Figure 332 Custom Signature Example Pattern 1; Figure 333 Custom Signature Example Pattern 2; Figure 334 Custom Signature Example Patterns 3 And 4 - ZyXEL Communications Unified Security Gateway ZyWALL 1000 User Manual

Unified security gateway
Hide thumbs Also See for Unified Security Gateway ZyWALL 1000:
Table of Contents

Advertisement

Chapter 29 IDP
29.10.2.2 Analyze Packets
Then use a packet sniffer such as TCPdump or Ethereal to investigate some more.
From the NetBIOS header you see that the first byte '00' defines the message type. The next
three bytes represent the length of data, so you can ignore it. Therefore enter |00| as the first
pattern.

Figure 332 Custom Signature Example Pattern 1

Next, check the content of the SMB header. Add |FF|SMB% and 'TransactionNmPipe' to the
signature as the next patterns.

Figure 333 Custom Signature Example Pattern 2

Figure 334 Custom Signature Example Patterns 3 and 4

Our final custom signature should look like as shown in the following figure.
If the attack occurs, check the logs for a log of your custom signature. This indicates the
signature works correctly.
440
ZyWALL USG 1000 User's Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall usg 1000

Table of Contents