Snort mailing list archives

Re: Help with pass rule


From: "prabu" <prabu333 () hotpop com>
Date: Fri, 3 Sep 2004 12:00:23 +0530

Hello Sekure,
            It was good response with lot of pratical informations for using
the Windows Rules.Great !!!!!!!

But,coming back to point,
   It was You ,who wrote that sig_id is 2405.
   I corrected it as 2404.But,now u r talking in the otherway,the
vise-versa.

Look at my reply
cut and paste of my mail:
On Thu, 2 Sep 2004 09:54:09 +0530, prabu <prabu333 () hotpop com> wrote:
Hi,
    I guess that correct sig_id suppose for thar rule to be 2404,instead
of
2405.

So the suppress command should be as
suppress gen_id 1, sig_id 2404, track by_src, ip 160.214.186.9
instead of;
suppress gen_id 1, sig_id 2405, track by_src, ip 160.214.186.9


Have a look at your first reply:
Carlton,

A better solution would be to add the following to your threshold.conf:
suppress gen_id 1, sig_id 2405, track by_src, ip 160.214.186.9


Now,it may be clear to you.My intension was not to critisis you ,but to give
the correct information to the list.


Cheers,
prabu.S





----- Original Message ----- 
From: "sekure" <sekure () gmail com>
To: "prabu" <prabu333 () hotpop com>
Cc: "Carlton L. Whitmore" <cwhitmore () advocacyinc org>;
<snort-users () lists sourceforge net>
Sent: Thursday, September 02, 2004 8:30 PM
Subject: Re: [Snort-users] Help with pass rule


Prabu,

The orignal message included the following alert:

[1:2404:5] NETBIOS SMB-DS Session Setup AndX request unicode username
overflow attempt [Classification: Attempted Administrator Privilege
Gain] [Priority: 1]: {TCP} 160.214.186.9:2636 -> 160.214.186.45:445

The sid is 2404, so my initial post was correct.
Sid 2505 is " WEB-PHP phptest.php access"

But this does bring up an interesting point.  Carlton, a lot of the
windows rules have two versions, one for SMB over NBT (port 139) and
one for SMB over TCP/IP (port 445).  So if you are going to be
suppressing rules, make sure you suppress them both, if they are both
popping up.  The other sid is 2403 " NETBIOS SMB Session Setup AndX
request unicode username overflow attempt".

It's a subtle difference and i've been caught dumfounded more than
once, after suppressing one rule, seeing the other, but not realizing
it and thinking snort was somehow broken.

good luck

On Thu, 2 Sep 2004 09:54:09 +0530, prabu <prabu333 () hotpop com> wrote:
Hi,
    I guess that correct sig_id suppose for thar rule to be 2404,instead
of
2405.

So the suppress command should be as
suppress gen_id 1, sig_id 2404, track by_src, ip 160.214.186.9
instead of;
suppress gen_id 1, sig_id 2405, track by_src, ip 160.214.186.9


Cheers,
Prabu.S


---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.747 / Virus Database: 499 - Release Date: 9/1/2004




-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_id=5047&alloc_id=10808&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: