<nettime> WEF attack and homework

Any helpful hints for this poor "intrursion and dection" student?


> Hi,
> I'm currently following a course about intrusion
> detection and security with Marc Dacier.
> I had to study your attack against WEF, which is
> quite easy to understand, but the second part
> seems more difficult to me : I have to detect this
> attack (possibly before it's too late) and block
> it if possible.  We're supposed to use snort as
> firewall, but imho it's impossible to detect the
> attack without a statefull firewall (all HTTP
> requests are valid, without stats about traffic
> it's imposiible to do anything)
> Do you have an idea of what I could do with snort
> ?
> Thanks in advance.
> Julien Delfosse

