WinDump , . . , , , (IDS). , , , , , TCP SYN. , TCP- . SYN-, , . SYN|ACK , . RST . SYN|ACK, RST- . , SYN-.
, , cmd.exe, (IIS) web- Microsoft. - , Nimda Code Red. cmd.exe Windows, IIS, Internet Server API (ISAPI). . IIS:
length = 55
000: 47 45 54 20 2F 73 63 72 69 70 74 73 2F 2E 2E 25 GET / scripts/..%
E 2E 2F 77 69 6E 6E 74 2F 73 79 5c%5c../winnt/sy
020: 73 74 65 6D 33 32 2F 63 6D 64 2E 65 78 65 3F 2F stem32/cmd.exe?/
030: 63 2B 64 69 72 0D 0A c+dir..
, , , . WinDump .
, WinDump IDS , , , . , .
IDS SNORT
Snort , . C Snort . UNIX . Windows. web- www.snort.org , . , .
|
|
Snort , . 1200 , .
. , 1999 . Snort Shadow. , Snort . , , , , .
Snort
Snort . , , , , . , . , , . , , , CGI-, OS ..
Snort .
1. . Snort , .
2. . ASCII .
3. . .
Snort , . . Internet , Snort.
. . .
1. , (pattern-based signatures), , . , . , cwd ~root FTP- FTP- FTP-. Java CA FE BA BE. , .
2. , . , , . SYN Flood. , . .
3. . , . , 2.30, , .