This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Buffer Overflow Attempts
Original Source:
[Sigma source]
Title:
Buffer Overflow Attempts
Status:
test
Description:
Detects buffer overflow attempts in Unix system log files
References:
-https://github.com/ossec/ossec-hids/blob/1ecffb1b884607cb12e619f9ab3c04f530801083/etc/rules/attack_rules.xml
-https://docs.oracle.com/cd/E19683-01/816-4883/6mb2joatd/index.html
-https://www.giac.org/paper/gcih/266/review-ftp-protocol-cyber-defense-initiative/102802
-https://blu.org/mhonarc/discuss/2001/04/msg00285.php
-https://rapid7.com/blog/post/2019/02/19/stack-based-buffer-overflow-attacks-what-you-need-to-know/
Author:
Florian Roth (Nextron Systems)
Date:
2017-03-01
modified:
2025-03-17
Tags:
-'attack.t1068'
-'attack.privilege-escalation'
Logsource:
product: linux
Detection:
keywords:
- 'attempt to execute code on stack by'
- '0bin0sh1'
- 'AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA'
- 'stack smashing detected'
condition
:
keywords
Falsepositives:
-Base64 encoded data in log entries
Level:
high