<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Sourcefire on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/sourcefire/</link>
    <description>Recent content in Sourcefire on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Sat, 18 Oct 2014 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/sourcefire/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>A “Please, Don’t Waste my Time” Approach and the Sourcefire/Snort Evasion</title>
      <link>https://insinuator.net/2014/10/a-please-dont-waste-my-time-approach-and-the-sourcefire/snort-evasion/</link>
      <pubDate>Sat, 18 Oct 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/10/a-please-dont-waste-my-time-approach-and-the-sourcefire/snort-evasion/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Yesterday we (Rafael Schaefer, Enno and me) had the pleasure to deliver together our talk at BlackHat Europe 2014 named &lt;a href=&#34;https://www.blackhat.com/eu-14/briefings.html#evasion-of-high-end-idps-devices-at-the-ipv6-era&#34;&gt;Evasion of High-End IDPS Devices at the IPv6 Era&lt;/a&gt; (by the way, latest slides can be found &lt;a href=&#34;https://www.ernw.de/download/Atlasis_Rey_Schaefer_BHEU_2014_Evasion_of_HighEnd_IPS_Devices.pdf&#34;&gt;here&lt;/a&gt; and the white paper &lt;a href=&#34;https://www.ernw.de/download/eu-14-Atlasis-Rey-Schaefer-briefings-Evasion-of-HighEnd-IPS-Devices-wp.pdf&#34;&gt;here&lt;/a&gt;). In this talk we summarised all the IDPS evasion techniques that we have found so far. At previous blogposts I had the chance to describe how to evade &lt;a href=&#34;http://www.insinuator.net/2014/08/evading-idps-by-combining-ipv6-extension-headers-and-fragmentation-features-the-story-of-my-life/&#34;&gt;Suricata&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2014/05/a-novel-way-of-abusing-ipv6-extension-headers-to-evade-ipv6-security-devices/&#34;&gt;TippingPoint&lt;/a&gt;. In this post I am going to describe some other techniques that can be used to evade &lt;a href=&#34;https://www.snort.org/&#34;&gt;Snort&lt;/a&gt;, and its companion commercial version, &lt;a href=&#34;http://www.sourcefire.com/&#34;&gt;Sourcefire&lt;/a&gt;. The tool used to evade these IDPS is –  what else – &lt;a href=&#34;http://www.insinuator.net/2014/10/chiron-an-all-in-one-ipv6-penetration-testing-framework/&#34;&gt;Chiron&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
