Solved

How about DOS rule of Snort?

Posted on 2009-07-15
6
967 Views
Last Modified: 2013-11-29
I install ok Snort + IDSCenter + Winpcap
OS: w2003

Snort run well, but I have not rule for DOS HTTP
my server run IIS
I 'attack' DOS by sending 1000 query/s to home page, but Snort not recorgnize DOS

What about DOS rules for snort ?

Thanks!
0
Comment
Question by:sunwsposelr60068
  • 3
  • 2
6 Comments
 
LVL 7

Expert Comment

by:Phateon
ID: 24869768
This is an old .conf file, but you might try it - http://www.0xdeadbeef.info/conf/snort.conf.190
0
 

Author Comment

by:sunwsposelr60068
ID: 24875505
I tried, not success, because have not RULE files, only configfile?
0
 
LVL 7

Expert Comment

by:Phateon
ID: 24877346
Yes. It is a config file.
0
 

Author Comment

by:sunwsposelr60068
ID: 24877715
but how about rules to recorgnize DOS HTTP?
0
 
LVL 7

Accepted Solution

by:
Phateon earned 250 total points
ID: 24877738
From the .conf file:
#########################################################
# Section #1 (Variables): Service ports
#
# This allows Snort to look for attacks directed to a
# specific application only on the ports that it runs on.
# This also improves overall performance of Snort.
#
# Ports you run Web servers on
var HTTP_PORTS 80
# Ports you want to look for shellcode on.
var SHELLCODE_PORTS !$HTTP_PORTS
# Ports you run Oracle servers on
var ORACLE_PORTS 1521

#########################################################
# Section #1 (Variables): Service ports
#
# This allows Snort to look for attacks directed to a
# specific application only on the ports that it runs on.
# This also improves overall performance of Snort.
#
# Ports you run Web servers on
var HTTP_PORTS 80
# Ports you want to look for shellcode on.
var SHELLCODE_PORTS !$HTTP_PORTS
# Ports you run Oracle servers on
var ORACLE_PORTS 1521

#########################################################
# Section #2 (Preprocessors): stream4
#
# Stateful inspection and stream reassembly for Snort.
# This preprocessor defeats stick/snot attacks against
# TCP rules and can statefully detect various portscan
# flavours, TCP fingerprinting, and more (see original
# snort.conf for further details). You can safely turn
# off "detect_scans" if you feel it's too noisy.
#
preprocessor stream4: detect_scans, disable_evasion_alerts
preprocessor stream4_reassemble


#########################################################
# Section #2 (Preprocessors): http_decode
#
# HTTP traffic normalizer. This preprocessor normalizes
# HTTP requests by converting any %XX character to his
# ASCII equivalent. Now supports unicode, iis_alt_unicode,
# double_encode, iis_flip_slash and full_whitespace
# (see original snort.conf for further details).
#
preprocessor http_decode: 80 unicode iis_alt_unicode double_encode iis_flip_slash full_whitespace
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
New firewall implementation guidance 12 89
Creating a Vendor Admin user 23 80
ASP server side get value 15 35
CDC and AOG on MS SQL 2012 13 23
Knowing where your website is hosted is as important as the features you receive, the monthly fee, and the support you receive. Due diligence should be done when choosing your next hosting provider.
Most MSPs worth their salt are already offering cybersecurity to their customers. But cybersecurity as a service is wide encompassing and can mean many things.  So where are MSPs falling in this spectrum?
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question