|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[sec-adv] Snort "detect_scan" Bypass
From: Secunia Security Advisories (sec-adv
secunia.com)
Date: Fri Mar 28 2003 - 10:22:49 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
TITLE:
Snort "detect_scan" Bypass
READ ONLINE:
http://www.secunia.com/advisories/8442/
CRITICAL:
Less critical
IMPACT:
Security Bypass
WHERE:
From remote
SOFTWARE:
Snort 1.9.x
DESCRIPTION:
A vulnerability in Snort can be exploited by malicious people to
bypass the port scan detection.
Snort does not detect packets with both the SYN, FIN and ECN echo
bits set, if the default configuration is used. This can be exploited
by a malicious person to conduct a portscan without being detected by
Snort.
The vulnerability has been confirmed in Snort 1.9.1, but other
versions might also be affected.
SOLUTION:
Upgrade to version Snort-2.0.0rc1:
http://www.snort.org/dl/snort-2.0.0rc1.tar.gz
Snort 1.9.1:
Enable the portscan preprocessor or delete the "detect_scans" option
in the stream 4 preprocessor.
Generally, a packet with both the SYN and FIN bits set, should be
filtered in a border router or firewall, since this is not valid bit
combination.
REPORTED BY / CREDITS:
Toby Miller
----------------------------------------------------------------------
Secunia recommends that you verify all advisories you receive, by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
Contact details:
Web : http://www.secunia.com/
E-mail : support
secunia.com
Tel : +44 (0) 20 7016 2693
Fax : +44 (0) 20 7637 0419
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
----------------------------------------------------------------------
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]