Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Re: Re: Re: HTTP traffic |
|---|---|
| Date: | 9 Aug 2007 04:07:19 -0000 |
well what abhicc might have meant is to, have a proper protocol parser/rule, which will decode the data on the wire correctly and specifically to a protocol. And using this decide whether a vulnerability/exploit exists. And not directly checking for Vulnerability in the data on the wire stream. All data has to be seen in context with the protocol its coming for. Same sequence of bytes have diff meanings for different protocols/versions. Regarding Exploit vs Vuln Argument. Well going with the vulnerability is always a better option. Being exploit specific means, that whenever someone smart out there comes up with a sequence of code different enough, the IDS/IPS gets bypassed. And devs have to scram to cover this new one. Having exploit specific signatures also means having more signatures on the box, whereas all these exploits might be using a common vector, and if the signature/rule was vulnerability specific, only 1 signature could have stopped all the exploits. Just depends how much work the DEV/QA team wanna put in :-) And i agree with Hirosh, better to do take time and do it once and do it right, than modify it everytime a new version of the exploit comes out. ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw to learn more. ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Re: Re: Re: HTTP traffic, hirosh |
|---|---|
| Next by Date: | Re: Re: Re: Re: HTTP traffic, abhicc285 |
| Previous by Thread: | Re: Re: Re: Re: HTTP traffic, hirosh |
| Next by Thread: | Re: Re: Re: Re: HTTP traffic, abhicc285 |
| Indexes: | [Date] [Thread] [Top] [All Lists] |