Re: Cisco IOS Shellcode - McAfee IPS Protection

From: Martin Roesch (roesch_at_sourcefire.com)
Date: 08/09/05

  • Next message: Krzysztof Cabaj: "Re: TCP Sack processing"
    Date: Mon, 8 Aug 2005 19:07:10 -0400
    To: Ron Gula <rgula@tenablesecurity.com>
    
    

    On Aug 8, 2005, at 1:22 PM, Ron Gula wrote:

    > I think most of them are relying on existing technology. For example,
    > a quick check of snort.org and bleedingsnort.org didn't have any new
    > cisco-specific rules, yet there are signatures to detect various Cisco
    > attacks already.

    We stopped looking for shellcode with Snort years ago, we focus our
    rule development efforts on detection of people exercising the
    protocols improperly instead of looking for specific signatures
    whenever possible. Our existing Cisco rules most likely need to have
    the messages updated from "DoS" to "exploit", that's about it.
    Playing the shellcode detection game is a dead end unless that's all
    you've got.

          -Marty

    -- 
    Martin Roesch - Founder/CTO, Sourcefire Inc. - +1-410-290-1616
    Sourcefire - Network Defense for the Real World - http:// 
    www.sourcefire.com
    Snort: Open Source Intrusion Detection and Prevention - http:// 
    www.snort.org
    ------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it 
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
    to learn more.
    ------------------------------------------------------------------------
    

  • Next message: Krzysztof Cabaj: "Re: TCP Sack processing"

    Relevant Pages

    • RE: Detecting trojans on random ports with encrypted traffic...
      ... Isn't this similar to what SPADE does in snort? ... >>> Intrusion Detection does not have to rely on signatures ... >>> detect connections from and to ports that you normally ... >>> counting any connections that are normal like virus scanner ...
      (Focus-IDS)
    • Re: Obfuscated shellcode
      ... quite correct of course that this type of thing should be included in a pentest. ... Intrusion Detection Specialist ... a while since I've ran a snort NIDS. ... NOP Equivalent opcodes for shellcodes - Canonical List ...
      (Pen-Test)
    • [Snort-users] Snort 2.0 rc1 available (fwd)
      ... This came across Snort-users, many of you probably saw it, but for anyone ... The Snort 2.0 release candidate 1 is available for your testing. ... Tons of bug fixes ... New detection keywords & ...
      (Focus-IDS)
    • Re: Snort exploits
      ... He has given the IDS vendors several months heads up that this stuff is in the ... Odds are now that this info has gone out snort cvs will have fixes for this ... The TCP evasions are fairly easily detectable as overlaps should not normally occur. ... Similarly the IP fragmentation detection just needs slightly more rigorous ...
      (Bugtraq)
    • REVIEW: "Intrusion Detection with Snort", Jack Koziol
      ... %I Macmillan Computer Publishing ... %T "Intrusion Detection with Snort" ... The background overview of Snort, ...
      (alt.computer.security)