[prev in list] [next in list] [prev in thread] [next in thread] 

List:       issforum
Subject:    [ISSForum] Unable to detect reverse telnet - Resolved
From:       "jefferson\.macedos" <jefferson.macedos () terra ! com ! br>
Date:       2005-07-16 20:08:54
Message-ID: IJQLAU$4061250F8CDA163F6B51C0B93E44D4B9 () terra ! com ! br
[Download RAW message or body]

Does some anyone remmember about this question???
--------------
Hello 

Question: 
Is Network Sensor able to analysis packets that doesn´t match a normal HTTP \
connection like a example: reverse telnet through port 80(http)? 

PAM(Protocol Analysis Module) shouldn't detect this protocol anomaly? 

Last weekend my webserver was exploited using "reverse telnet" and I my Network \
Sensor 7.0 was unable to detect this protocol anomaly. 

Jefferson 

Ps: (Reverse Telnet)http://www.onlamp.com/pub/a/onlamp/2003/05/29/netcat.html 
_-----------------------------------------------------------

Well, now the anomally is detected by Sensors with the new XPU 24.11, PERFECTO!!!!!!!

HTTP unknown protocol
http-unknown-protocol (21259)

Thank you in advance for help!!!!






_______________________________________________
ISSForum mailing list
ISSForum@iss.net

TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to \
https://atla-mm1.iss.net/mailman/listinfo/issforum

To contact the ISSForum Moderator, send email to mod-issforum@iss.net

The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 \
Barfield Road, Atlanta, Georgia, USA 30328.


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic