OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[sec-adv] Snort "detect_scan" Bypass

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Fri Mar 28 2003 - 10:22:49 CST


TITLE:
Snort "detect_scan" Bypass

READ ONLINE:
http://www.secunia.com/advisories/8442/

CRITICAL:
Less critical

IMPACT:
Security Bypass

WHERE:
From remote

SOFTWARE:
Snort 1.9.x

DESCRIPTION:
A vulnerability in Snort can be exploited by malicious people to
bypass the port scan detection.

Snort does not detect packets with both the SYN, FIN and ECN echo
bits set, if the default configuration is used. This can be exploited
by a malicious person to conduct a portscan without being detected by
Snort.

The vulnerability has been confirmed in Snort 1.9.1, but other
versions might also be affected.

SOLUTION:
Upgrade to version Snort-2.0.0rc1:
http://www.snort.org/dl/snort-2.0.0rc1.tar.gz

Snort 1.9.1:
Enable the portscan preprocessor or delete the "detect_scans" option
in the stream 4 preprocessor.

Generally, a packet with both the SYN and FIN bits set, should be
filtered in a border router or firewall, since this is not valid bit
combination.

REPORTED BY / CREDITS:
Toby Miller

----------------------------------------------------------------------

Secunia recommends that you verify all advisories you receive, by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

Contact details:
Web : http://www.secunia.com/
E-mail : supportsecunia.com
Tel : +44 (0) 20 7016 2693
Fax : +44 (0) 20 7637 0419

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------