Evading IDS?

From: Mark G. Spencer (mspencer_at_evidentdata.com)
Date: 03/18/04

  • Next message: Dante Mercurio: "Bank Audit Best practices"
    To: <pen-test@securityfocus.com>
    Date: Thu, 18 Mar 2004 10:55:52 -0800
    
    

    I've come across what I assume is an IDS during some network reconnaissance.
    I am able to run nmap (connect scan, default ports) against the entire
    target class C in question without any problems, but when I run Nikto
    against any of the webservers, Nikto output dies just after the trace/track
    method information and I am then unable to access anything on the target
    class C for a set period of time - at least fifteen minutes.

    If I move to a different netblock, I can access the target class C again ..
    well, until I run Nikto. ;)

    It looks like all the routing and VPN gear on the target class C is Cisco
    based, so I'll make an assumption for now that the IDS is also Cisco.

    Any advice on how to evade the IDS? I know Nessus and Nikto offer a variety
    of IDS evasion techniques, but am I correct in assuming that a vendor such
    as Cisco (or any large vendor) has taken well-known evasion techniques into
    account? I will try different combinations of evasion techniques today and
    hopefully won't run out of open class C IP addresses on my network as I
    continue getting 15min+ blacklisted.

    Thanks for the advice,

    Mark

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------


  • Next message: Dante Mercurio: "Bank Audit Best practices"

    Relevant Pages

    • RE: Evading IDS?
      ... As far as already available tools go, use fragroute with the ... > target class C in question without any problems, but when I run Nikto ... so I'll make an assumption for now that the IDS is also Cisco. ...
      (Pen-Test)
    • Re: Evading IDS?
      ... One other thing to consider, if it is a Cisco IDS, is that ... one ofter another), then after about 100 IP's, the IDS will be unable to ... You will be able to run your Nikto from a new IP address so long as you ... >>target class C in question without any problems, ...
      (Pen-Test)
    • Re: Evading IDS?
      ... perceived attacks. ... it's a commercial system doens't automatically make it a good IDS. ... > target class C in question without any problems, but when I run Nikto ... > If I move to a different netblock, I can access the target class C again .. ...
      (Pen-Test)
    • Re: Testing IDS with tcpreplay
      ... different things than with Metasploit or similar tools. ... I would argue that you are testing the IDS to figure out if it will be ... instance of the target then replay makes sense. ... Which is why you should capture the same exploit being used ...
      (Focus-IDS)
    • RE: IDS Informer
      ... quickly answer you question we can target any ip address. ... on the same segment as the IDS without harming that machine. ... I was looking at the IDS Informer and noticed ... While the attack is happening we have a network ...
      (Focus-IDS)

  • Quantcast