<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>InfoSecPodcast.com &#187; Snort</title>
	<atom:link href="http://www.infosecpodcast.com/category/security/snort/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.infosecpodcast.com</link>
	<description>Information Security related news, opinions and ramblings</description>
	<lastBuildDate>Sun, 25 Jul 2010 13:04:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Google exposing Snort deployments</title>
		<link>http://www.infosecpodcast.com/2006/08/google-exposing-snort-deployments/</link>
		<comments>http://www.infosecpodcast.com/2006/08/google-exposing-snort-deployments/#comments</comments>
		<pubDate>Tue, 15 Aug 2006 00:35:28 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
				<category><![CDATA[Snort]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/snort/2006/08/google-exposing-snort-deployments/</guid>
		<description><![CDATA[I was setting up a Snort / Base / Barnyard box for a friend tonight. When looking in the root directory where Base was installed I didn&#8217;t see a robots.txt file. This got me thinking&#8230;I know&#8230;dangerous. Anyway, I did some Googling and in about 5 minutes I found: 5 Acid consoles 2 Base consoles 1 [...]]]></description>
			<content:encoded><![CDATA[<p>I was setting up a <a target="_blank" href="http://www.snort.org">Snort</a> / <a target="_blank" href="http://secureideas.sourceforge.net/">Base</a> / <a target="_blank" href="http://sourceforge.net/projects/barnyard">Barnyard</a> box for a friend tonight. When looking in the root directory where Base was installed I didn&#8217;t see a robots.txt file. This got me thinking&#8230;I know&#8230;dangerous. Anyway, I did some Googling and in about 5 minutes I found:</p>
<p>5 Acid consoles<br />
2 Base consoles<br />
1 Open Aanval console</p>
<p>The power of Google&#8217;s cache&#8230;. All were wide open with no passwords. Someone with malicious intent could delete all alerts, alert groups, cache and probably more. Not to mention the topology info they could get. I didn&#8217;t make note of the versions but I remember both Acid and Base having security issues&#8230;.Base I believe was affected by a cross-site scripting vulnerability at one point.<br />
It&#8217;s not Google&#8217;s fault really, the spiders are just doing thier jobs. My recommendation to anyone delpoying Acid / Base, create a robots.txt file in the Acid / Base root directory. In that file put these lines:</p>
<p>User-agent: *<br />
Disallow: /</p>
<p>This will tell any Search Engine spiders not to index that site. You could also put this on each php page as well:</p>
<p><METAÂ NAME="ROBOTS"Â CONTENT="NOINDEX,NOFOLLOW"><br />
&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/Snort" rel="tag"> Snort</a>, <a href="http://technorati.com/tag/Base" rel="tag"> Base</a>, <a href="http://technorati.com/tag/Acid" rel="tag"> Acid</a>, <a href="http://technorati.com/tag/Google" rel="tag"> Google</a>, <a href="http://technorati.com/tag/robots.txt" rel="tag"> robots.txt </a></p>
<div id="crp_related"><h2>Related Posts:</h2><ul><li><a href="http://www.infosecpodcast.com/2006/09/google-exposing-ip-cameras/" rel="bookmark" class="crp_title">Google exposing IP cameras</a></li><li><a href="http://www.infosecpodcast.com/2007/06/ip-address-to-user/" rel="bookmark" class="crp_title">IP Address to User??</a></li><li><a href="http://www.infosecpodcast.com/2006/07/security-search-plugins-for-firefox/" rel="bookmark" class="crp_title">Security Search Plugins for Firefox</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div><img src="http://www.infosecpodcast.com/?ak_action=api_record_view&id=33&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2006/08/google-exposing-snort-deployments/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>&#8220;0-Day&#8221; exploit for PowerPoint, Snort sigs to block .ppt files</title>
		<link>http://www.infosecpodcast.com/2006/07/0-day-exploit-for-powerpoint-snort-sigs-to-block-ppt/</link>
