|
|||||||||||
|
RES: HTTP based trojans
From: <AQBARROS(at)BKB.com.br>
Date: Wed Nov 06 2002 - 07:56:51 EST
People has been using HTTP based trojans for some years, but only after the Sensepost Black Hat presentation about Setiri it has become a major point of discussion. I didn't see nobody sharing ideas about detecting (or even blocking) this stuff. I can imagine a couple of Snort rules to try to detect it, based on filenames and paths, like cmd.exe, \winnt, etc, but it would find a lot of false positives and wouldn´t be effective on cases using SSL. So, perhaps the point is on HIDS; But how can we detect the abnormal behaviour if the trojan is getting out through a IE window? Which adverse effects there will be if we block the use of invisible IE windows? Regards, Augusto
-----Mensagem original-----
Hi, What other open-source tool do you use to detect this attack?
Sam.
> As I saw on the last messages about detecting trojans through flow-based
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:04 EDT |
||||||||||
|
|||||||||||