established connection and ids signatures

"lola marais" <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
The following signature looks for an established connection,

./rules/web-misc.rules:alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 
$HTTP_PORTS (msg:"WEB-MISC .htaccess access"; flow:to_server,established; 
content:".htaccess"; nocase; classtype:attempted-recon; sid:1129; rev:5;)

I am busy trying to follow this practical
"http://www.dshield.org/pipermail/intrusions/2004-June/008049.php"

but cannot see how the mtvpm at bigpond.com
got the alert to trigger without actually modifying the signature


here is the alert that was posted:

[**] [1:1129:4] WEB-MISC .htaccess access [**]
[Classification: Attempted Information Leak]
[Priority: 2]
10/27-10:45:29.116507 210.186.62.136:1361 ->
32.245.166.119:80


This is the only packets in the file for ephemeral port 1361

# tcpdump -nnvr ./tcpdump_file/GIAC_raw/2002.9.27 port 1361
02:45:29.116507 210.186.62.136.1361 > 32.245.166.119.80: P [bad tcp cksum 
b198!] 805877:806366(489) ack 3123381758 win 8576 (DF) (ttl 108, id 29485, 
len 529, bad cksum abf2!)
02:45:29.906507 210.186.62.136.1361 > 32.245.166.119.80: . [bad tcp cksum 
b198!] 489:1025(536) ack 793 win 8576 (DF) (ttl 108, id 33581, len 576, bad 
cksum 9bc3!)

Is there some special switch that one needs to enable in order to stop snort 
from looking for established connections when one is reading back the binary 
files from /log/raw or have I missed something.

_________________________________________________________________
Post your best pics online - only on MSN Groups! 
http://groups.msn.com/people.msnw?pgmarket=en-za

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.