Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[Snort-sigs] 1631 CHAT AIM login false positive

From: Terence Runge <terencerunge(at)sbcglobal.net>
Date: Fri May 02 2003 - 17:57:05 EDT


  This rule is fired when a user starts netscape mail and a mailbox is checked. It appears that it has become a habit of netscape to "call home" to port 5190 whenever netscape mail is used and "Get Msgs" is completed. Proof of concept from my system.

C:\>netstat -an | grep 5190
  TCP xxx.xxx.xxx.xxx:xxxx 64.12.25.151:5190 ESTABLISHED

Search results for: 64.12.25.151

OrgName: America Online, Inc.
OrgID: AMERIC-158
Address: 10600 Infantry Ridge Road
City: Manassas
StateProv: VA
PostalCode: 20109
Country: US

I have opted to not use AOL IM and have also disabled automatic launch in the browser preferences. Still, the connection is attempted, established and maintained, resulting in a false positive.

alert tcp $HOME_NET any -> $AIM_SERVERS any (msg:"CHAT AIM login"; flow:to_server,established; content:"|2a 01|"; offset:0; d epth:2; classtype:policy-violation; sid:1631; rev:4;)

How could this signature be revised to not fire when a user checks mail using netscape? Changing the destination port will not do it and will only result in missing all valid and in-valid AOL IM logins.

-Terence



This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven.
http://thinkgeek.com/sf

Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs Received on Fri May 2 18:54:12 2003
Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:27 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library