Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Signatures
[Top] [All Lists]

[Snort-sigs] L3Retriever false positives

Subject: [Snort-sigs] L3Retriever false positives
Date: Tue, 25 Jan 2005 12:05:50 +0100

I believe the L3Retriever information should be enhanced as shown below.

--------------------------------------------------------------------------
Rule: alert icmp $EXTERNAL_NET any -> $HOME_NET any (msg:"ICMP L3retriever Ping"; icode:0; itype:8; content:"ABCDEFGHIJKLMNOPQRSTUVWABCDEFGHI"; depth:32; reference:arachnids,311; classtype:attempted-recon; sid:466; rev:4;)
--
Sid: 1:466
--
False positives:
[add] Windows 2000 and Windows XP systems are also known to occasionally send similar ICMP echo requests with this content when communicating with their domain controller or other Windows systems when trying to mount remote shares or doing network discovery.
--------------------------------------------------------------------------


This has been brought up a number of times in the list:

Message-ID: <C038832A1A43884582CACB4B95217DC2011838EE@MIS_17>
Message-ID: <3D89EF6753768740AE4A1DD594736C0701A80E@email.olympus.spectra-inc.com>
Message-Id: <s0fbae32.096@hpsk12.net>
Message-ID: <20040716125316.34288.qmail@web90108.mail.scd.yahoo.com>



¿Any reason why it's not included yet? I understand that this is sometimes seen because HOME_NET and EXTERNAL_NET are not properly defined, but for IDS monitoring internal sensors for worm activities you really want to have EXTERNAL_NET = HOME_NET so you can detect attacks between internal users.


The funny thing is I noticed this while reviewing somebody's Kerio Firewall logs which includes this signatures as a "medium priority intrusion" (that's probably been fixed in Kerio, he was using an old version). Googling I've found people discussing this signature at
http://forums.speedguide.net/archive/index.php/t-160456.html
and
http://www.wilderssecurity.com/showthread.php?s=640949ba590225f0f8f60cad22bcfe8a&p=147781#post147781


:-)

Regards

Javier


------------------------------------------------------- This SF.Net email is sponsored by: IntelliVIEW -- Interactive Reporting Tool for open source databases. Create drag-&-drop reports. Save time by over 75%! Publish reports on the web. Export to DOC, XLS, RTF, etc. Download a FREE copy at http://www.intelliview.com/go/osdn_nl _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs

<Prev in Thread] Current Thread [Next in Thread>