Re: Cisco IOS Shellcode - McAfee IPS Protection

From: Ed Gibbs (ed_at_digitalconclave.com)
Date: 08/08/05

  • Next message: Ron Gula: "Re: Cisco IOS Shellcode - McAfee IPS Protection"
    To: "Joel Esler" <eslerj@gmail.com>, "planz 235" <planz2009@gmail.com>
    Date: Mon, 8 Aug 2005 10:12:38 -0700
    
    

    Having used IntruShield for several years, I called them on this because I
    thought the same thing. As it turns out, they protect detect the shell
    code, and if your policies setup can actually block it. Their detection of
    shell-code execution is pretty strong from our research.

    Ed

    ----- Original Message -----
    From: "Joel Esler" <eslerj@gmail.com>
    To: "planz 235" <planz2009@gmail.com>
    Cc: <focus-ids@securityfocus.com>
    Sent: Thursday, August 04, 2005 3:25 PM
    Subject: Re: Cisco IOS Shellcode - McAfee IPS Protection

    > How can they have "0-day" if ISS (makers of RealSecure and proventia IDS)
    > announced the vuln? Wouldn't that lead us to believe that ISS had it
    > first?
    >
    > Beyond that, it's been a week, I am sure that all the major IDS venders
    > have it.
    >
    > Joel
    >
    > (Yes, I work for an IDS company, and yes, we have a way to detect it)
    >
    >
    > On Aug 4, 2005, at 3:53 AM, planz 235 wrote:
    >
    >> Hi,
    >>
    >> McAfee claims to have "Zero-day" protection against the recent
    >> vulnerability disclosed against Cisco particularly on Shellcodes.
    >> Their press release says, McAfee IntruShield's existing infrastructure
    >> protection proactively covers new exploit techniques against Cisco
    >> IOS, such as those demonstrated at last week's Black Hat conference.
    >> [http://www.mcafeesecurity.com/us/about/press/corporate/
    >> 2005/20050803_181545.htm
    >> ]
    >>
    >> Someone using Intrushield can validate this statement..?
    >>
    >> Regards,
    >> Planz
    >>
    >
    >
    > ------------------------------------------------------------------------
    > Test Your IDS
    >
    > Is your IDS deployed correctly?
    > Find out quickly and easily by testing it with real-world attacks from
    > CORE IMPACT.
    > Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    > to learn more.
    > ------------------------------------------------------------------------
    >
    >
    >

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------


  • Next message: Ron Gula: "Re: Cisco IOS Shellcode - McAfee IPS Protection"

    Relevant Pages

    • Re: Recommending an IDS system
      ... re: Cisco IDS, I have a few things to say about Cisco's product: junk. ... into ONE inky-dinky "black box" that was maintained by a "security ... Like I said before, ISS ...
      (Security-Basics)
    • RE: Recommending an IDS system
      ... That feature is not an "Auto-Update" in Cisco. ... As for writing your own signatures, ... Subject: Recommending an IDS system ...
      (Security-Basics)
    • Re: Recommending an IDS system
      ... I'm running a smaller setup than your old employer attempted to run. ... re: Cisco IDS, I have a few things to say about Cisco's product: junk. ... but the management of the signatures and ...
      (Security-Basics)
    • RE: CISCOs new IPS
      ... There is no way we would consider using their IPS units....their IDS have enough problems. ... Christoph, ... I can tell you from real world experience that Cisco has not been the best ...
      (Focus-IDS)
    • RE: Recommending an IDS system
      ... Same here - haven't used the ISS, but I have no problem with auto updates, and Cisco is releasing signatures very quickly. ... Subject: Recommending an IDS system ... I never worked with ISS IDS appliance before so I can't really comment on ...
      (Security-Basics)