|
From: Michal Zalewski <lcamtuf@coredump.cx>
Date: Thu May 27 2004 - 19:48:21 EDT
On Thu, 27 May 2004, Alexander E. Cuttergo wrote:
> If the attacker is on the same LAN as your IDS, you have many problems
In a sufficiently complex network, you are going to face internal threats.
I would not even bother to post if IDSes were not commonly used in such a
> More generally, if you can send a packet which is accepted by the IDS
You won't be able to do this in a reasonable IDS setup (span port or
> A packet which is not accepted by the recipient will not elicit an ACK
One that is does not have to do this, either. Window size, etc.
--
------------------------- bash$ :(){ :|:&};: --
Michal Zalewski * [http://lcamtuf.coredump.cx]
Did you know that clones never use mirrors?
--------------------------- 2004-05-28 00:04 --
http://lcamtuf.coredump.cx/photo/current/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Received on Fri May 28 00:11:10 2004
This archive was generated by hypermail 2.1.8 : Fri May 28 2004 - 01:01:07 EDT |
Custom Search
|