LoFP LoFP / base64 encoded data in log entries

Techniques

Sample rules

Buffer Overflow Attempts

Description

Detects buffer overflow attempts in Unix system log files

Detection logic

condition: keywords
keywords:
- attempt to execute code on stack by
- 0bin0sh1
- AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
- stack smashing detected