Snort security holes and strategies for safe network monitoring

Wednesday, 4 June 2003, 3:50 PM EST

In April, a CERT advisory announced the discovery of two separate buffer-overflow vulnerabilities in Snort, a popular security-monitoring tool used for detecting suspicious network activities. This development was disturbing and ironic: system administrators install and run programs like Snort to improve security, and don't often consider the possibility that the tools themselves might be attacked and exploited to create entirely new security holes. It's therefore important to understand precisely what happened here, especially since the same mechanisms used against Snort could threaten other security tools.

In this article, I will review the attacks that have been launched against Snort in the past, as well as the recent (and more serious) buffer overflows. In each case, I'll discuss the ways Snort developers have responded to the attacks, and the strategies system administrators can take to minimize the risks. Furthermore, I'll show that Snort's vulnerabilities extend to other security-monitoring tools, implying that we need to be careful when we use them, as well. Finally, I'll summarize techniques to do just that: secure monitoring.

[ Read more ]

Related items




Spotlight

Patching: The least understood line of defense

Posted on 29 August 2014.  |  How many end users, indeed how many IT pros, truly get patching? Sure, many of us see Windows install updates when we shut down our PC and think all is well. Itís not.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Tue, Sep 2nd
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //