Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [ISSForum] Unix/Linux Shell code execution signatures Proventia A 201 |
|---|---|
| Date: | Fri, 24 Jun 2005 16:43:40 +0200 |
Hi Juan, signatures that detect shellcode have not necessarily the word "shellcode" in their names. I would assume you activate all attack-signatures and see what events get triggered when you perform your tests. Greetings, --Detmar Juan Roa wrote:
Hi: We had made some testing in our labs, in order to determine if the signatures already present in siteprotector sensors( wee can only find 8) are able to detect code shell execution in unix/linux web servers enviroments. We try a lot of examples of code shell execution attemps , starting off very specific to very general shell code execution attemps, and we only can trigger the " HTTP_Unix_Passwords". The signatures that we enabled in the policies were: (HTTP_Shells_Bash) (HTTP_Shells_C) (HTTP_Shells_Ksh) (HTTP_Shells_Perl) (HTTP_Shells_Perl_Exe) (HTTP_Shells_Rksh) (HTTP_Shells_Sh) (HTTP_Shells_Tcsh) (HTTP_Unix_Passwords) We are very worried because we was unable to detect a lot of attemps of attacks of this kind. Any ideas would help. Thanks in advance
_______________________________________________ ISSForum mailing list ISSForum@iss.net TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum To contact the ISSForum Moderator, send email to mod-issforum@iss.net The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [ISSForum] Visio stencils, Doug . Janelle |
|---|---|
| Next by Date: | [ISSForum] Inline Appliance and Switch Configuration, Chris Norris/AMIG |
| Previous by Thread: | [ISSForum] Unix/Linux Shell code execution signatures Proventia A 201, Juan Roa |
| Next by Thread: | [ISSForum] Visio stencils, CAUSEY, David |
| Indexes: | [Date] [Thread] [Top] [All Lists] |