03.04.2013 Views

The menace came from below - Hack.lu

The menace came from below - Hack.lu

The menace came from below - Hack.lu

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Detect FTP injection - step 3<br />

Rule 3<br />

We already know we have a unsollicited 227<br />

Now combine it with stream event<br />

a l e r t tcp any 21 −> any any \<br />

(msg : "FTP PASV 227 i n j e c t i o n a t t a c k " ; \<br />

flow : t o _ c l i e n t ; \<br />

f l o w b i t s : i s s e t , f t p . p o s s i b l e _ i n j e c t i o n ; \<br />

stream −event : reassembly_overlap_different_data ; \<br />

classtype : misc−a t t a c k ; s i d : 3 ; rev : 1 ; )<br />

Éric Leblond, Victor Julien (OISF) <strong>The</strong> <strong>menace</strong> <strong>came</strong> <strong>from</strong> <strong>below</strong> <strong>Hack</strong>.<strong>lu</strong> 2012 43 / 66

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!