		<comments>http://www.infosecpodcast.com/2006/07/0-day-exploit-for-powerpoint-snort-sigs-to-block-ppt/#comments</comments>
		<pubDate>Sat, 15 Jul 2006 01:58:07 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
				<category><![CDATA[Security Alert]]></category>
		<category><![CDATA[Snort]]></category>
<category>Backdoor.Bifrose.E</category><category>Intrusion Prevention</category><category>IPS</category><category>microsoft powerpoint</category><category>MS06 028</category><category>secunia</category><category>signature</category><category>Snort</category><category>trojan</category><category>vulnerability</category>
		<guid isPermaLink="false">http://www.infosecpodcast.com/2006/07/14/0-day-exploit-for-powerpoint-snort-sigs-to-block-ppt/</guid>
		<description><![CDATA[Just 3 days after Patch Tueday, Microsoft confirms a new vulnerability in PowerPoint that will could casue complete system compromise. To be clear, this is different than the MS06-028 PowerPoint vulnerability announced on Tuesday. Snort signatures to block PPT files are available on the blog post.]]></description>
			<content:encoded><![CDATA[<p>Just 3 days after Patch Tuesday, Microsoft confirms a new vulnerability in PowerPoint that will could cause complete system compromise. To be clear, this is different than the <a target="_blank" href="http://www.microsoft.com/technet/security/bulletin/ms06-028.mspx">MS06-028 PowerPoint vulnerability</a> announced on Tuesday. There is no patch available at this time. A specially crafted PowerPoint file (.ppt) causes unknown error in the PowerPoint application. This error may be causing a buffer overflow that allows an attacker to execute code of their choice on the users computer. Reported exploits in the wild leave <a target="_blank" href="http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2006-071212-4413-99&#038;tabid=2">Trojan.PPDropper.B</a>   followed by <a target="_blank" href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-022716-2959-99">Backdoor.Bifrose.E</a>. Here is a the image you will see if you open an infected PowerPoint file.</p>
<p><img src="http://static.flickr.com/67/189742033_bc6d7b5e1d.jpg?v=0" /></p>
<p class="MsoNormal">As you can see the exploit displays Chinese writing which seems to be a clue to it&#8217;s origin. There are several similarities between how this exploit was released and how a 0-Day for Microsoft Word was released in June. Many speculate that the same person(s) are behind both.</p>
<p>Fortunately Symantec (and probably others) have virus definitions for this Trojan. The problem is it could and probably will be a different Trojan next time. Secunia is calling this one Extremely Critical in their <a target="_blank" href="http://secunia.com/advisories/21040/">write-up</a>. I agree and here are some factors that make this one very bad news.</p>
<p><strong>1. The number of vulnerable systems is very large.</strong><br />
This looks to affect all versions of Microsoft PowerPoint. Microsoft sells somewhere around $10 Billion worth of Office products per year. Folks, that is a lot of applications.</p>
<p><strong>2. Relatively few, if any vulnerabilities with PowerPoint files before.<br />
</strong>I did a quick search to see if PowerPoint files have been the entry point for vulnerabilities before and did not see any. This means in general people &#8220;trust&#8221; that opening a PPT file will not cause them problems.</p>
<p><strong>3. PowerPoint files are almost ubiquitous in the enterprise.<br />
</strong>With this being the case IT and Security managers may have to do a lot of tap dancing if they try to block PPT files at the gateway, mail server, etc. I know of one case today where the CEO had to step in and publicly support the blocking of PPT files until a resolution is available.</p>
<p>All these coupled with the usual problems like outdated AV definitions, users running as local admin, no egress filtering on the gateway&#8230;..make this a sticky situation.</p>
