Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: HTTP based trojans

From: s.wun <s.wun(at)thales-is.com.hk>
Date: Wed Nov 06 2002 - 21:13:08 EST

I think this so-called flow-based IDS is about analyse each end-to-end connection based on what protocol the connection is using. For example, if protocol is 6, it should follow standard TCP communication standard, anything other than that will be regarded as Potential hack. That's why in http connection, it detected communication is not belong to http, so it should be able to raise alarm.

One can create this kind of analyse with simple programming, not neccessary to purchase StealthWatch if we understand the principle of it.

sam
----- Original Message -----
From: <AQBARROS@BKB.com.br>
To: <focus-ids@securityfocus.com>
Sent: Wednesday, November 06, 2002 8:56 PM Subject: RES: HTTP based trojans

Good question! It's just what I want to know, but it seems that my question did not raise a discussion.

People has been using HTTP based trojans for some years, but only after the Sensepost Black Hat presentation about Setiri it has become a major point of discussion.

I didn't see nobody sharing ideas about detecting (or even blocking) this stuff. I can imagine a couple of Snort rules to try to detect it, based on filenames and paths, like cmd.exe, \winnt, etc, but it would find a lot of false positives and wouldn´t be effective on cases using SSL. So, perhaps the point is on HIDS; But how can we detect the abnormal behaviour if the trojan is getting out through a IE window? Which adverse effects there will be if we block the use of invisible IE windows?

Regards,

Do you need help?X

Augusto

-----Mensagem original-----
De: s.wun [mailto:s.wun@thales-is.com.hk] Enviada em: quarta-feira, 6 de novembro de 2002 0:27 Para: AQBARROS@BKB.com.br; focus-ids@securityfocus.com Assunto: Re: HTTP based trojans

Hi,

What other open-source tool do you use to detect this attack?

Sam.
----- Original Message -----
From: <AQBARROS@BKB.com.br>
To: <focus-ids@securityfocus.com>
Sent: Thursday, October 31, 2002 8:46 PM Subject: HTTP based trojans

> As I saw on the last messages about detecting trojans through flow-based
that
> use Internet Explorer controls to communicate with the client, even on
Did
> anyone try to do such kind of thing?
Received on Thu Nov 7 11:51:02 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:04 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library