Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] For Instance: Hostile FTP Sigs |
|---|---|
| Date: | Mon, 31 Dec 2007 10:04:34 -0500 |
To exemplify our discussion, I have a new set of sigs that need some discussion likely. Best to send to emerging-sigs only, or snort-sigs? Who prefers what? We have a smaller readership on emerging-sigs partly because it's new, and partly because snort-sigs is definitely the mainstream place to discuss. But do folks want discussion of sigs not going into the mainstream rulesets on snort-sigs? I definitely want the new sigs and discussion to get in front of as many sec people as possible, peer review has saved us making many huge mistakes. :) But anyway, these are going live now. Please test! ---------------- Seeing malware use a stripped down ftp server, not too unusual. but these sigs will help catch the login and transfer. Committing these now: #by Matt Jonkman # Just stats codes, no welcome, etc. Very unique # something like: #220 #USER a #331 #PASS a #230 #TYPE I #200 #PORT 10,2,32,214,4,9 #200 #RETR msnnmaneger.exe #150 #226 #QUIT #221 alert tcp any 1024: -> $HOME_NET 1024: (msg:"BLEEDING-EDGE ATTACK_RESPONSE Off-Port FTP Without Banners - 220"; flow:established,to_server; dsize:6; content:"220 |0d 0a|"; offset:0; depth:6; flowbits:noalert; flowbits:set,ET.strippedftp220; sid:2007714; rev:1;) alert tcp $HOME_NET 1024: -> any 1024: (msg:"BLEEDING-EDGE ATTACK_RESPONSE Off-Port FTP Without Banners - user"; flowbits:isset,ET.strippedftp220; flow:established,from_server; dsize:>7; content:"USER "; depth:5; offset:0; content:" |0d 0a|"; distance:1; flowbits:noalert; flowbits:set,ET.strippedftpuser; sid:2007715; rev:1;) alert tcp any 1024: -> $HOME_NET 1024: (msg:"BLEEDING-EDGE ATTACK_RESPONSE Off-Port FTP Without Banners - 331"; flowbits:isset,ET.strippedftpuser; flow:established,to_server; dsize:6; content:"331 |0d 0a|"; offset:0; depth:6; flowbits:noalert; flowbits:set,ET.strippedftp331; sid:2007716; rev:1;) alert tcp $HOME_NET 1024: -> any 1024: (msg:"BLEEDING-EDGE ATTACK_RESPONSE Off-Port FTP Without Banners - pass"; flowbits:isset,ET.strippedftp331; flow:established,from_server; dsize:>7; content:"PASS "; depth:5; offset:0; content:" |0d 0a|"; distance:1; flowbits:set,ET.strippedftppass; sid:2007717; rev:1;) alert tcp any 1024: -> $HOME_NET 1024: (msg:"BLEEDING-EDGE ATTACK_RESPONSE Off-Port FTP Without Banners - 230 Successful Login"; flowbits:isset,ET.strippedftpuser; flow:established,to_server; dsize:6; content:"230 |0d 0a|"; offset:0; depth:6; flowbits:set,ET.strip pedftp230; sid:2007718; rev:1;) alert tcp $HOME_NET 1024: -> any 1024: (msg:"BLEEDING-EDGE ATTACK_RESPONSE Off-Port FTP Without Banners - type i"; flowbits:isset,ET.strippedftp230; flow:established,from_server; dsize:8; content:"TYPE I|0d 0a|"; depth:8; offset:0; flowbits:set,ET.strippedftptype; sid:2007719; rev:1;) alert tcp any 1024: -> $HOME_NET 1024: (msg:"BLEEDING-EDGE ATTACK_RESPONSE Off-Port FTP Without Banners - 200"; flowbits:isset,ET.strippedftptype; flow:established,to_server; dsize:6; content:"200 |0d 0a|"; offset:0; depth:6; flowbits:set,ET.strippedftp200; sid:2007720; rev:1;) alert tcp $HOME_NET 1024: -> any 1024: (msg:"BLEEDING-EDGE ATTACK_RESPONSE Off-Port FTP Without Banners - port set"; flowbits:isset,ET.strippedftp200; flow:established,from_server; dsize:>12; content:"PORT "; depth:5; offset:0; flowbits:set,ET.strippedftpport; sid:2007721; rev:1;) alert tcp any 1024: -> $HOME_NET 1024: (msg:"BLEEDING-EDGE ATTACK_RESPONSE Off-Port FTP Without Banners - 200"; flowbits:isset,ET.strippedftpport; flow:established,to_server; dsize:6; content:"200 |0d 0a|"; offset:0; depth:6; flowbits:set,ET.strippedftp200.2; sid:2007722; rev:1;) alert tcp $HOME_NET 1024: -> any 1024: (msg:"BLEEDING-EDGE ATTACK_RESPONSE Off-Port FTP Without Banners - retr"; flowbits:isset,ET.strippedftp200.2; flow:established,from_server; dsize:>7; content:"RETR "; depth:5; offset:0; sid:2007723; rev:1;) -- -------------------------------------------- Matthew Jonkman Emerging Threats US Phone 765-429-0398 US Fax 312-264-0205 AUS Fax 61-29-4750-026 http://www.emergingthreats.net -------------------------------------------- PGP: http://www.jonkmans.com/mattjonkman.asc ------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/ _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-sigs] Emerging Threats Daily Signature Changes, Matt Jonkman |
|---|---|
| Next by Date: | Re: [Snort-sigs] For Instance: Hostile FTP Sigs, Brian Caswell |
| Previous by Thread: | [Snort-sigs] Confused by 'IMAP SSLv3 Server_Hello request'?, Sun |
| Next by Thread: | Re: [Snort-sigs] For Instance: Hostile FTP Sigs, Brian Caswell |
| Indexes: | [Date] [Thread] [Top] [All Lists] |