Dailydave mailing list archives

RE: Dreaming of Summer


From: "Halvar Flake" <HalVar () gmx de>
Date: Sun, 7 Dec 2003 21:42:12 +0100 (MET)

Add a shim to the packet capture engine. Before the captured packet gets
set up the stack for traditonal protocol decodes you can check for
conditions like the seq number matches a predefined set and if it does
you can readsomething like the window size and translate that into a
part of a command. If a packet like this is captured it woun't get
flagged by the IDS becasue it never makes it to the IDS analysis phase.
Command response is done by the same shim via packet injection. This
would require some device driver foo. This would not work well if the
IDS supplies its own network card driver.

The installations I've seen so far lack any ability to talk back to the
network for use of a cable without the appropriate wires -- but then
again I am no expert on this.

Cheers,
Halvar

-- 
+++ GMX - die erste Adresse für Mail, Message, More +++
Neu: Preissenkung für MMS und FreeMMS! http://www.gmx.net


_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://www.immunitysec.com/mailman/listinfo/dailydave


Current thread: