|
|
|
|
Snort Forums Archive
Archive Home » Snort Advanced » Offline Backdoor detection
Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.
[ Notice: Full Version of This Topic ]
Offline Backdoor detection
Posted by TheHammer on August 23, 2005 01:34:33
How can I analyze a (tcp)dumpfile and detect if some "standard" services are running on non-standard
ports? |
|
Posted by Joel_Esler on August 26, 2005 12:05:55
As long as there is a rule to detect these patterns in the traffic, you can run a tcpdump file through Snort
using the "-r" option.
Joel Esler
Sourcefire |
|
|
|
|
|