This is a discussion on Re: [Snort-users] Team0x42 Snort rules within the Snort forums, part of the System Security and Security Related category; --===============1794587161== Content-Type: multipart/alternative; boundary="_f2cc7d17-db1d-4faf-be3f-14886dc02f49_" --_f2cc7d17-db1d-4faf-be3f-14886dc02f49_ Content-Type: ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
--===============1794587161==
Content-Type: multipart/alternative; boundary="_f2cc7d17-db1d-4faf-be3f-14886dc02f49_" --_f2cc7d17-db1d-4faf-be3f-14886dc02f49_ Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Everyone knows Team0x41 pwns all Shirkdog ' or 1=3D1-- =0A= http://www.shirkdog.us > From: lurene.grenier@sourcefire.com > To: TheWell@team0x42.homeunix.org > Date: Mon, 7 Apr 2008 18:05:44 -0400 > CC: snort-users@lists.sourceforge.net > Subject: Re: [Snort-users] Team0x42 Snort rules >=20 > In addition you might want to note that the MSF default behavior is to > encode all shellcode and append a decoder to the beginning of the payload= , > so none of those MSF shellcode rules will work except the HPUX on PA-RISC > because it lacks a valid encoder (though HPUX on ia64 should still be > undetectable with that rule). >=20 > I'm not in Brooklyn but I am crafty. >=20 > _________________________ > Lurene A Grenier,=20 > Analyst Team Lead > Senior Research Engineer > =20 > Office: (410) 423-1918 > Mobile: (703) 839-3898 > ,,_ > SourceFire Inc. o" )~ > '''' >=20 >=20 > -----Original Message----- > From: snort-users-bounces@lists.sourceforge.net > [mailto:snort-users-bounces@lists.sourceforge.net] On Behalf Of Brian > Caswell > Sent: Monday, April 07, 2008 6:00 PM > To: TheWell > Cc: snort-users@lists.sourceforge.net > Subject: Re: [Snort-users] Team0x42 Snort rules >=20 > On Apr 7, 2008, at 5:01 PM, TheWell wrote: > > Some good snort rules by Team0x42 >=20 > Team B, >=20 > Really? >=20 > I see 5 rules that are all basically the same thing. Perhaps you =20 > should update your regular expression to include all 5 cases you =20 > attempt to cover in 1 rule. >=20 > The following regular expression is released under the license to ill, =20 > however you may not use it unless you are in Brooklyn, and you did not =20 > sleep while traveling to said city. >=20 > (\%(60|3b|7c|00)|<) >=20 > Brian >=20 > ------------------------------------------------------------------------- > This SF.net email is sponsored by the 2008 JavaOne(SM) Conference=20 > Register now and save $200. Hurry, offer ends at 11:59 p.m.,=20 > Monday, April 7! Use priority code J8TLD2.=20 > http://ad.doubleclick.net/clk;198757...va.sun.com/ja= vao > ne > _______________________________________________ > Snort-users mailing list > Snort-users@lists.sourceforge.net > Go to this URL to change user options or unsubscribe: > https://lists.sourceforge.net/lists/...fo/snort-users > Snort-users list archive: > http://www.geocrawler.com/redir-sf.p...=3Dsnort-users >=20 >=20 > ------------------------------------------------------------------------- > This SF.net email is sponsored by the 2008 JavaOne(SM) Conference=20 > Register now and save $200. Hurry, offer ends at 11:59 p.m.,=20 > Monday, April 7! Use priority code J8TLD2.=20 > http://ad.doubleclick.net/clk;198757...va.sun.com/ja= vaone > _______________________________________________ > Snort-users mailing list > Snort-users@lists.sourceforge.net > Go to this URL to change user options or unsubscribe: > https://lists.sourceforge.net/lists/...fo/snort-users > Snort-users list archive: > http://www.geocrawler.com/redir-sf.p...