lostriver has asked for the wisdom of the Perl Monks concerning the following question:
Regexes will not cut it... Will Parse::RecDescent help? Any other way? Thanks.("TELNET:OVERFLOW:OPTIONS-REPLY" :info ( :english ( :name ("TELNET:OVERFLOW:OPTIONS-REPLY") :long_name ("TELNET Options Overflow (Response +)") :description ("This signature detects attempts + to exploit a known vulnerability against the BSD-based TELNET daemon. The option processing function (telrcv) in the daemon produces responses w +ith a fixed size buffer, but does not perform bounds checking. Attackers c +an send a combination of TELNET protocol options to the daemon to overflo +w the buffer and execute arbitrary commands.") ) ) :color (red) :severity (5) :category (TELNET) :keywords ("telnet dangerous command bin") )
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Tricky parsing.
by ikegami (Patriarch) on Mar 17, 2006 at 00:15 UTC | |
|
Re: Tricky parsing.
by saintmike (Vicar) on Mar 17, 2006 at 00:18 UTC | |
|
Re: Tricky parsing.
by zer (Deacon) on Mar 17, 2006 at 00:48 UTC | |
|
Re: Tricky parsing.
by zer (Deacon) on Mar 16, 2006 at 23:58 UTC | |
by lostriver (Initiate) on Mar 17, 2006 at 00:06 UTC |