Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: IDS detection approaches |
|---|---|
| Date: | Fri, 12 Oct 2007 14:05:28 -0300 |
It is trivial to filter out post fact and is not normally occurring, I consider the alert successful at detecting nefarious activity. Simple, practical, effective.
I do sorry you have this idea, because it is dangerous and you sub estimating your "enemy". I sent just one example and the point is not the example itself, the point is the way the pattern matching IDS/IPS approaches the signature design. The pattern matching, in their concept, limits you to check a pattern. That is the point, because if you miss any vulnerable condition when detect / protect then you will miss the accuracy of the detection. This is well known by years.
We are talking right past each other here. So what if it is a null payload, if your goal is resource exhaustion then use a real payload. You have achieved absolutely nothing using the null payload, except perhaps to make it easily filtered out of your result set.
No, I disagree, we are not talking right past each other here, we are talking about different things here and I suppose I'm not be clear enough or I really need to get back my English classes. :D The resource exhaustion does not target the SQL, it targets the IPS. If you launch this attack against the SQL, it will send you back a valid answer for your request just if you are really using a SQL in the test environment, because this kind of attack does not depend on SQL and you can run packets targeting any IP address protected by the IPS and it still reports the false positive. That said I presume you now understand my point, otherwise I do refuse to keep this thread alive. ------------------------------------------------------------------------ Test Your IDS Is your IDS deployed correctly? Find out quickly and easily by testing it with real-world attacks from CORE IMPACT. Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw to learn more. ------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Sessions Resource Exhaustion, Andrew Hay |
|---|---|
| Next by Date: | Re: Sessions Resource Exhaustion, H D Moore |
| Previous by Thread: | Re: IDS detection approaches, Sec urity |
| Next by Thread: | Re: IDS detection approaches, Jason |
| Indexes: | [Date] [Thread] [Top] [All Lists] |