Re: TCP Dump Filters

From: Mark Coleman (mcoleman@uniontown.com)
Date: 12/20/01


From: "Mark Coleman" <mcoleman@uniontown.com>
To: <JCFontelera@SolanoCounty.com>, <focus-ids@securityfocus.com>
Date: Thu, 20 Dec 2001 11:28:00 -0800

I believe that TCPDump just grabs packet headers, so it can't watch for
anything in the payload, thus making it a poor choice for IDS beyond layer
4.

I have seen it used to detect connections to boxen that should never happen
for example, but NOT to see that an email attachment is called README.EXE.

I may be wrong on this one, but I don't think I am. You need something like
Snort for any good payload monitoring.

-Mark

----- Original Message -----
From: <JCFontelera@SolanoCounty.com>
To: <focus-ids@securityfocus.com>
Sent: Wednesday, December 19, 2001 4:25 PM
Subject: TCP Dump Filters

> Does anyone know a good web site that explains how
> to create TCPDUMP or windump filters to detect all sorts of
> attack signatures ?
>
> Thanks,
> Jaime



Relevant Pages

  • RE: TCP Dump Filters
    ... examination of payload, but I wouldn't suggest doing so. ... TCPdump, by default, captures the frame header for Ethernet) and as Crist ... you have to know exactly where in the packet the text falls. ... have multiple filters to capture longer strings. ...
    (Focus-IDS)
  • Re: TCP Dump Filters
    ... but can you FILTER on the contents of the payload? ... filter on all kinds of packet characteristics like port, ... would be a major drawback in the use of TCPdump as an IDS engine. ...
    (Focus-IDS)
  • RE: TCP Dump Filters
    ... TCPDump is capable of grabbing full frames. ... Regards, ... Subject: TCP Dump Filters ... Snort for any good payload monitoring. ...
    (Focus-IDS)
  • Re: [SLE] tcpdump ?
    ... Maybe there is another sniffer that manages this task better? ... Well..I haven't seen such a tool that would only show you the payload. ... see plain text, therefore the only payload you will be able to see is plain ... functions like that of tcpdump. ...
    (SuSE)
  • Re: [Full-Disclosure] Re: Automated SSH login attempts?
    ... > to poke another machine under your control, and use tcpdump or ethereal ... capture of the entire payload. ...
    (Full-Disclosure)