1 of 15

Using Zeek Signatures To Detect CVEs

Keith J. Jones

1

2 of 15

2

3 of 15

Why This Video?

3

4 of 15

Let’s Look At The First One On The List…

4

5 of 15

Wireshark Analysis

5

6 of 15

RPC Portmap DUMP Call

6

7 of 15

RPC Portmap SET Call

7

8 of 15

Walk Through The Code

8

9 of 15

9

XID

Msg Type�Call/Reply

Vers

Prog

Prog Vers

Proc (Set)

Note: You Can Pause The Video To Read This

10 of 15

10

Proc (Dump)

11 of 15

TCP Prepends 4 Length Bytes

11

12 of 15

main.zeek

12

13 of 15

main.zeek

13

14 of 15

That’s All!

14

15 of 15

15