PaulDotCom mailing list archives
Re: IPS detection and plausible deniability
From: Michael <sector876 () gmail com>
Date: Sun, 26 Jun 2011 15:52:32 -0500
Hi Robin, SprayPal, introduced during Blackhat last year may help with the first technique. http://media.blackhat.com/bh-us-10/whitepapers/Engebretson_Pauli_Cronin/BlackHat-USA-2010-Engebretson-Pauli-Cronin-SprayPAL-wp.pdf Regards, Michael Sent from my iPad On Jun 26, 2011, at 10:07 AM, Robin Wood <robin () digininja org> wrote:
I'm interested in two IPS detection techniques and looking for papers or tools on both. The first is something like WafW00f from Sandro Gauci. Something that will fire loads of traffic against a network and see what happens then determine what, if anything, is in place based on the results. The second is anything about a tool that will maybe just detect there is an IPS in place but the traffic it generates could be explained as legitimate traffic so allow plausible deniability. Anyone got anything? Robin _______________________________________________ Pauldotcom mailing list Pauldotcom () mail pauldotcom com http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom Main Web Site: http://pauldotcom.com
_______________________________________________ Pauldotcom mailing list Pauldotcom () mail pauldotcom com http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom Main Web Site: http://pauldotcom.com
Current thread:
- IPS detection and plausible deniability Robin Wood (Jun 26)
- Re: IPS detection and plausible deniability Michael (Jun 26)
- Re: IPS detection and plausible deniability Will Metcalf (Jun 26)
- Re: IPS detection and plausible deniability Michael (Jun 26)
- Re: IPS detection and plausible deniability Will Metcalf (Jun 26)
- Re: IPS detection and plausible deniability Michael (Jun 26)