Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Snort-users] Detecting Packed Executables? |
|---|---|
| Date: | Fri, 18 Jul 2008 18:07:17 -0400 |
We've got sigs for Themida, WinUPack, FSG and RLPack in the emerging ruleset. There are many more we could sig, but the research hasn't been done yet. These that we have are very effective. If you're interested in helping out on the research I'd happily work with you. Matt Tommy Cansanay wrote:
Has anybody successfully created signatures that detect packers? I tried a simple content search where the sniffer sees the packed executable, but Snort does not. Tried several things, which included Hex, pcre, used |03| (DNS search), etc, but no luck. Doing some google searches, PE hunter could possibly do the trick, but it requires re-compiling snort. I was wondering if there was an easier way. Thanks ------------------------------------------------------------------------ ------------------------------------------------------------------------- This SF.Net email is sponsored by the Moblin Your Move Developer's challenge Build the coolest Linux based applications with Moblin SDK & win great prizes Grand prize is a trip for two to an Open Source event anywhere in the world http://moblin-contest.org/redirect.php?banner_id=100&url=/ ------------------------------------------------------------------------ _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
-- -------------------------------------------- Matthew Jonkman Emerging Threats Phone 765-429-0398 Fax 312-264-0205 http://www.emergingthreats.net -------------------------------------------- PGP: http://www.jonkmans.com/mattjonkman.asc ------------------------------------------------------------------------- This SF.Net email is sponsored by the Moblin Your Move Developer's challenge Build the coolest Linux based applications with Moblin SDK & win great prizes Grand prize is a trip for two to an Open Source event anywhere in the world http://moblin-contest.org/redirect.php?banner_id=100&url=/ _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-users] Detecting Packed Executables?, Tommy Cansanay |
|---|---|
| Next by Date: | Re: [Snort-users] snort ftp preprocessor alerts on port 2100 ??, Steven Sturges |
| Previous by Thread: | [Snort-users] Detecting Packed Executables?, Tommy Cansanay |
| Next by Thread: | [Snort-users] Mike Potamousis/Poughkeepsie/Contr/IBM is out of the office., Mike Potamousis |
| Indexes: | [Date] [Thread] [Top] [All Lists] |