=3Dsnort-users __________________________________________________ _______________ Use video conversation to talk face-to-face with Windows Live Messenger. http://www.windowslive.com/messenger...d=3DTXT_TAGLM= _WL_Refresh_messenger_video_042008= --_f2cc7d17-db1d-4faf-be3f-14886dc02f49_ Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable <html> <head> <style> ..hmmessage P { margin:0px; padding:0px } body.hmmessage { FONT-SIZE: 10pt; FONT-FAMILY:Tahoma } </style> </head> <body class=3D'hmmessage'><div style=3D"text-align: left;">Everyone knows T= eam0x41 pwns all<br></div><br>Shirkdog<br>' or 1=3D1-- =0A= <br>http://www.shirkdog.us<br><br><hr id=3D"stopSpelling">> From: lurene= ..grenier@sourcefire.com<br>> To: TheWell@team0x42.homeunix.org<br>> D= ate: Mon, 7 Apr 2008 18:05:44 -0400<br>> CC: snort-users@lists.sourcefor= ge.net<br>> Subject: Re: [Snort-users] Team0x42 Snort rules<br>> <br>= > In addition you might want to note that the MSF default behavior is to= <br>> encode all shellcode and append a decoder to the beginning of the = payload,<br>> so none of those MSF shellcode rules will work except the = HPUX on PA-RISC<br>> because it lacks a valid encoder (though HPUX on ia= 64 should still be<br>> undetectable with that rule).<br>> <br>> I= 'm not in Brooklyn but I am crafty.<br>> <br>> ______________________= ___<br>> Lurene A Grenier, <br>> Analyst Team Lead<br>> Senior Res= earch Engineer<br>> <br>> Office: (410) 423-1918<br>> Mobile: (70= 3) 839-3898<br>> ,,_<br>> SourceFire Inc. o" )~<br>= > ''''<br>> <br>> <br>> -----Original Message-= ----<br>> From: snort-users-bounces@lists.sourceforge.net<br>> [mailt= o:snort-users-bounces@lists.sourceforge.net] On Behalf Of Brian<br>> Cas= well<br>> Sent: Monday, April 07, 2008 6:00 PM<br>> To: TheWell<br>&g= t; Cc: snort-users@lists.sourceforge.net<br>> Subject: Re: [Snort-users]= Team0x42 Snort rules<br>> <br>> On Apr 7, 2008, at 5:01 PM, TheWell = wrote:<br>> > Some good snort rules by Team0x42<br>> <br>> Team= B,<br>> <br>> Really?<br>> <br>> I see 5 rules that are all ba= sically the same thing. Perhaps you <br>> should update your regular e= xpression to include all 5 cases you <br>> attempt to cover in 1 rule.<= br>> <br>> The following regular expression is released under the lic= ense to ill, <br>> however you may not use it unless you are in Brookly= n, and you did not <br>> sleep while traveling to said city.<br>> <b= r>> (\%(60|3b|7c|00)|<)<br>> <br>> Brian<br>> <br>> -----= --------------------------------------------------------------------<br>>= ; This SF.net email is sponsored by the 2008 JavaOne(SM) Conference <br>>= ; Register now and save $200. Hurry, offer ends at 11:59 p.m., <br>> Mon= day, April 7! Use priority code J8TLD2. <br>> http://ad.doubleclick.net/= clk;198757673;13503038;p?http://java.sun.com/javao<br>> ne<br>> _____= __________________________________________<br>> Snort-users mailing list= <br>> Snort-users@lists.sourceforge.net<br>> Go to this URL to change= user options or unsubscribe:<br>> https://lists.sourceforge.net/lists/l= istinfo/snort-users<br>> Snort-users list archive:<br>> http://www.ge= ocrawler.com/redir-sf.php3?list=3Dsnort-users<br>> <br>> <br>> ---= ----------------------------------------------------------------------<br>&= gt; This SF.net email is sponsored by the 2008 JavaOne(SM) Conference <br>&= gt; Register now and save $200. Hurry, offer ends at 11:59 p.m., <br>> M= onday, April 7! Use priority code J8TLD2. <br>> http://ad.doubleclick.ne= t/clk;198757673;13503038;p?http://java.sun.com/javaone<br>> ____________= ___________________________________<br>> Snort-users mailing list<br>>= ; Snort-users@lists.sourceforge.net<br>> Go to this URL to change user o= ptions or unsubscribe:<br>> https://lists.sourceforge.net/lists/listinfo= /snort-users<br>> Snort-users list archive:<br>> http://www.geocrawle= r.com/redir-sf.php3?list=3Dsnort-users<br><br /><hr />Use video conversatio= n to talk face-to-face with Windows Live Messenger. <a href=3D'http://www.w= indowslive.com/messenger/connect_your_way.html?ocid=3DTXT_TAGLM_WL_Refresh_ = messenger_video_042008' target=3D'_new'>Get started!</a></body> </html>= --_f2cc7d17-db1d-4faf-be3f-14886dc02f49_-- --===============1794587161== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline ------------------------------------------------------------------------- This SF.net email is sponsored by the 2008 JavaOne(SM) Conference Register now and save $200. Hurry, offer ends at 11:59 p.m., Monday, April 7! Use priority code J8TLD2. http://ad.doubleclick.net/clk;198757...un.com/javaone --===============1794587161== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users --===============1794587161==-- |