Re: RPC Evasion techniques

From: Nick Black (dank_at_qemfd.net)
Date: 10/28/05

  • Next message: Evil Adam Smith: "On the definition of false positive - was: Re: location of an IPS"
    Date: Thu, 27 Oct 2005 23:31:27 -0400
    To: tcp fin <inet_inaddr@yahoo.com>
    
    

    tcp fin rigorously showed:
    > Hi Guys ,
    > Any tips and tricks or good article on IDS/IPS evasion
    > ?
    > I have beautiful paper "Insertion, Evasion and Denial
    > of Service:
    > Eluding Network Intrusion detection".
    > I need some pointers on RPC based evasion techniques.

    David Maynor of the ISS X-Force has at the least presented on this
    topic; he reads this list last I checked, and could probably point you
    in the right direction.

    -- 
    nick black          "np:  the class of dashed hopes and idle dreams."
    ------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it 
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
    to learn more.
    ------------------------------------------------------------------------
    

  • Next message: Evil Adam Smith: "On the definition of false positive - was: Re: location of an IPS"