Bluehost.com Web Hosting $6.95

[Snort-users] stream4: logging characteristics

This is a discussion on [Snort-users] stream4: logging characteristics within the Snort forums, part of the System Security and Security Related category; Regarding the stream4 preprocessor: First: My understanding is that the stream4 preprocessor configured with the log_flushed_streams option should, on a ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 11-15-2003
Brian A Kee
 
Posts: n/a
Default [Snort-users] stream4: logging characteristics

Regarding the stream4 preprocessor:

First:
My understanding is that the stream4 preprocessor configured with the
log_flushed_streams option should, on a positive signature detect, log the
entire stream or "uber" packet when logging to tcpdump output.

preprocessor stream4: log_flushed_streams


Combining this with the strem4_reasemble options of client_only, server_only,
or both should result in entire stream packet dump of the client side, server
side, or both sides of the tcp stream, respectively.

preprocessor stream4_reassemble: both


Is this a correct interpretation of these options?


Second:
The stream4 preprocessor is supposed to combine all of the packets from a tcp
stream into a single session "uber" packet. This being the case would it not
be possible to write a rule such as"

alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS \
(msg:"POSITIVE -- WEB-IIS cmd.exe access"; \
flow:established,only_stream; content:"cmd.exe"; nocase; \
content: "200 OK"; nocase; )

that would match "cmd.exe" and "200 OK" only in the same session?



--
Thank You,

Brian A. Kee




-------------------------------------------------------
This SF. Net email is sponsored by: GoToMyPC
GoToMyPC is the fast, easy and secure way to access your computer from
any Web browser or wireless device. Click here to Try it Free!
https://www.gotomypc.com/tr/OSDN/AW/...=mm/g22lp.tmpl
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 05:03 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0