Downloads
Downloads
Downloads Home » Presentations
DocumentsDate added
-
Attack/Defend 1: DCOM, WebDAV, TTYPROMPThot!
- 14.08.2003
- The first in perhaps a series of presentations which show common attacks along with detailed, annotated network traces. This gives a perspective on both sides of a network intrusion. The attacks are shown step-by-step, and the network traces are examined and explained at a high level. This zip file includes the actual ethereal log files and explains how to use filters to isolate important data from those log files. I try to remain technically agnostic in this presentation so technical and non-technical readers can benefit. This first installment of Attack-Defend looks at quiet and noisy nmap scans, a high-end vulnerability scanner (www.heatscanner.com), the Solaris TTYPROMPT telnet bypass (tool-less!), the Microsoft Webdav overflow, and the Microsoft RPC DCOM overflow (the attack used in the August 2003 LoveSan/Msblaster/DCOM worm!)
- Hits: 13995
-
Passive Information Gathering - The Risk of the Silent Attackerhot!
- 15.04.2000
- The risk of the silent attacker. I wrote this paper for a "SANS at Night" presentation in D.C.
- Hits: 10482