Snort mailing list archives
Re: Individual rule msg definitions
From: Chris Green <cmg () uab edu>
Date: 27 Jul 2001 14:16:55 -0500
"Scott" <scottr () vdot net> writes:
Yes I am aware of the bugtraq, IDS numbers and cert ones, but what about those that aren't referenced such as the ones I listed in the previous email. I did a google but all I found were incidents but no definitions as to what was the meaning.[110:2:1] spp_unidecode: Unicode Directory Transversal I have no idea as to whether these alerts are serious or whatthey mean.
The alert is from spp_unidecode. This attempts to act like the http decode plugin but also decode multibyte unicode encodings into the normal ascii style bytes. if (((c==0x5c) || (c==0x2f) || (c==0x2e)) && do_detect) { snprintf(logMessage, sizeof(logMessage), MODNAME ": Unicode Directory Transversal attack detected"); For the hex slow people: perl -e 'printf("%c %c %c\n", 0x5c, 0x2f, 0x2e);' \ / . So, if the encoded byte is one of those characters, log it as a unicode directory transversal attack. Eg: a unicode mapping such that is might be interpreted as /../ -- Chris Green <cmg () uab edu> To err is human, to moo bovine. _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- RE: Fatal Error OpenLogFile, (continued)
- RE: Fatal Error OpenLogFile Scott (Jul 25)
- Re: Fatal Error OpenLogFile J. C. Woods (Jul 25)
- RE: Fatal Error OpenLogFile Scott (Jul 25)
- RE: Fatal Error OpenLogFile Erek Adams (Jul 25)
- RE: Fatal Error OpenLogFile Scott (Jul 25)
- RE: Fatal Error OpenLogFile Scott (Jul 25)
- RE: Fatal Error OpenLogFile Erek Adams (Jul 26)
- Individual rule msg definitions Scott (Jul 26)
- Re: Individual rule msg definitions Dragos Ruiu (Jul 27)
- RE: Individual rule msg definitions Scott (Jul 27)
- Re: Individual rule msg definitions Chris Green (Jul 27)
- RE: Fatal Error OpenLogFile Scott (Jul 25)