Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Advanced » Offline Backdoor detection

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Offline Backdoor detection


Posted by TheHammer on August 23, 2005 01:34:33

How can I analyze a (tcp)dumpfile and detect if some "standard" services are running on non-standard
ports?

Posted by Joel_Esler on August 26, 2005 12:05:55

As long as there is a rule to detect these patterns in the traffic, you can run a tcpdump file through Snort
using the "-r" option.

Joel Esler
Sourcefire