sidestep

From: Jill Tovey (jill.tovey_at_bigbluedoor.com)
Date: 04/25/03

  • Next message: Shwaine: "Snort test logs available?"
    To: focus-ids@securityfocus.com
    Date: 25 Apr 2003 08:06:29 +0100
    
    

    Hi All,

    I have a snort box and I am testing it using a tool called sidestep.

    For those that don't know, the tool works by allowing you to chose which
    type of attack you want, for example RPC, DNS, FTP etc and then run it
    with a switch such as -evade, which will perform the attack on the box
    and attempt to "evade" the IDS. The URL is
    http://www.robertgraham.com/tmp/sidestep.html

    Now I have run the tool with all of the possible attacks and it has
    worked fine, but it doesn't always manage to evade snort.

    So I am writing up the results of this for a project I am doing at Uni
    however, when it comes explaining how this tool tries to evade the IDS,
    I can't because, I don't know, and there seems to be no documentation to
    explain how it is working, and I can't look at the source code.

    So I wondered if anyone here knew how it worked, or had some info on how
    it worked.

    I have managed to find one article on sans detailing how it works for
    the RPC attack, which is very helpful,
    (http://www.sans.org/resources/idfaq/rpc_evas.php ) but nothing to
    explain what it does for the other attacks.

    Any info would be much appreciated.

    ------------------------------------------------------------------------------
    INTRUSION PREVENTION: READY FOR PRIME TIME?
     
    IntruShield now offers unprecedented Intrusion IntelligenceTM capabilities -
    including intrusion identification, relevancy, direction, impact and analysis - enabling a path to prevention.
     
    Download the latest white paper "Intrusion Prevention: Myths, Challenges, and Requirements" at: http://www.securityfocus.com/IntruVert-focus-ids


  • Next message: Shwaine: "Snort test logs available?"

    Relevant Pages

    • RE: True definition of Intrusion Prevention
      ... Here is the some of the attack patterns type signatures being classified ... None of the listed above, should be classified as Intrusion Prevention, ... implementing sound security measures at the network device levels (i.e. ...
      (Focus-IDS)
    • AW: General term for Gateway IDS, IDP, IPS ...
      ... I'd like to know the general term for Gateway IDS, IDP, IPS ... ... Symantec Symantec Gateway Security,TopLayer Attack Mitigator IPS, ... I know NetScreen call their products "Intrusion Detectsion ... "Intrusion Prevention Solutions." ...
      (Focus-IDS)
    • RE: Snort test logs available?
      ... Whether you use these or the ones from SANS you will want to run snort ... repositories of Snort logs which we could use to test our tools. ... IntruShield now offers unprecedented Intrusion ... > INTRUSION PREVENTION: READY FOR PRIME TIME? ...
      (Focus-IDS)
    • RE: ISS and Snort logs
      ... Integrating through their HIDS should take care of meta-data ... >> the Snort DB. ... > INTRUSION PREVENTION: READY FOR PRIME TIME? ... > IntruShield now offers unprecedented Intrusion IntelligenceTM ...
      (Focus-IDS)
    • RE: dragon and snort logs
      ... Send the snort alerts via syslog to a remote host. ... snort syslog into Dragon HIDS, ... INTRUSION PREVENTION: READY FOR PRIME TIME? ...
      (Focus-IDS)

  • Quantcast