iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > Snort Vulnerable To Back Orifice Packets
Search:
[ insider_reports_insider ]

Snort Vulnerable To Back Orifice Packets



David Utter
Staff Writer
2005-10-19

SecurityProNews: Insider Reports Insider Reports RSS Feed


ISS X-Force has reported the Snort intrusion detection system is vulnerable to a stack-based overflow when parsing Back Orifice packets.

Snort Vulnerable To Back Orifice Packets
Beware Of Unwanted Packets

Versions of Snort from 2.4.0 on could be fully compromised when processing a single UDP packet. Once compromised, a Snort sensor would likely give the attacker full root or admin privileges. ISS noted that default installations of Snort possess the vulnerability.

"When determining the direction (to or from server) of a BO packet, a stack-based overflow can be triggered by an attacker," ISS said in its alert.

The alert about the issue with Snort's Back Orifice pre-processor notes how the UDP packet can bypass firewalls and enter a network by virtually any open port. All an attacker would have to do is to blast packets at a network. If a vulnerable Snort sensor picks up the packet, the exploit would be triggered.

"Due to the trivial nature of this vulnerability and its potential to bypass perimeter firewalls, there is grave concern that this issue might be exploited as part of a network-based worm. X-Force urges all affected users to upgrade immediately," the company said.

Sourcefire has already released version Snort 2.4.3 for users of the open source version. Users may be able to disable Snort's Back Orifice preprocessor by editing snort.conf and commenting out the relevant line:

# preprocessor bo

The US CERT team has also provided an alert about the vulnerability.








About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds