IDS mailing list archives

Re: Single Stage Attacks?


From: Jamie Riden <jamie.riden () gmail com>
Date: Tue, 19 May 2009 17:33:54 +0100

2009/5/17 snort user <snort.user () gmail com>:
Greetings All,

Typically, network based attacks have multiple stages.
(reconnaissance, infection, download rootkit, call home, further infection etc)

Some attacks may have a single stage (without reconnaissance) to
compromise a host.
However, even those attacks have a post-compromise stage, such as call home
or transfer/steal data or something else.
Otherwise, what's the motivation for compromising in the first place?

Can someone enlighten me if there are attacks that only have a single stage?
Examples or scenarios is much appreciated.

SQL Slammer.

(stage 2 - if there was one - was just stage 1, but outgoing instead
of incoming, so not really separate in my opinion)

cheers,
 Jamie
-- 
Jamie Riden / jamesr () europe com / jamie () honeynet org uk
http://www.ukhoneynet.org/members/jamie/



Current thread: