OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Karalon test report on Snort

From: Abhishek Bhuyan (abhuyangmail.com)
Date: Wed Sep 05 2007 - 15:02:12 CDT


Surya,
Detection capabilities will depend how good the signatures are written
(also depends what all functionality are there). Karalon most of the
time provide packet capture which are exploit specific. Or say run
metasploit, take packet capture with all encoders and test. Just
because your IDS would detect all karalon coverage won't mean thats
good enough.

-Abhishek
On 8/30/07, Surya Batchu <suryak_batchuyahoo.com> wrote:
> Hi,
>
> Karalon Traffic IQ Pro can be used to test attack/exploit detection capabilities of IDS/IPS systems. I am interested in knowing SNORT IDS detection capabilities and its coverage when Traffic IQ Pro system is used. Any reports in public domain?
>
> Thanks
> Surya
>
>
> ____________________________________________________________________________________
> Fussy? Opinionated? Impossible to please? Perfect. Join Yahoo!'s user panel and lay it on us. http://surveylink.yahoo.com/gmrs/yahoo_panel_invite.asp?a=7
>
>
> ------------------------------------------------------------------------
> Test Your IDS
>
> Is your IDS deployed correctly?
> Find out quickly and easily by testing it
> with real-world attacks from CORE IMPACT.
> Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
> to learn more.
> ------------------------------------------------------------------------
>
>

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
to learn more.
------------------------------------------------------------------------