[Snort-sigs] P2P foldershare.com ftp connection with FTP STUFF

daniel uriah clemens daniel_clemens at ...842...
Tue Jul 8 14:30:05 EDT 2003

alert tcp $EXTERNAL_NET 21 -> $HOME_NET any \
(msg:"P2P foldershare.com ftp connection with FTP STUFF ";\
content:"|45 5f 00 15 01 00 0c|"; content:"|01 bb|"; distance:4;



A client on your network is trying to intiate a connection to a
foldershare.com p2p remote file sharing service.
Usually before this client initiates its connection via ssl for its file
sharing purposes it will connect to remote computers on port 80,8000,and
21 with similar payloads.

Content in the packet will look for 45 5f 00 15 01 00 0c followed by 01 bb
within a range of 4 bytes.


Many corporations view this type of p2p file sharing activity a breach of
their privacy policy or acceptable use policy or even a security breach to
share files with untrusted sources.

Detailed Information:
Generally this connection will be made to on port 21 but may
change sometime in the future.

Affected Systems:

windows based operating systems.

Attack Scenarios:

Ease of Attack:


False Positives:

False Negatives:

Corrective Action:

The easiest way to block this activity is to block it at your border

access-list 101 deny ip any log  FolderShare site
access-list 101 deny ip any log  FolderShare SSL
access-list 101 deny ip any log  AudioGalaxy FTP
access-list 101 deny ip any log  AudioGalaxy site

