Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Signature & CVE id for Pyloris

Posted on 2014-09-17
1
Medium Priority
?
213 Views
Last Modified: 2014-10-04
https://cve.mitre.org/find/index.html   will give a CVE id for Slowloris
but not Pyloris.

Trendmicro 'approximated' that one of their IPS signature
“1003598 - Multiple HTTP Server Low Bandwidth Denial Of Service”
deals with both Slowloris & Pyloris.

I used the term 'approximated' because in Trend's signature database,
there is no equivalent CVE id for this signature while most of their
other signatures has a CVE id.

Q1:
Anyone know if Pyloris has a CVE id & what is the id?

Q2:
Does TippingPoint has a signature (or in HP's term, it's called
'Digital Vaccine') for Pyloris?   We found one for Slowloris but
not Pyloris

Q3:
As TrendMicro's host-based IPS (ie sit inside the servers) has
only one signature to deal with both Slowloris & Pyloris, can
I by the same token, reckon that TippingPoint's vaccine which
deal with Slowloris is likely to be able to deal with Pyloris by
tracking/blocking  "Low Bandwidth DoS" ?  Reason is we can't
locate any vaccine (or signature) in TippingPoint that specifically
deals with Pyloris.  TrendMicro must have run into the same
situation that they use only one signature for both threats.

I'm suspecting it's the behavior/characteristics of both
Pyloris & Slowloris not to take up much bandwidth that
they have a common signature for TrendMicro's IPS
0
Comment
Question by:sunhux
1 Comment
 
LVL 62

Accepted Solution

by:
gheist earned 2000 total points
ID: 40328539
CVE records vulnerabilieties, not exploits.
You can write same in shell script if you want, not python.
0

Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, WatchGuard's Director of Security Strategy and Research Teri Radichel, takes a look at insider threats, the risk they can pose to your organization, and the best ways to defend against them.
Spectre and Meltdown, how it affects me and my clients?
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…

581 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question