The following are Loki attack signatures:
- 6300—Loki ICMP tunnel (severity 5,
access): Loki is a tool designed to run an interactive session
that is hidden within ICMP traffic. An attacker needs to first
gain root on a system, but can then set up a Loki server (lokid)
as a backdoor. This can provide future command line access hidden
as ICMP traffic, which can be encrypted. This signature will fire
if the original Loki that was distributed in Phrack Issue 51 is
implemented.
- 6302—Modified Loki ICMP tunneling
(severity 5, access): Loki is a tool designed to run an
interactive session that is hidden within ICMP traffic. An
attacker needs to first gain root access on a system, but can then
set up a Loki server (lokid) as a backdoor. This can provide
future command line access hidden as ICMP traffic, which can be
encrypted. This signature will trigger on Loki even if certain
user-configurable options have been modified.
|
|