Re: Moving forward ...
Craig Hughes <[email protected]> Thu, 26 Feb 2004 14:38:29 -0800
| Newsgroups | gmane.ietf.asrg.filtering |
|---|---|
| Message-ID | <[email protected]> |
I'm not talking about counter-attacks, I'm talking about jumping into the middle of the conversation. Example: MALBOT: HELO attacker.com VICTIM: 250 Hi there! Attack at will! MALBOT to network: MAIL FROM: <piuadcouaowecuiboiubowyieboysdbcoywbfoqyweefboqqywbcobsod [at this point SUPERIDS kicks in] MALBOT [now talking to IDS redirect]: [email protected]> SUPERIDS to VICTIM: MAIL FROM: <[email protected]> VICTIM: 250 Ok SUPERIDS to MALBOT: 250 Ok MALBOT: RCPT TO: <[email protected]> SUPERIDS to MALBOT: 250 Do your worst you miserable attacker SUPERIDS to VICTIM: RCPT TO: <[email protected]> VICTIM: 250 Ok MALBOT: DATA <some plausible-looking msg> SUPERIDS to MALBOT: 250 Ok [or tempfail, or whatever] SUPERIDS to VICTIM: DATA <original message munged/defanged as necessary> VICTIM: 250 Ok. Thanks for the the protection There's nothing malicious going back to MALBOT -- as far as MALBOT knows, it's still talking to the original SMTP server. And as far as VICTIM knows it's still talking to MALBOT. There's other places in the conversation there where SUPERIDS could kick in too. But it'd still be nice to have some kind of way for SUPERIDS to signal to VICTIM (or downstream filters/MUAs/users) that something had happened. C On Feb 26, 2004, at 2:24 PM, David Nicol wrote: > Craig Hughes wrote: > >> hijacking "bad" network connections to either shut them down, or do >> something else with them. > > > Reminscent of the suggested "attack handler" directives for web > servers: when your web > server gets probed with a known IIS worm, instead of just redirecting > them to an error page, > one replies with a command, designed to exploit the weakness known to > be exploited by the > worm that is known to issue the probe in question, which will shut > down the server that > is issuing the probe. > > The down side is, whereas the worm was living as a parasite that was > letting the host-machine > continue its operations, the proactive response of shooting infected > patients on sight is > not, as I recall, legal in California. > > I don't remember who sued whom to get who to stop, but someone got in > trouble for > shutting down vulnerable and machines , and this was roundly regarded > on slashdot as > a perfect example of judicial miscarriage. > > -- > [email protected]. > Include phrase "cat and buttered toast" to get through my filter > >