Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-users] Testing Snort with Blade IDS Informer |
|---|---|
| Date: | Wed, 27 Apr 2005 19:47:53 +0200 |
Hello, I am writing a bachelor thesis about network intrusion detection in general and snort in special. I set up a snort based sensor in a real network. Now I have recently tested my snort sensor (using snort 2.3.2 and latest snort rules) with Blade Softwares IDS Informer demo version. However, I was a bit disappointed about the results. Besides the back orifice and the two portscan attempts, my sensor didn't detect anything else of the remaining 7 attacks provided by IDS Informer. In detail it didn't detect - TCP DNS Zone Transfer - Smurf DOS attempt - finger search - IIS Unicode Traps - IIS htr Buffer Overflow - rpc.statd exploit - traceroute attempt I have checked the rules and doesn't have any clue, why my sensor didn't detect these attacks. At least from reading rule descriptions I am of the opinion, that snort should detect all attacks. For example I have looked at the rule for the htr Buffer Overlow. In my opinion the rule "WEB-IIS ism.dll attempt" should be announced by this attack. The rule searches for " .htr" in the packets with uricontent. Looking into the tcpdumps of the IDS Informer simulated attack, I see the pattern "!.htr". Has someone else on this list tested his sensor(s) with IDS Informer? Were the results the same like mine? I have also tested my sensor with generating malicious traffic with hping2 and fragroute. The detection-engine detected the events. Furthermore I am already running my sensor on real network traffic. It already reported incidents. Thank you for your help, Holger -- Holger Mense
signature.asc
Description: Digital signature
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: [SPAM] - RE: [Snort-users] Fedora Core Linux 3 -- Snort IDS - Email found in subject, Marc Hering |
|---|---|
| Next by Date: | Re: [Snort-users] Testing Snort with Blade IDS Informer, Paul Schmehl |
| Previous by Thread: | RE: [SPAM] - RE: [Snort-users] Fedora Core Linux 3 -- Snort IDS - Email found in subject, Marc Hering |
| Next by Thread: | Re: [Snort-users] Testing Snort with Blade IDS Informer, Paul Schmehl |
| Indexes: | [Date] [Thread] [Top] [All Lists] |