exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Suricata IDS / IPS 3.2.x / 3.1.x IPv4 Evasion

Suricata IDS / IPS 3.2.x / 3.1.x IPv4 Evasion
Posted Feb 16, 2017
Authored by Jeremy Beaume

Suricata IDS / IPS versions 3.2.x before 3.2.13.13 and versions 3.1.3 and below suffered from an issue with IPv4 evasion.

tags | advisory
SHA-256 | ae4d50e6dd5d0d4d2b0cfb7661192e3225d3bededae3434f440a38ff2641bf79

Suricata IDS / IPS 3.2.x / 3.1.x IPv4 Evasion

Change Mirror Download
Here are the details of the (patched) IPv4 evasion I found in Suricata IDS/IPS:

# Software
Suricata IDS/IPS
website : https://suricata-ids.org/
editor : Open Information Security Foundation (OISF) https://oisf.net/

# Impacted version

3.2.x before 3.2.13.13
3.1.3 and before

All execution mode are impacted : nfqueue, af-packet, ...

# Vulnerability description

Suricata did not used the IP protocol field value to identify
fragments from a same packet, whereas the RFC 791 states that 2
fragments should be defragmented together only if the protocol
field have the same value.
This flaw makes it possible to craft a packet that will only
be defragmented by Suricata (and not the destination host), leading to
a packet injection in the IDS detection engine.

# Impact on security

An attacker can fully evade any TCP signature, without any logs / alerts.

# Resources and links :

New patched Suricata versions :
https://suricata-ids.org/2017/02/15/suricata-3-2-1-available/
https://suricata-ids.org/2017/02/15/suricata-3-2-1-available/

Bug tracker and patch commit :
https://redmine.openinfosecfoundation.org/issues/2019
https://github.com/inliniac/suricata/commit/4a04f814b15762eb446a5ead4d69d021512df6f8

# Thanks and note

I'd like to give a special thanks to the suricata development team and
especially Victor Julien : I contacted him concerning the issue, got an answer
the same day, and it was corrected on github 2 working days after.
Really impressive guys.

If anyone needs more information about this, feel free to contact me at
jeremy [dot] beaume (a) protonmail [dot] com

Cheers !
Jeremy BEAUME


Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close