lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon Aug  8 22:19:01 2005
From: fd at ew.nsci.us (fd@...nsci.us)
Subject: IDS or IPS detection and bypass

On Mon, 8 Aug 2005, Ahmad N wrote:

>  I was trying to gain a reverse shell to a website the other day using a
> buffer overflow exploit, unfortunaetly it seems like they have some kind
> of buffer overflow exploit protection coming from and IDS or IPS so is
> there a way to find out what exactly is running, an IDS or IPS, and
> accordingly is there a way to bypass these systems

If the IDS uses pcap (tcpdump et al) then you might find a way to crash
the IDS.  It seems that new IDS-crashing spoits come up often enough that
perhaps your customer isn't completely up to date.  Linuxsecurity.com has
a decent article on testing IDS systems here:  
  http://www.linuxsecurity.com/content/view/114356/65/.

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