R: host-based ids evaluation

From: Gianpiero Porchia (gianpiero.porchia@atsweb.it)
Date: 08/16/02


From: "Gianpiero Porchia" <gianpiero.porchia@atsweb.it>
To: "Detmar Liesen" <counter.spy@gmx.de>
Date: Fri, 16 Aug 2002 19:22:53 +0200

Detmar wrote:
>Shouldn't a decent HIDS detect a shell with no password getting bound to a
>TCP port???

I'm using an NFR-NID, and I've wrote a custom N-code script that can detect
connections, over strange ports. I've said that in a my precedent post, we
can do that easily writing a hosts list:

192.168.0.3, 80,25,22
192.168.0.4, 21,22
...

and for every connection not in this list, my NIDS is raising an alert.
Obiuvsly, the script can detect shells on that connection (example looking
for a prompt, or for a shell command - dir or ls).

Bye

- gianpiero

Ing. Gianpiero Porchia
Security Engineer
ATS - Advanced Telecom Systems
Designing, Testing, Managing Network Quality

Via Salgari, 17 - 41100 Modena - ITALY
Tel +39 059 821332
Fax +39 059 821492
E-mail: gianpiero.porchia@atsweb.it
Web site: http://www.atsweb.it



Relevant Pages

  • Re: VNC over SSH and SOCKS
    ... seems to fail all the time, in the same way, no matter what port numbers x ... I was of course getting a shell on B, ... the VNC connection will never succeed. ...
    (comp.security.ssh)
  • Re: port 8080
    ... >> I don't understand your question but if you want to change the port ... > C'è un comando, nella shell, per controllare la porta 8080 ... If the port is listening, you should see a line that shows connected. ... Connection closed. ...
    (comp.unix.shell)
  • Re: sample buffer overflow exploit problem
    ... You say that you can connect after the exploit, but then the connection gets ... >I'm very new to buffer overflow exploit technics and my boss wants me to ... >launches the shell in the remote machine. ... >However when I try to use port binding shell code, ...
    (Vuln-Dev)
  • ANNOUNCE: DJGPP port of GNU Make 3.81 uploaded
    ... This is a port of GNU Make 3.81 to MSDOS/DJGPP. ... The are two kind of required djgpp specific changes to the sources: ... of the SHELL Makefile variable is no longer exported automatically. ...
    (comp.os.msdos.djgpp)
  • RE: Port 4662 exploitation
    ... shell, but to get a tcp header and know what services might be running ... arbitrary port is clearly a most valuable find. ... Stay Ahead of the Hacker Curve! ... Security Trends Report from Cenzic ...
    (Pen-Test)