[TOOL] Cctde - Covert Channel and Tunneling Over the HTTP Protocol Detection
From: SecuriTeam (support_at_securiteam.com)
Date: 01/25/05
- Previous message: SecuriTeam: "[EXPL] Microsoft Internet Explorer .ANI Files Handling Exploit (MS05-002)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 25 Jan 2005 18:55:53 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Cctde - Covert Channel and Tunneling Over the HTTP Protocol Detection
------------------------------------------------------------------------
SUMMARY
DETAILS
Cctde is a first implementation of the Gray-World.net
<http://gray-world.net/projects/papers/html/cctde.html> Covert Channel and
Tunneling over the HTTP protocol Detection : GW implementation theoretical
design' paper.
The main goal of this project is to provide a way to register and disclose
informations leading to the detection of unauthorized tunnels and covert
channels embedded into the HTTP protocol but the concepts could also be
applied to the detection of arbitrary data flows inside other high level
protocols.
Located between a mandatory HTTP proxy server and the HTTP clients (or
before the NACS if no proxy exists), cctde is trying to detect if someone
on the internal located network is using a CC|T (Covert Channel OR
Tunneling) tool to bypass the NACS.
Located in front of corporate servers in DMZ, cctde is trying to detect if
someone located on the Internet is using server side tools such as
<http://gray-world.net/pr_wsh.shtml> WebShell or
<http://gray-world.net/pr_firepass.shtml> Firepass to run across the NACS
boundaries.
Cctde is currently designed as an analysis back-end for the
<http://www.snort.org/> Snort NIDS tool. Snort acts as a network sensor -
recording data streams or not in tcpdump format binary files - and
communicates with the cctde part using an Unix socket. Cctde then reads
Snort alerts and pcap packets from the Unix socket and store them into
memory. It is then possible to correlate recorded data in order to detect
specific network activities.
Download Information:
The tool can be obtained from:
<http://gray-world.net/projects/cctde/cctde-0.2.tar.gz>
http://gray-world.net/projects/cctde/cctde-0.2.tar.gz
ADDITIONAL INFORMATION
To keep updated with the tool visit the project's homepage at:
<http://gray-world.net/pr_cctde.shtml>
http://gray-world.net/pr_cctde.shtml
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[EXPL] Microsoft Internet Explorer .ANI Files Handling Exploit (MS05-002)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [UNIX] Snort Back Orifice Preprocessor Buffer Overflow Vulnerability
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Snort is a widely-deployed,
open-source network ... The vulnerable code will process any UDP packet that is not destined
to or ... The Snort Back Orifice preprocessor vulnerability can be triggered with a ...
(Securiteam) - [TOOL] SnortALog - Snort Analyzer Logs
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... SnortALog works with all
versions of SNORT and is ... the only script who can analyze snort's logs in all formats
(Syslog, ... (Securiteam) - [UNIX] Snort SACK TCP Option Handling DoS
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Snort is "an open source
network intrusion ... TCP Options => Violaci n de segmento ... que el campo TCP->th_sum
es 0, por lo tanto, el primer Router por ... (Securiteam) - [EXPL] Snort Back Orifice Preprocessor Buffer Overflow (Exploit #2)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Snort is a widely-deployed,
open-source network ... my $class = shift; ... sub Exploit { ... (Securiteam)