RE: Triggering IDS



Hi Adam,

A DNS version query is what we use to trigger NIDS sensors.
It does not matter whether the destination response yes or no since its
UDP and the trigger is the query. This can be performed to any host no
matter if the host has UDP 53 in listening state or not.
If you have allot of NIDS sensors then port scanning might be noisy.
Also this might not work against a firewalled host.
The same counts for the DNS query.
Another option and the most preferred one is writing your own signature.
I prefer UDP or another stateless protocol to avoid real session
creation.
Am not 100% certain but I do not think there is a real industry standard
packet for this.

Gr,
David

-----Oorspronkelijk bericht-----
Van: AdamT [mailto:adwulf@xxxxxxxxx]
Verzonden: woensdag 15 maart 2006 16:09
Aan: pen-test@xxxxxxxxxxxxxxxxx
Onderwerp: Triggering IDS

Dear all,

Y'know how there's the EICAR anti virus test file, which lets you see
if your anti-virus is working, well, I was wondering if there was
something similar to let you see what happens when your IDS triggers?

Should I just send a lot of NOPs in a TCP session, or make obvious
port scans, or is there some kind of 'industry standard' way to
deliberately trigger IDS alarms?

--
AdamT
'Thank-you for not requesting read receipts'

------------------------------------------------------------------------
------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
As attacks through web applications continue to rise, you need to
proactively
protect your applications from hackers. Cenzic has the most
comprehensive
solutions to meet your application security penetration testing and
vulnerability management needs. You have an option to go with a managed
service (Cenzic ClickToSecure) or an enterprise software (Cenzic
Hailstorm).
Download FREE whitepaper on how a managed service can help you:
http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm
your
results from other product. Contact us at request@xxxxxxxxxx
------------------------------------------------------------------------
------



------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
As attacks through web applications continue to rise, you need to proactively
protect your applications from hackers. Cenzic has the most comprehensive
solutions to meet your application security penetration testing and
vulnerability management needs. You have an option to go with a managed
service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm).
Download FREE whitepaper on how a managed service can help you:
http://www.cenzic.com/forms/ec.php?pubid=10025
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@xxxxxxxxxx
------------------------------------------------------------------------------



Relevant Pages

  • Re: getting data in triggers
    ... transaction will hold everything in lock until your trigger is done. ... Looking at your vbscript, you are making a new sqlconnection and attempting ... suggest you create a sql job and schedule it to run these external calls at ... >>> I can execute the script using xp_CmdShell in the SQL Query Analyzer ...
    (microsoft.public.sqlserver.programming)
  • Re: Please help me optimise this stored procedure.
    ... But do you really need this query? ... I assume your query is run in a trigger. ... UPDATE Titles ... Also, I forgot that the counters are in another table, not ...
    (microsoft.public.sqlserver.programming)
  • Re: date question
    ... that being said we have to agree that not all techniques are for all ... I haven't experienced such horrible benchmarks using the DATEDIFF functions. ... whether or not the trigger does any work, it is still a trigger and there ... query you just have to make the change to the code). ...
    (microsoft.public.sqlserver.programming)
  • RE: I want the user to decide if duplicates are ok
    ... Sorry QBF = Query By Form ... The basics are that you filter a query by the contents of controls on a ... The event to trigger the action is up to you. ...
    (microsoft.public.access.gettingstarted)
  • Re: When will the new BCE driver in HEAD be incorporated into RELENG_6?
    ... We couldn't trigger this bug using UDP NFS mounts. ... Neither could we trigger it with multiple simultaneous TCP connections. ...
    (freebsd-stable)