All the latest UK technology news, reviews and analysis

Evasion tool puts Snort's nose out of joint

by James Middleton

17 Apr 2002

Be the first to comment

  • Tweet this

The darling of the intrusion detection system (IDS) industry had its nose put out of joint yesterday when a security developer released an evasion tool capable of undermining it.

Open source development Snort has been heralded as one of the most flexible IDS offerings, comparing well with alternative commercial products.

But the release of a security testing tool on Security Focus' IDS Focus mailing list yesterday may have opened up a method of sneaking past Snort.

Developer Dug Song yesterday released Fragroute, a tool which claims to "intercept, modify and rewrite outbound traffic destined for a specified host, implementing most of the attacks described in the Secure Networks Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection paper".

Song explained that the tool uses a simple rule set language to "delay, duplicate, drop, fragment, overlap, print, reorder, segment, source-route and otherwise monkey around with all outbound packets destined for a target host".

He said that the tool was "written in good faith to aid in the testing of network intrusion detection systems, firewalls and basic TCP/IP stack behaviour. Please do not abuse this software." But as is the case with such tools it may only be a matter of time before evil hackers are using it.

Another reader on the IDS Focus list said that Fragroute could be used to "totally blindside" Snort.

"The Readme.snort file contains several Fragroute scripts which blindside even the current Snort version, tested on RedHat 7.2. For example, the latest wu-ftpd exploits don't trigger any Snort alerts at all," he said.

According to reports, Fragroute can be a "very powerful" tool, but its effectiveness may not just be limited to Snort. It could potentially be used to test, and therefore attack, other IDS systems.

More info on Fragroute can be found here.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

36%

0%

10%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Software Developers - London Start-up

Start-up company in West London are looking for a number...

Telephony/Media Software Developer

This team is responsible for developing and running carrier...

Graduate Mathematical Modeller

Graduate Mathematical Modelling position focused on research...

Software Engineers – Network programming

Working on real projects and real high performance software...

To send to more than one email address, simply separate each address with a comma.