|
|
|
|
Snort Forums Archive
Archive Home » Snort Advanced » Does/can Snort detect services on unusual ports
Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.
[ Notice: Full Version of This Topic ]
Does/can Snort detect services on unusual ports
Posted by uva_snort on August 03, 2005 23:59:58
Does or can Snort detect services on unusual ports by analysing traffic?
Like ssh traffic on port 976 ?
Exploiters regulary run backdoor services on unusual ports after gaining access and if the intrusion is not detected earlier this should be a good extra detection opportunity. |
|
Posted by wuertz on August 12, 2005 03:50:09
I don't know about a special rule for SSH on unusual ports,
though this would be nice,...
but in general, snort indeed looks at the content of packets and
_can_ detect services on non-standard ports.
|
|
|
|
|
|