[Snort-users] non-standard-protocol : BAD-TRAFFIC IP Proto 103 PIM

This is a discussion on [Snort-users] non-standard-protocol : BAD-TRAFFIC IP Proto 103 PIM within the Snort forums, part of the System Security and Security Related category; --===============1594712337== Content-Language: en-US Content-Type: multipart/alternative; boundary="_000_EBAB1794F75FC646884764EA1D425B861A8 35F81usadcsmbxpf01qu_" --_000_EBAB1794F75FC646884764EA1D425B861A835F81usadc smbxpf01qu_ Content-Type: text/plain; ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-17-2007
David Ryan
 
Posts: n/a
Default [Snort-users] non-standard-protocol : BAD-TRAFFIC IP Proto 103 PIM

--===============1594712337==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_EBAB1794F75FC646884764EA1D425B861A8 35F81usadcsmbxpf01qu_"

--_000_EBAB1794F75FC646884764EA1D425B861A835F81usadc smbxpf01qu_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi all,

I am seeing loads (like 90% of all events) of these events showing up on on=
e of my Snort sensors. I have looked at the description here - http://www.=
snort.org/pub-bin/sigs.cgi?sid=3D2189 - and I looked at the rule definition=
and it appears to match simply on the existence of IP protocol 103 as dist=
inct from any payload within it.

I see the traffic coming from two known Cisco routers on the subnet I'm mon=
itoring and the traffic is destined for 224.0.0.13 which is the multicast a=
ddress for PIM - http://www.networksorcery.com/enp/protocol/pim.htm I have=
also I have seen it on other sites and subnets on the network I am monitor=
ing, so I guess whatever function is causing this traffic to originate from=
the router is used across the organisation.

In order to make the output from snort a little more readable (and because =
it is matching on the protocol and not the payload) I have disabled this ru=
le. I know the protocol in question is a routing-related protocol, but doe=
s anyone have any views or explanation on the normal use of this protocol ?

Thanks,

David
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D
David Ryan
IT Security Engineer, Global IT Security
Quintiles, Global IT - Infrastructure, QDUB

david.ryan@quintiles.com
v: +353-1-819-5186, GMT+0
m: +353-87-124-9108
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D




********************** IMPORTANT--PLEASE READ ************************
This electronic message, including its attachments, is COMPANY CONFIDENTIAL
and may contain PROPRIETARY or LEGALLY PRIVILEGED information. If you are=20
not the intended recipient, you are hereby notified that any use, disclosur=
e,
copying, or distribution of this message or any of the information included
in it is unauthorized and strictly prohibited. If you have received this
message in error, please immediately notify the sender by reply e-mail and
permanently delete this message and its attachments, along with any copies
thereof. If this electronic message contains a zipped attachment and you do
not have a decompression tool, you may download unZIP (free of cost) from:
http://www.mk-net-work.com/us/uz/unzip.htm. Alternatively, you may request
that the attachment be resent in an uncompressed format. Thank you.=20
************************************************** **********************


--_000_EBAB1794F75FC646884764EA1D425B861A835F81usadc smbxpf01qu_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii">
<meta name=3D"Generator" content=3D"Microsoft Exchange Server">
<!-- converted from rtf -->
<style>.EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800=
000 2px solid; }</style>
</head>
<body>
<font face=3D"Calibri, sans-serif" size=3D"2">
<div>Hi all,</div>
<div>&nbsp;</div>
<div>I am seeing loads (like 90% of all events) of these events showing up =
on one of my Snort sensors.&nbsp; I have looked at the description here - <=
a href=3D"http://www.snort.org/pub-bin/sigs.cgi?sid=3D2189"><font color=3D"=
#0000FF"><u>http://www.snort.org/pub-bin/sigs.cgi?sid=3D2189</u></font></a>
- and I looked at the rule definition and it appears to match simply on the=
existence of IP protocol 103 as distinct from any payload within it.</div>
<div>&nbsp;</div>
<div>I see the traffic coming from two known Cisco routers on the subnet I'=
m monitoring and the traffic is destined for 224.0.0.13 which is the multic=
ast address for PIM - <a href=3D"http://www.networksorcery.com/enp/protocol=
/pim.htm"><font color=3D"#0000FF"><u>http://www.networksorcery.com/enp/prot=
ocol/pim.htm</u></font></a>&nbsp;
I have also I have seen it on other sites and subnets on the network I am m=
onitoring, so I guess whatever function is causing this traffic to originat=
e from the router is used across the organisation.</div>
<div>&nbsp;</div>
<div>In order to make the output from snort a little more readable (and bec=
ause it is matching on the protocol and not the payload) I have disabled th=
is rule.&nbsp; I know the protocol in question is a routing-related protoco=
l, but does anyone have any views or
explanation on the normal use of this protocol ?</div>
<div>&nbsp;</div>
<div>Thanks,</div>
<div>&nbsp;</div>
<div>David</div>
<div><font face=3D"Courier New, monospace" size=3D"1">=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D</font></div>
<div><font face=3D"Courier New, monospace" size=3D"1">David Ryan</font></di=
v>
<div><font face=3D"Courier New, monospace" size=3D"1">IT Security Engineer,=
Global IT Security</font></div>
<div><font face=3D"Courier New, monospace" size=3D"1">Quintiles, Global IT =
- Infrastructure, QDUB</font></div>
<div><font face=3D"Courier New, monospace" size=3D"1">&nbsp;</font></div>
<div><font face=3D"Courier New, monospace" size=3D"1">david.ryan@quintiles.=
com</font></div>
<div><font face=3D"Courier New, monospace" size=3D"1">v:&nbsp; +353-1-8=
19-5186, GMT+0</font></div>
<div><font face=3D"Courier New, monospace" size=3D"1">m: +353-87-124-91=
08</font></div>
<div><font face=3D"Courier New, monospace" size=3D"1">=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3 D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D</font></div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div>&nbsp;</div>
</font>
<pre>
********************** IMPORTANT--PLEASE READ ************************
This electronic message, including its attachments, is COMPANY CONFIDENTIAL
and may contain PROPRIETARY or LEGALLY PRIVILEGED information. If you are=20
not the intended recipient, you are hereby notified that any use, disclosur=
e,
copying, or distribution of this message or any of the information included
in it is unauthorized and strictly prohibited. If you have received this
message in error, please immediately notify the sender by reply e-mail and
permanently delete this message and its attachments, along with any copies
thereof. If this electronic message contains a zipped attachment and you do
not have a decompression tool, you may download unZIP (free of cost) from:
http://www.mk-net-work.com/us/uz/unzip.htm. Alternatively, you may request
that the attachment be resent in an uncompressed format. Thank you.=20
************************************************** **********************

</pre></body>
</html>

--_000_EBAB1794F75FC646884764EA1D425B861A835F81usadc smbxpf01qu_--


--===============1594712337==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
http://sourceforge.net/powerbar/db2/
--===============1594712337==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
--===============1594712337==--

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 03:09 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0