Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Snort-Users
[Top] [All Lists]

[Snort-users] Testing Snort with Blade IDS Informer

Subject: [Snort-users] Testing Snort with Blade IDS Informer
Date: Wed, 27 Apr 2005 19:47:53 +0200
Hello,

I am writing a bachelor thesis about network intrusion detection in general 
and snort in special. I set up a snort based sensor in a real network.

Now I have recently tested my snort sensor (using snort 2.3.2 and latest snort 
rules) with Blade Softwares IDS Informer demo version.

However, I was a bit disappointed about the results. Besides the back orifice 
and the two portscan attempts, my sensor didn't detect anything else of the 
remaining 7 attacks provided by IDS Informer.

In detail it didn't detect
 - TCP DNS Zone Transfer
 - Smurf DOS attempt
 - finger search
 - IIS Unicode Traps
 - IIS htr Buffer Overflow
 - rpc.statd exploit
 - traceroute attempt

I have checked the rules and doesn't have any clue, why my sensor didn't 
detect these attacks. At least from reading rule descriptions I am of the 
opinion, that snort should detect all attacks.

For example I have looked at the rule for the htr Buffer Overlow. In my 
opinion the rule "WEB-IIS ism.dll attempt" should be announced by this attack. 
The rule searches for " .htr" in the packets with uricontent. Looking into the 
tcpdumps of the IDS Informer simulated attack, I see the pattern "!.htr". 

Has someone else on this list tested his sensor(s) with IDS Informer? Were the 
results the same like mine? 

I have also tested my sensor with generating malicious traffic with hping2 and 
fragroute. The detection-engine detected the events. Furthermore I am already 
running my sensor on real network traffic. It already reported incidents.

Thank you for your help,
Holger

-- 
Holger Mense

Attachment: signature.asc
Description: Digital signature

<Prev in Thread] Current Thread [Next in Thread>