[33080] in bugtraq

home help back first fref pref prev next nref lref last post

Snort-inline

daemon@ATHENA.MIT.EDU (Federico Petronio)
Tue Jan 13 17:47:33 2004

Message-ID: <40046D6D.9020609@petrus.agro.uba.ar>
Date: 	Tue, 13 Jan 2004 19:13:01 -0300
From: Federico Petronio <fpetronio@petrus.agro.uba.ar>
MIME-Version: 1.0
To: bugtraq@securityfocus.com
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit

I have snort-inline 2.0.1 installed. I change the rule 2077 acction to drop.

Then I try to access, using Mozilla 1.5 and IE6.0, the URL:
http://server_name/admin/fileman/upload.php?dir=

the snort-inline log start showing lines like this:

[**] [1:2077:2] WEB-PHP Mambo upload.php access [**]
[Classification: access to a potentially vulnerable web application] 
[Priority: 2]
01/13-18:31:06.944124 200.43.81.205:1586 -> 10.2.0.10:80 TCP TTL:117 
TOS:0x0 ID:3095 IpLen:20 DgmLen:578 DF
***AP*** Seq: 0x45A19C2C Ack: 0x425899A4 Win: 0xFFFF TcpLen: 20
[Xref => http://www.securityfocus.com/bid/6572]


but after 5 minutes of that, the webserver finally got the query and 
answed. That means that snort-inline let pass through the packet that 
should drop. Can anyone check that? I try several time and got the same 
result.

-- 
                                         Federico Petronio
                                         fpetronio@petrus.agro.uba.ar
                                         Linux User #129974

---
There are only 10 types of people in the world:
               Those who understand binary and those who don't.


home help back first fref pref prev next nref lref last post