IDS mailing list archives
Re: Single Stage Attacks?
From: Jamie Riden <jamie.riden () gmail com>
Date: Tue, 19 May 2009 17:33:54 +0100
2009/5/17 snort user <snort.user () gmail com>:
Greetings All, Typically, network based attacks have multiple stages. (reconnaissance, infection, download rootkit, call home, further infection etc) Some attacks may have a single stage (without reconnaissance) to compromise a host. However, even those attacks have a post-compromise stage, such as call home or transfer/steal data or something else. Otherwise, what's the motivation for compromising in the first place? Can someone enlighten me if there are attacks that only have a single stage? Examples or scenarios is much appreciated.
SQL Slammer. (stage 2 - if there was one - was just stage 1, but outgoing instead of incoming, so not really separate in my opinion) cheers, Jamie -- Jamie Riden / jamesr () europe com / jamie () honeynet org uk http://www.ukhoneynet.org/members/jamie/
Current thread:
- Single Stage Attacks? snort user (May 19)
- Re: Single Stage Attacks? Jamie Riden (May 19)
- Re: Single Stage Attacks? dreamwvr (May 20)
- Re: Single Stage Attacks? Stuart Staniford (May 20)
