a fragmented "Don't Fragment" packet. As all of the other ports are associated with Microsoft vulnerabilites, I assume that the fragmentation was intended to trigger a vulnerability in IIS. Merton Campbell Crockett ---------- Forwarded message ---------- Date: Tue, 24 Aug 2004 21:00:01 -0700 (PDT) From: "WAVE (SG-1) Administrator" <[email protected]> To: [email protected] Subject: SG-1.IMS.IDEAS.GD-AIS.COM 08/24/04:21.00 system check Security Violations =-=-=-=-=-=-=-=-=-= [...] Aug 24 18:00:47 SG-1 ipfwlog[123]: 04/08/24 18:00:47 !I 02 61.149.95.79 -> 192.73.3.83 D frag @ 1472 Aug 24 18:00:47 SG-1 ipfwlog[123]: 04/08/24 18:00:47 !I 02 61.149.95.79 -> 192.73.3.83 DM TCP 3662 -> 80 A Aug 24 18:00:47 SG-1 ipfwlog[123]: 04/08/24 18:00:47 !I 02 61.149.95.79 -> 192.73.3.83 D frag @ 1472 Aug 24 18:00:47 SG-1 ipfwlog[123]: 04/08/24 18:00:47 !I 02 61.149.95.79 -> 192.73.3.83 DM TCP 3662 -> 80 A [...] Aug 24 18:00:50 SG-1 ipfwlog[123]: 04/08/24 18:00:50 !I 34 61.149.95.79 -> 192.73.3.83 D TCP 3627 -> 1433 S Aug 24 18:00:50 SG-1 ipfwlog[123]: 04/08/24 18:00:50 !I 32 61.149.95.79 -> 192.73.3.83 D TCP 2984 -> 1025 S Aug 24 18:00:50 SG-1 ipfwlog[123]: 04/08/24 18:00:50 !I 34 61.149.95.79 -> 192.73.3.83 D TCP 3259 -> 6129 S Aug 24 18:00:51 SG-1 ipfwlog[123]: 04/08/24 18:00:51 !I 02 61.149.95.79 -> 192.73.3.83 DM TCP 3662 -> 80 A Aug 24 18:00:57 SG-1 ipfwlog[123]: 04/08/24 18:00:57 !I 34 61.149.95.79 -> 192.73.3.83 D TCP 3627 -> 1433 S Aug 24 18:00:57 SG-1 ipfwlog[123]: 04/08/24 18:00:57 !I 32 61.149.95.79 -> 192.73.3.83 D TCP 2984 -> 1025 S Aug 24 18:00:58 SG-1 ipfwlog[123]: 04/08/24 18:00:58 !I 02 61.149.95.79 -> 192.73.3.83 DM TCP 3662 -> 80 A Aug 24 18:01:12 SG-1 ipfwlog[123]: 04/08/24 18:01:12 !I 02 61.149.95.79 -> 192.73.3.83 D frag @ 1472 Aug 24 18:01:12 SG-1 ipfwlog[123]: 04/08/24 18:01:12 !I 02 61.149.95.79 -> 192.73.3.83 DM TCP 3662 -> 80 A [...] Aug 24 18:01:40 SG-1 ipfwlog[123]: 04/08/24 18:01:40 !I 02 61.149.95.79 -> 192.73.3.83 DM TCP 3662 -> 80 A [...] Aug 24 18:02:32 SG-1 ipfwlog[123]: 04/08/24 18:02:32 !I 02 61.149.95.79 -> 192.73.3.83 D frag @ 1472 Aug 24 18:02:32 SG-1 ipfwlog[123]: 04/08/24 18:02:32 !I 02 61.149.95.79 -> 192.73.3.83 DM TCP 3662 -> 80 A -- BEGIN: vcard VERSION: 3.0 FN: Merton Campbell Crockett ORG: General Dynamics Advanced Information Systems; Intelligence and Exploitation Systems N: Crockett;Merton;Campbell EMAIL;TYPE=internet: [email protected] TEL;TYPE=work,voice,msg,pref: +1(805)497-5045 TEL;TYPE=work,fax: +1(805)497-5050 TEL;TYPE=cell,voice,msg: +1(805)377-6762 END: vcard _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions