|
Focus on IDS
Help in writing Network IDS/IPS signature to detect sftp vulnerability Jun 07 2008 12:21AM Ravi Chunduru (ravi is chunduru gmail com) (2 replies) RE: Help in writing Network IDS/IPS signature to detect sftp vulnerability Jun 09 2008 06:55PM Sergio Castro (sergio castro unicin net) (1 replies) Re: Help in writing Network IDS/IPS signature to detect sftp vulnerability Jun 10 2008 01:03AM Ravi Chunduru (ravi is chunduru gmail com) |
|
Privacy Statement |
As an administrator, one can create a 'Policy violation' signature. freeSSHD
daemon is sending string "SSH-2.0-WeOnlyDo 2.0.3" upon client connection.
It seems that 'WeOnlyDo' is the name of company which made this software.
2.0.3 could be software internal version. You could write a signature which
checks for string 'WeOnlyDo' and possibly version string.
Srini
-----Original Message-----
From: listbounce (at) securityfocus (dot) com [email concealed] [mailto:listbounce (at) securityfocus (dot) com [email concealed]] On
Behalf Of Ravi Chunduru
Sent: Friday, June 06, 2008 5:22 PM
To: Focus IDS
Subject: Help in writing Network IDS/IPS signature to detect sftp
vulnerability
Hi,
Check this disclosure at
http://archives.neohapsis.com/archives/fulldisclosure/2008-06/0101.html
the attack data is encrypted within the encrypted SSH. Without
having to decrypt the SSH, is there any clever way to detect this
(using some kind of anomaly on the packet size, type of characters
etc.. )?
thanks
Ravi
------------------------------------------------------------------------
Test Your IDS
Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to
http://www.coresecurity.com/index.php5?module=Form&action=impact&campaig
n=in
tro_sfw
to learn more.
------------------------------------------------------------------------
------------------------------------------------------------------------
Test Your IDS
Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaig
n=intro_sfw
to learn more.
------------------------------------------------------------------------
[ reply ]