<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SHELLCODE x86 NOOP, Snort alert, what would you do? in Secure OS Software for Linux</title>
    <link>https://community.hpe.com/t5/secure-os-software-for-linux/shellcode-x86-noop-snort-alert-what-would-you-do/m-p/3467016#M393</link>
    <description>Snort is telling you that someone connected and sent you a NOOP sled to shellcode, used in buffer overflow exploits.  The thing I would do is look up where the IP address is registed, in this case:&lt;BR /&gt;&lt;BR /&gt;styx:~$ whois 207.218.97.235&lt;BR /&gt;&lt;BR /&gt;OrgName:    Global Crossing&lt;BR /&gt;OrgID:      GBLX&lt;BR /&gt;Address:    14605 South 50th Street&lt;BR /&gt;City:       Phoenix&lt;BR /&gt;StateProv:  AZ&lt;BR /&gt;PostalCode: 85044-6471&lt;BR /&gt;Country:    US&lt;BR /&gt;&lt;BR /&gt;Then I'd give them a call/email and tell them about the logs, usually they drop the hammer for you.  If you see a lot of traffic from this IP you'll wanna deep six it at your perimeter router.&lt;BR /&gt;&lt;BR /&gt;--Dave&lt;BR /&gt;</description>
    <pubDate>Thu, 20 Jan 2005 20:17:46 GMT</pubDate>
    <dc:creator>Dave Falloon</dc:creator>
    <dc:date>2005-01-20T20:17:46Z</dc:date>
    <item>
      <title>SHELLCODE x86 NOOP, Snort alert, what would you do?</title>
      <link>https://community.hpe.com/t5/secure-os-software-for-linux/shellcode-x86-noop-snort-alert-what-would-you-do/m-p/3467015#M392</link>
      <description>Hello,&lt;BR /&gt;I have an entry in my Snort log that looks like this:&lt;BR /&gt;&lt;BR /&gt;SHELLCODE x86 NOOP [**] [Classification: Executable code was detected] [Priority: 1] {TCP} 207.218.97.235:3415 -&amp;gt; My_IP_Address:80&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Beside the obvious like keeping software up-to-date, what would you do to respond to these kinds of activities?&lt;BR /&gt;&lt;BR /&gt;Would you block 207.218.97.0/22 ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;What else?&lt;BR /&gt;&lt;BR /&gt;Thanks.</description>
      <pubDate>Wed, 19 Jan 2005 19:51:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/secure-os-software-for-linux/shellcode-x86-noop-snort-alert-what-would-you-do/m-p/3467015#M392</guid>
      <dc:creator>david lang_2</dc:creator>
      <dc:date>2005-01-19T19:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: SHELLCODE x86 NOOP, Snort alert, what would you do?</title>
      <link>https://community.hpe.com/t5/secure-os-software-for-linux/shellcode-x86-noop-snort-alert-what-would-you-do/m-p/3467016#M393</link>
      <description>Snort is telling you that someone connected and sent you a NOOP sled to shellcode, used in buffer overflow exploits.  The thing I would do is look up where the IP address is registed, in this case:&lt;BR /&gt;&lt;BR /&gt;styx:~$ whois 207.218.97.235&lt;BR /&gt;&lt;BR /&gt;OrgName:    Global Crossing&lt;BR /&gt;OrgID:      GBLX&lt;BR /&gt;Address:    14605 South 50th Street&lt;BR /&gt;City:       Phoenix&lt;BR /&gt;StateProv:  AZ&lt;BR /&gt;PostalCode: 85044-6471&lt;BR /&gt;Country:    US&lt;BR /&gt;&lt;BR /&gt;Then I'd give them a call/email and tell them about the logs, usually they drop the hammer for you.  If you see a lot of traffic from this IP you'll wanna deep six it at your perimeter router.&lt;BR /&gt;&lt;BR /&gt;--Dave&lt;BR /&gt;</description>
      <pubDate>Thu, 20 Jan 2005 20:17:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/secure-os-software-for-linux/shellcode-x86-noop-snort-alert-what-would-you-do/m-p/3467016#M393</guid>
      <dc:creator>Dave Falloon</dc:creator>
      <dc:date>2005-01-20T20:17:46Z</dc:date>
    </item>
  </channel>
</rss>

