6.7 6000 Series—Cross-Protocol Signatures
6.7.8 Loki attack signatures
The following are Loki attack signatures:
  • 6300—Loki ICMP tunnel (severity 5, access): Loki is a tool designed to run an interactive session that is hidden within ICMP traffic. An attacker needs to first gain root on a system, but can then set up a Loki server (lokid) as a backdoor. This can provide future command line access hidden as ICMP traffic, which can be encrypted. This signature will fire if the original Loki that was distributed in Phrack Issue 51 is implemented.
  • 6302—Modified Loki ICMP tunneling (severity 5, access): Loki is a tool designed to run an interactive session that is hidden within ICMP traffic. An attacker needs to first gain root access on a system, but can then set up a Loki server (lokid) as a backdoor. This can provide future command line access hidden as ICMP traffic, which can be encrypted. This signature will trigger on Loki even if certain user-configurable options have been modified.