Snort mailing list archives
Re: SHELLCODE Attacks
From: Matt Kettler <mkettler () evi-inc com>
Date: Fri, 05 Dec 2003 17:39:19 -0500
At 05:16 PM 12/5/2003, Jeff wrote:
The reasons for excluding webserver ports are that certain binary data can resemble shellcode. For example, a GIF color table can look like a NOP sled. Also, if you're using curses over telnet, it can also resemble shellcode.
Agreed... And for reference, even though the ruleset in snort 2.0.5 is broken (ie: http exclusion on the wrong side) this appears to be fixed in snortrules-current and snortrules-stable, on the website.
------------------------------------------------------- This SF.net email is sponsored by: IBM Linux Tutorials. Become an expert in LINUX or just sharpen your skills. Sign up for IBM's Free Linux Tutorials. Learn everything from the bash shell to sys admin. Click now! http://ads.osdn.com/?ad_id=1278&alloc_id=3371&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- SHELLCODE Attacks Naman Latif (Dec 05)
- Re: SHELLCODE Attacks Matt Kettler (Dec 05)
- Re: SHELLCODE Attacks Erwin Van de Velde (Dec 05)
- Re: SHELLCODE Attacks Matt Kettler (Dec 05)
- Re: SHELLCODE Attacks Jeff Nathan (Dec 05)
- Re: SHELLCODE Attacks Matt Kettler (Dec 05)
- Re: SHELLCODE Attacks Erwin Van de Velde (Dec 05)
- Re: SHELLCODE Attacks Matt Kettler (Dec 05)
- <Possible follow-ups>
- RE: SHELLCODE Attacks Naman Latif (Dec 05)
- Windows 2000 Terminal Snort Issues Jim Robinson (Dec 05)