ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Back Orifice problems lead to pain for Snort

Dawn Kawamoto CNET News.com

Published: 27 Oct 2005 09:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

An exploit has been published that could take advantage of a flaw in Snort, a popular open source intrusion protection system, according to a security group.

The exploit code, published on the Web by FrSirt on Tuesday, demonstrates how vulnerabilities in a Snort sensor designed to detect an exploit tool called Back Orifice can be subject to a buffer overflow attack. Back Orifice is used by remote intruders to take control of compromised systems.

Last week, security experts warned of flaws in systems running Snort 2.4.0 and higher. The vulnerabilities could allow an attacker to send a malicious packet through a network that is using Snort to guard against Back Orifice.

Available for free, Snort software is estimated to have more than 100,000 active users, according to figures from Sourcefire, the software's developer. Sourcefire has issued a patch, Snort version 2.4.3, to address the problem. Sourcefire also advised people to disable the Back Orifice preprocessor in Snort if they are running it on vulnerable versions of the software.

Meanwhile, a tool to guard against the exploit has also been developed by an incident handler at the Internet Storm Center, which tracks network threats.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
54 out of 102 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Statistical Programmer - Sponsor Co. South East.

Program, according to specifications, analysis datasets, pooled datasets, listing tables and figures for phase I-IV trials. SAS, programming, SAS ...

Technical Autor- Media and Entertainment

Huxley Associates reputable Media and Entertainment client require a technical author who is experienced at liaising with subject matter experts ...

IBM Maximo Solution Architect

Be capable of proactively engaging subject matter experts from various organisations (including IBM) as a means to deliver a complete vision of the ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment