Intrusion Detection Systems mailing list archives
Re: Mod FWD
From: Keiji Takeda <keiji () sfc keio ac jp>
Date: Fri, 08 Sep 2000 13:56:01 +0900
Archive: http://msgs.securepoint.com/ids FAQ: http://www.ticm.com/kb/faq/idsfaq.html IDS: http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html HELP: Having problems... email questions to ids-owner () uow edu au NOTE: Remove this section from reply msgs otherwise the msg will bounce. SPAM: DO NOT send unsolicted mail to this list. UNSUBSCRIBE: email "unsubscribe ids" to majordomo () uow edu au ----------------------------------------------------------------------------- Hello, Thanks for your info. When I did the testing. I used both of RealSecure 3.2 and 5.0 3.2 genarated the alarm you mentioned that simply warns receving fragmented packet. However 5.0 launched an alarm that came from the result of packet reconstruction. When I tested fragmented /cgi-bin/phf attack these two versions generated different alarms. One is about fragmentation itself(3.2) the other is about reconstructed /cgi-bin/phf(5.0). Isn't this 5.0 enough as an networkbased IDS? mark.teicher () networkice com san wrote on Thu, 07 Sep 2000 10:20:38 -0700
I would recommend trying this attack again and seeing what ISS RealSecure actually records to both the Display and the database. It is not exactly what is stated below. /mark /begin excerpt from their manual. IP Fragmentation RealSecure has detected a fragmented IP packet. Type Unauthorized Access Attempt Console Name IPFrag Technical Description
Keiji Takeda ( http://www.sfc.keio.ac.jp/~keiji/ )
Current thread:
- Re: Mod FWD Marcus J. Ranum (Sep 06)
- Re: Mod FWD Jackie Chan (Sep 06)
- Re: Mod FWD Marcus J. Ranum (Sep 06)
- Re: Mod FWD Jackie Chan (Sep 06)
- Re: Mod FWD Keiji Takeda (Sep 07)
- Re: Mod FWD mark . teicher (Sep 07)
- Re: Mod FWD Dragos Ruiu (Sep 08)
- Re: Mod FWD mark . teicher (Sep 08)
- Re: Mod FWD Keiji Takeda (Sep 08)
- Re: Mod FWD Richard Jones (Sep 08)
- Re: Mod FWD Jackie Chan (Sep 08)
- Re: Mod FWD Marcus J. Ranum (Sep 08)
- Re: Mod FWD Marcus J. Ranum (Sep 06)
- Re: Mod FWD Jackie Chan (Sep 06)
- Re: Mod FWD Marcus J. Ranum (Sep 06)
- <Possible follow-ups>
- Re: Mod FWD Jackie Chan (Sep 07)
- Re: Mod FWD Richard Jones (Sep 07)
