{"id":43,"date":"2005-08-05T19:38:54","date_gmt":"2005-08-06T02:38:54","guid":{"rendered":"http:\/\/outflux.net\/blog\/archives\/2005\/08\/05\/defcon-13-patch-round-up\/"},"modified":"2005-08-05T20:15:46","modified_gmt":"2005-08-06T03:15:46","slug":"defcon-13-patch-round-up","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2005\/08\/05\/defcon-13-patch-round-up\/","title":{"rendered":"defcon 13 patch round-up"},"content":{"rendered":"<p>In (useless) preparation for DefCon 13&#8217;s CTF this year, I hacked at <a href=\"http:\/\/ettercap.sourceforge.net\/\">ettercap<\/a> and <a href=\"http:\/\/www.snort.org\/\">Snort<\/a>.  Since the TTL filtering trick was out of the bag, I figured I&#8217;d implement the other idea I had.  Since the score bot generally is a short-lived connection to a service in CTF, it would be great if Snort-inline rules could be written to detect how long a conenction had been around for.  Initially I hacked at ettercap, but that was mostly so I could build a quick-and-dirty <a href=\"http:\/\/outflux.net\/software\/patches\/ettercap-ttl_watch.patch\">TTL statistics gatherer<\/a>.  In ettercap, I had to add <a href=\"http:\/\/outflux.net\/software\/patches\/ettercap-conntrack_age.patch\">session time tracking<\/a>, but in Snort, it was actually already there.  There just wasn&#8217;t anything that could be matched against in the rules section.  I lifted the TTL matcher from Snort and just used the existing connection timers to do the work and <a href=\"http:\/\/outflux.net\/software\/patches\/snort-age.patch\">created the &#8220;age&#8221; rule<\/a>.  Works like a charm.  I hope they take my patches.<\/p>\n<p style='text-align:left'>&copy; 2005, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>In (useless) preparation for DefCon 13&#8217;s CTF this year, I hacked at ettercap and Snort. Since the TTL filtering trick was out of the bag, I figured I&#8217;d implement the other idea I had. Since the score bot generally is a short-lived connection to a service in CTF, it would be great if Snort-inline rules [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/43"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=43"}],"version-history":[{"count":0,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/43\/revisions"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=43"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=43"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=43"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}