<p>Should you want to block PPT files and you have <a href="http://www.snort.org">Snort</a> (or a Snort-like IPS), here are some Snort signatures that will help. The first one will detect inbound PowerPoint files in an email. The second two will detect PowerPoint files on any TCP port. A big thanks to Steve Reynolds ( sreynolds @ nitrosecurity . com ) from <a target="_blank" href="http://www.nitrosecurity.com">NitroSecurity</a> for providing the signatures. These are not official NitroSecurity signatures, they are ones he wrote.</p>
<p>Although commercial IPS vendors may have signatures to detect the exploit, I have not seen any free Snort signatures that do. I suspect that <a href="http://www.bleedingsnort.com">Bleeding Snort</a> will post them if some become available.</p>
<p>Remember to have your $SMTP_SERVERS variable set correctly and change <strong>alert</strong> to <strong>drop </strong>if you want to block them.</p>
<p><strong>****NOTE****</strong>  These signatures block ALL PowerPoint attachments. You have been warned.</p>
<p class="MsoNormal"><span style="font-size: 10pt; font-family: Arial">alert TCP $EXTERNAL_NET any -> $SMTP_SERVERS 25 (msg:&#8221;PowerPoint attachment detected in SMTP&#8217;&#8221;; content:&#8221;Content-Disposition|3a|&#8221;; content:&#8221;filename=|22|&#8221;; distance:0; within:50; content:&#8221;.ppt|22|&#8221;; distance:0; within:50; nocase; classtype:suspicious-filename-detect; )</span></p>
<p><span style="font-size: 10pt; font-family: Arial">alert TCP $EXTERNAL_NET any -> $SMTP_SERVERS 25 (msg:&#8221;PowerPoint attachment detected in SMTP&#8217;&#8221;; content:&#8221;Content-Type|3a|&#8221;; content:&#8221;name=|22|&#8221;; distance:0; within:50; content:&#8221;.ppt|22|&#8221;; distance:0; within:50; nocase; classtype:suspicious-filename-detect; )</span></p>
<p><span style="font-size: 10pt; font-family: Arial">alert TCP $EXTERNAL_NET any -> $HOME_NET any (msg:&#8221;PowerPoint attachment detected&#8217;&#8221;; content:&#8221;Content-Disposition|3a|&#8221;; content:&#8221;filename=|22|&#8221;; distance:0; within:50; content:&#8221;.ppt|22|&#8221;; distance:0; within:50; nocase; classtype:suspicious-filename-detect; )</span> <span style="font-size: 10pt; font-family: Arial">alert TCP $EXTERNAL_NET any -> $HOME_NET any (msg:&#8221;PowerPoint attachment detected&#8217;&#8221;; content:&#8221;Content-Type|3a|&#8221;; content:&#8221;name=|22|&#8221;; distance:0; within:50; content:&#8221;.ppt|22|&#8221;; distance:0; within:50; nocase; classtype:suspicious-filename-detect; )</span>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/PowerPoint" rel="tag">PowerPoint</a>, <a href="http://technorati.com/tag/Vulnerability" rel="tag"> Vulnerability</a>, <a href="http://technorati.com/tag/Snort" rel="tag"> Snort</a>, <a href="http://technorati.com/tag/Exploit" rel="tag"> Exploit</a></p>
<p><strong>UPDATEÂ </strong></p>
<p>Microsoft has released an advisory on this vulnerability <a target="_blank" href="http://www.microsoft.com/technet/security/advisory/922970.mspx ">here</a></p>
<div id="crp_related"><h2>Related Posts:</h2><ul><li><a href="http://www.infosecpodcast.com/2006/09/info-on-ie-0-day-with-snort-sig/" rel="bookmark" class="crp_title">Info on IE 0-Day with Snort sig</a></li><li><a href="http://www.infosecpodcast.com/2007/03/social-engineering-search-engines-and-the-massachusetts-rmv/" rel="bookmark" class="crp_title">Social Engineering, Search Engines and the Massachusetts RMV</a></li><li><a href="http://www.infosecpodcast.com/2006/07/exploits-in-the-wild-for-recent-microsoft-vulnerabilities/" rel="bookmark" class="crp_title">Exploits in the wild for recent Microsoft vulnerabilities</a></li><li>Powered by <a href="http://ajaydsouza.com/wordpress/plugins/contextual-related-posts/">Contextual Related Posts</a></li></ul></div><img src="http://www.infosecpodcast.com/?ak_action=api_record_view&id=8&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2006/07/0-day-exploit-for-powerpoint-snort-sigs-to-block-ppt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
