established connection and ids signatures
"lola marais" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
The following signature looks for an established connection, ./rules/web-misc.rules:alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"WEB-MISC .htaccess access"; flow:to_server,established; content:".htaccess"; nocase; classtype:attempted-recon; sid:1129; rev:5;) I am busy trying to follow this practical "http://www.dshield.org/pipermail/intrusions/2004-June/008049.php" but cannot see how the mtvpm at bigpond.com got the alert to trigger without actually modifying the signature here is the alert that was posted: [**] [1:1129:4] WEB-MISC .htaccess access [**] [Classification: Attempted Information Leak] [Priority: 2] 10/27-10:45:29.116507 210.186.62.136:1361 -> 32.245.166.119:80 This is the only packets in the file for ephemeral port 1361 # tcpdump -nnvr ./tcpdump_file/GIAC_raw/2002.9.27 port 1361 02:45:29.116507 210.186.62.136.1361 > 32.245.166.119.80: P [bad tcp cksum b198!] 805877:806366(489) ack 3123381758 win 8576 (DF) (ttl 108, id 29485, len 529, bad cksum abf2!) 02:45:29.906507 210.186.62.136.1361 > 32.245.166.119.80: . [bad tcp cksum b198!] 489:1025(536) ack 793 win 8576 (DF) (ttl 108, id 33581, len 576, bad cksum 9bc3!) Is there some special switch that one needs to enable in order to stop snort from looking for established connections when one is reading back the binary files from /log/raw or have I missed something. _________________________________________________________________ Post your best pics online - only on MSN Groups! http://groups.msn.com/people.msnw?pgmarket=en-za _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions