Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



IDS: Re: ForeScout ActiveScout (was: Re: Intrusion Prevention)

Re: ForeScout ActiveScout (was: Re: Intrusion Prevention)

From: Dug Song <dugsong_at_monkey.org>
Date: Tue, 17 Dec 2002 14:27:10 -0500

On Tue, Dec 17, 2002 at 12:48:27PM -0500, Matthew L. McGuirl wrote:

> They "shine" because as far as I can tell, they're correlating their
> own data with their own data. This magical "mark" they stamp on the
> prober is unlikely to be more than something like a dummy username &
> password combination that gets stored in their database. When their
> IDS module sees a packet come in bearing this dummy data they can
> detect it regardless of its source IP.

just a new twist on an old idea:

http://lists.insecure.org/lists/nmap-hackers/1999/Jan-Mar/0279.html

-d.

---
http://www.monkey.org/~dugsong/
Received on Dec 17 2002
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos