Intrusion Detection Systems mailing list archives
Re: Detecting exploits/shellcode
From: vision () whitehats com (Max Vision)
Date: Sat, 17 Jun 2000 08:40:56 -0700 (PDT)
Archive: http://msgs.securepoint.com/ids FAQ: http://www.ticm.com/kb/faq/idsfaq.html IDS: http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html UNSUBSCRIBE: email "unsubscribe ids" to majordomo () uow edu au On Fri, 16 Jun 2000, Max Vision wrote:
On Thu, 15 Jun 2000, Ron Gula wrote:[*] Connection modeling. In some cases, connections to email or web servers which last for several hours may be of concern.This is really good stuff! Doesn't necessarily relate to buffer overflows at all, but it's a good consideration. :) There are a few sessions that
Hi, I was wrong here to say this was unrelated. My posts are lagged by probably ten hours so there may already be some flames on their way, but I thought I'd follow up - yes this can have a *lot* to do with detecting buffer overflows. Specifically, many exploits consist of shellcode that, instead of executing a separate activity, spawn an interactive shell replacing the daemon process that was exploited. It didn't initially occur to me that a naive attacker might actually use this intereactive shell for any length of time. Max
Current thread:
- Detecting exploits/shellcode Jonas Eriksson (Jun 15)
- Re: Detecting exploits/shellcode diphen () agitation net (Jun 15)
- Re: Detecting exploits/shellcode Marco Vaz (Jun 15)
- FW: Snort 1.6 and nmap 2.54beta1 Mila, Brian D (Jun 15)
- <Possible follow-ups>
- Re: Detecting exploits/shellcode Marcus J. Ranum (Jun 15)
- Re: Detecting exploits/shellcode Ron Gula (Jun 15)
- Re: Detecting exploits/shellcode Max Vision (Jun 16)
- Re: Detecting exploits/shellcode Max Vision (Jun 17)
- Re: Detecting exploits/shellcode Ron Gula (Jun 15)
- Testing Message at 12:35 idsmlist owner (Jun 15)
- Testing Message at 15:45 idsmlist owner (Jun 16)
- Re: Detecting exploits/shellcode Robert Graham (Jun 15)
- Re: Detecting exploits/shellcode Mark.Teicher () predictive com (Jun 15)
- Re: Detecting exploits/shellcode John Bradberry (Jun 16)
- Re: Detecting exploits/shellcode turnere (Jun 16)
- Re: Detecting exploits/shellcode Max Vision (Jun 16)
