[Snort-users] Curse of the cmd.exe

Andy McLeod andy.mcleod at ...6107...
Mon Jun 17 20:10:03 EDT 2002


Sam

I am using sec, a Perl based correlation engine to allow me to correlate
events detected by snort and/or from other engines. I make sure all the
events I am interested in are reported to syslog (from wherever they are
detected, in your case snort and httpd) then use sec to track the
correlation.

For sec see:-

http://www.estpak.ee/~risto/sec/


rgds/andy


-----Original Message-----
From: snort-users-admin at lists.sourceforge.net
[mailto:snort-users-admin at lists.sourceforge.net]On Behalf Of Sam Evans
Sent: 14 June 2002 01:28
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] Curse of the cmd.exe


I was wondering if there is any way to alter a signature (maybe by using the
dynamic rules?) to have it record when a cmd.exe attempt on port 80 is
followed by the server's 200 OK ?

It seems pointless to me, to log 10,000 cmd.exe attempts from outside hosts,
when you don't know what the actual outcome was..  Sure, you have to go to
your webserver logs to find out the real result, but, with all the Nimda /
Codered still going on..   That makes for a very long day of log searching.

Does anyone have suggestions for a solution?  Is there one?  It seems like
it should be really easy to do.. in theory..

Thanks,
Sam



_______________________________________________________________

Don't miss the 2002 Sprint PCS Application Developer's Conference
August 25-28 in Las Vegas -
http://devcon.sprintpcs.com/adp/index.cfm?source=osdntextlink

_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users





More information about the Snort-users mailing list