Re: established connection and ids signatures

Andrew Rucker Jones <[email protected]>
Newsgroups gmane.comp.security.intrusions
Organization Private Individual
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

This used to be accomplished with the -z switch. You might want to take
a look at deactivating the stream4 preprocessor in snort.conf, too. I'm
not really sure of the answer to Your question, though. Snort has become
a lot more stateful in the last few releases.

		-&


lola marais wrote:
| The following signature looks for an established connection,
|
| ./rules/web-misc.rules:alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS
| $HTTP_PORTS (msg:"WEB-MISC .htaccess access";
| flow:to_server,established; content:".htaccess"; nocase;
| classtype:attempted-recon; sid:1129; rev:5;)
|
| I am busy trying to follow this practical
| "http://www.dshield.org/pipermail/intrusions/2004-June/008049.php"
|
| but cannot see how the mtvpm at bigpond.com
| got the alert to trigger without actually modifying the signature
|
|
| here is the alert that was posted:
|
| [**] [1:1129:4] WEB-MISC .htaccess access [**]
| [Classification: Attempted Information Leak]
| [Priority: 2]
| 10/27-10:45:29.116507 210.186.62.136:1361 ->
| 32.245.166.119:80
|
|
| This is the only packets in the file for ephemeral port 1361
|
| # tcpdump -nnvr ./tcpdump_file/GIAC_raw/2002.9.27 port 1361
| 02:45:29.116507 210.186.62.136.1361 > 32.245.166.119.80: P [bad tcp
| cksum b198!] 805877:806366(489) ack 3123381758 win 8576 (DF) (ttl 108,
| id 29485, len 529, bad cksum abf2!)
| 02:45:29.906507 210.186.62.136.1361 > 32.245.166.119.80: . [bad tcp
| cksum b198!] 489:1025(536) ack 793 win 8576 (DF) (ttl 108, id 33581, len
| 576, bad cksum 9bc3!)
|
| Is there some special switch that one needs to enable in order to stop
| snort from looking for established connections when one is reading back
| the binary files from /log/raw or have I missed something.
|
| _________________________________________________________________
| Post your best pics online - only on MSN Groups!
| http://groups.msn.com/people.msnw?pgmarket=en-za
|
| _______________________________________________
| Intrusions mailing list
| [email protected]
| http://www.dshield.org/mailman/listinfo/intrusions
|

- --
GPG key / Schlüssel -- http://simultan.dyndns.org/~arjones/gpgkey.txt
Encrypt everything. / Alles verschlüsseln.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFBL5PxoI7tqy5bNGMRAq22AKDUw7OgE7H9vKI7v9F0yljDChkQ8wCeIkS1
ai/qBTv0+2AzEbEEe90F1fQ=
=O0qd
-----END PGP SIGNATURE-----
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.