Buffer Overflow Attempts

 Original Source: [Sigma source]
Title: Buffer Overflow Attempts
Status: test
Description:Detects buffer overflow attempts in Unix system log files
References:
  -https://github.com/ossec/ossec-hids/blob/1ecffb1b884607cb12e619f9ab3c04f530801083/etc/rules/attack_rules.xml
  -https://docs.oracle.com/cd/E19683-01/816-4883/6mb2joatd/index.html
  -https://www.giac.org/paper/gcih/266/review-ftp-protocol-cyber-defense-initiative/102802
  -https://blu.org/mhonarc/discuss/2001/04/msg00285.php
  -https://rapid7.com/blog/post/2019/02/19/stack-based-buffer-overflow-attacks-what-you-need-to-know/
Author: Florian Roth (Nextron Systems)
Date: 2017-03-01
modified:2025-03-17
Tags:
  • -'attack.t1068'
  • -'attack.privilege-escalation'
Logsource:
  • product: linux
Detection:
  keywords:
    - 'attempt to execute code on stack by'
    - '0bin0sh1'
    - 'AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA'
    - 'stack smashing detected'
  condition:keywords
Falsepositives:
  -Base64 encoded data in log entries
Level: high