ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Enterprise applications Toolkit

New tool camouflages hacker programs

Published: 22 Apr 2002 09:11 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new tool for manipulating packets of data that travel over the Internet could allow attackers to camouflage malicious programs just enough to bypass many intrusion-detection systems and firewalls.

The tool, called Fragroute, performs several techniques to fool the signature-based recognition systems used by many intrusion-detection systems and firewalls. Many of these duping techniques were outlined in a research paper published four years ago.

Arbor Networks security researcher Dug Song posted the tool to his Web site this week. Arbor is a network protection company.

"(Some) firewalls and intrusion prevention or other application-layer content-filtering devices have similar vulnerabilities that may be tested with Fragroute," Song wrote in a posting to security mailing list Bugtraq on Thursday.

The new tool tips the arms race between those who look to break in to networks and those who defend them toward the attackers, at least for the moment. Any firewall or intrusion-detection system that fails the Fragroute test is vulnerable attack from vandals using the program.

Song was travelling and could not be reached for comment, an Arbor representative said, and his company would not comment on the issue.

The Fragroute program is a dual-use program: It illuminates weaknesses in a network's security -- information that can aid a system administrator in protecting the network or helping a hacker attack the network. The program exploits several ways of inserting specific data into a sequence of information to fool detection programs. The methods were highlighted in a January 1998 paper written by Thomas Ptacek and Timothy Newsham of security specialist Secure Networks, a company later bought by Network Associates.

The program exploits intrusion-detection systems, which often check the correctness of incoming data less stringently than the server software that is typically targeted by hackers. In one version of such "insertion" attacks, a command sent to a server could be disguised by adding extraneous, illegitimate data. The targeted server software will throw away any bad data, leaving itself with a valid, but malicious, command.

However, many intrusion-detection systems don't remove the corrupted data, so the hostile command remains disguised from the system's recognition functions.

For example, an intrusion-detection system that watches out for a recent buffer overflow might recognise the attack by the text "http:///" appearing in the incoming data. However, if an attacker sends "http://somegarbagehere/" and knows that the "somegarbagehere" portion will be thrown out by the target computer, then the attack still works. Moreover, if the intrusion-detection system doesn't remove the same text portion as the server, it won't recognise the threat.

Marti Roesch, president of security appliance seller SourceFire and the creator of the popular open-source intrusion-detection system Snort, said that the majority of the problems exploited by Fragroute have been fixed, and he plans to fix the rest by next week.

"Dug contacted me about this stuff several months ago, and I fixed it," Roesch said.

While he hasn't programmed a defence to every stealth attack that Fragroute has in its repertoire, doing so won't be hard, he added.

"Many of these take 10 minutes of coding, max, to fix," he said. "It just wasn't an issue before."

While many of the attacks won't work against Snort if it's configured properly, Roesch said that the default configuration doesn't detect the camouflaged data, because such settings produce a far greater number of false alarms.

Some security aficionados posting to the Bugtraq list concentrated on Snort as a program vulnerable to the Fragroute program, but Song waved off the implied criticism on the open-source program in his posting.

"Snort, I'd wager, does much better than most," he wrote, adding that many other proprietary programs are also vulnerable.

One commercial software seller, network protection firm Internet Security Systems, claimed that its product, RealSecure, wasn't affected.

"We initially fixed the fragmentation issues when we saw the paper quite some time ago," said Dan Ingevaldson, team lead for the company's security research and development group.

His group tested Song's tool earlier this week, and they were still able to detect attacks, Ingevaldson said.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
35 out of 82 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

CCNA/CCNP Cisco Engineer - Routers/Switches/Firewalls - Bath

The ideal candidate will have a skill set to include as many of the following: CCNA or CCNP certified, Routers, Catalyst Switches 29xx, 35xx and ...

JAVA recognition! 38,000 to 40,000 North West

Gifted JAVA developers North West. The leading distributor of software products to the service industry currently seeks gifted Java developers to add ...

Birmingham/Coventry - Cisco Security - Firewalls - 40k-45k basic

You will need to hold experience in Firewalls ideally PIX/ASA whilst holding skills within routing and switching. My Birmingham based client located ...

Featured Talkback

The internet is going to have do a lot of maturing before it is ready for this kind of traffic. Security is always going to be a problem, connectivity is poor, and most business's are unwilling for their employees to have open access.

By: ator1940

Read full story:
Microsoft prepares to take Office online