• On MovieTome: Megan Fox on TRANSFORMERS 2!

February 21, 2007 6:22 AM PST

Open-source intrusion detector found to be flawed

Snort, the open-source intrusion-detection software, is vulnerable to hackers, its developers said this week.

Snort's popularity has grown as many businesses have been tempted away from expensive proprietary intrusion-detection systems. Advocates of Snort argue that it is more secure than products created by network gear makers such as Cisco Systems because its code is open for developers to both find and fix flaws.

But on Monday, Sourcefire, the company behind Snort, said that hackers could potentially execute malicious code on a system running Snort and gain access to confidential data.

The vulnerability was reported to Sourcefire by Internet Security Systems, the security arm of IBM.

Reporting the weakness, an Internet Security Systems report said: "Snort IDS and Sourcefire Intrusion Sensor (intrusion-detection/prevention system) are vulnerable to a stack-based buffer overflow, which can result in remote code execution?Compromise of machines using affected versions of Snort or Sourcefire may lead to exposure of confidential information, loss of productivity and further compromise. Successful exploitation of this vulnerability results in remote code execution with the privilege level of Snort, usually root or system."

Internet Security Systems said the following products are affected: Snort 2.6.1, 2.6.1.1, and 2.6.1.2; Snort 2.7.0 beta 1; Sourcefire Intrusion Sensors versions 4.1.x, 4.5.x, and 4.6.x with SEUs prior to SEU 64; Sourcefire Intrusion Sensor Software for Crossbeam versions 4.1.x, 4.5.x and 4.6.x with SEUs prior to SEU 64

Those using version 2.6.1, 2.6.1.1 or 2.6.1.2 should upgrade to 2.6.1.3, which is not vulnerable, Snort said. Users of version 2.7 should disable the DCE/RPC preprocessor, the program that contains the vulnerability. Version 2.7 is currently in beta, and the issue will be resolved in a second beta version, Snort said.

Richard Thurston of ZDNet UK reported from London.

See more CNET content tagged:
Snort, Sourcefire Inc., Internet Security Systems Inc., hacker, vulnerability

Add a Comment (Log in or register) 1 comment
The flaws in IDSolutions
by Schratboy February 22, 2007 11:26 AM PST
What a hoot! All the technology in the world won't make your network safe as long as everyone continues to "react" to all the known threats. Go ahead and spend tons of money on Sourcefire or any other type of technology, put it in a closet and believe that you're secure. The simplest and most innocuous stuff is what topples the smartest and cockiest among the IT gods. A small stone took Goliath's arse and so too today the small non-rule-based crap is what fouls up all the brilliant technology as well as all the sycophantic believers that think it will do their jobs for them....Suckersssssss...... Ahem...Sorry about the hubris.
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right