Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-sigs] help with LSASS rule |
|---|---|
| Date: | Mon, 13 Sep 2004 13:04:43 -0400 |
On 0, "Esler, Joel - Contractor" <joel.esler@rcert-s.army.mil> allegedly wrote:
I would consult the docs, this rule would be alot to explain..
The doc will tell you what the underlying vulnerability detection is aimed at.
-----Original Message----- From: snort-sigs-admin@lists.sourceforge.net [mailto:snort-sigs-admin@lists.sourceforge.net] On Behalf Of Wohlberg, Jonathan Sent: Monday, September 13, 2004 8:26 AM To: snort-sigs@lists.sourceforge.net Subject: [Snort-sigs] help with LSASS rule I am trying to figure out how this rule works. Any help breaking it down would be appreciated.
This is not a very simple rule to explain, the notable piece though is: flowbits:isset,netbios.lsass.bind.attempt; Which means that for this rule to generate an event, a previous rule that sets the value netbios.lsass.bind.attempt must also meet certain conditions. Essentially, the previous rule makes sure that a bind attempt has been made before any potentially malicious content gets sent to generate an event from this particular rule. So, to understand what is happening in total, you must also look for the rule(s) that do this: flowbits:set,netbios.lsass.bind.attempt;
Jon
+-------------------------------------------------------------------------+
Nigel Houghton Research Engineer Sourcefire Inc.
Vulnerability Research Team
"Dude, dolphins are intelligent and friendly!" - Wendy
"Intelligent and friendly on rye bread, with some mayonaise." - Cartman
+-------------------------------------------------------------------------+
-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 13. Go here: http://sf.net/ppc_contest.php
_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: [Snort-sigs] help with LSASS rule, Esler, Joel - Contractor |
|---|---|
| Next by Date: | [Snort-sigs] smtp pass rules, David Lowless |
| Previous by Thread: | RE: [Snort-sigs] help with LSASS rule, Esler, Joel - Contractor |
| Next by Thread: | [Snort-sigs] smtp pass rules, David Lowless |
| Indexes: | [Date] [Thread] [Top] [All Lists] |