Re: established connection and ids signatures
Andrew Rucker Jones <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Organization | Private Individual |
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This used to be accomplished with the -z switch. You might want to take a look at deactivating the stream4 preprocessor in snort.conf, too. I'm not really sure of the answer to Your question, though. Snort has become a lot more stateful in the last few releases. -& lola marais wrote: | The following signature looks for an established connection, | | ./rules/web-misc.rules:alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS | $HTTP_PORTS (msg:"WEB-MISC .htaccess access"; | flow:to_server,established; content:".htaccess"; nocase; | classtype:attempted-recon; sid:1129; rev:5;) | | I am busy trying to follow this practical | "http://www.dshield.org/pipermail/intrusions/2004-June/008049.php" | | but cannot see how the mtvpm at bigpond.com | got the alert to trigger without actually modifying the signature | | | here is the alert that was posted: | | [**] [1:1129:4] WEB-MISC .htaccess access [**] | [Classification: Attempted Information Leak] | [Priority: 2] | 10/27-10:45:29.116507 210.186.62.136:1361 -> | 32.245.166.119:80 | | | This is the only packets in the file for ephemeral port 1361 | | # tcpdump -nnvr ./tcpdump_file/GIAC_raw/2002.9.27 port 1361 | 02:45:29.116507 210.186.62.136.1361 > 32.245.166.119.80: P [bad tcp | cksum b198!] 805877:806366(489) ack 3123381758 win 8576 (DF) (ttl 108, | id 29485, len 529, bad cksum abf2!) | 02:45:29.906507 210.186.62.136.1361 > 32.245.166.119.80: . [bad tcp | cksum b198!] 489:1025(536) ack 793 win 8576 (DF) (ttl 108, id 33581, len | 576, bad cksum 9bc3!) | | Is there some special switch that one needs to enable in order to stop | snort from looking for established connections when one is reading back | the binary files from /log/raw or have I missed something. | | _________________________________________________________________ | Post your best pics online - only on MSN Groups! | http://groups.msn.com/people.msnw?pgmarket=en-za | | _______________________________________________ | Intrusions mailing list | [email protected] | http://www.dshield.org/mailman/listinfo/intrusions | - -- GPG key / Schlüssel -- http://simultan.dyndns.org/~arjones/gpgkey.txt Encrypt everything. / Alles verschlüsseln. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFBL5PxoI7tqy5bNGMRAq22AKDUw7OgE7H9vKI7v9F0yljDChkQ8wCeIkS1 ai/qBTv0+2AzEbEEe90F1fQ= =O0qd -----END PGP SIGNATURE----- _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions