[Snort-sigs] SID 558 contrib (please note msg change; done for consistency with 556, 557, 559)
gegomez at ...1889...
Mon Sep 22 06:58:18 EDT 2003
alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"P2P Outbound GNUTella
client request"; flow:established; content:"GNUTELLA OK"; depth:40;
classtype:misc-activity; sid:558; rev:5;)
A network-external server has okayed an internal GNUTella client
connection attempt and they have begun communications.
Possible policy violation.
GNUTella is a P2P (Peer-to-Peer) protocol for exchanging arbitrary
files. Depending on your site's policies, using it may be a policy
If not propely configured, GNUTella clients may accidentally share out
confidential files. GNUTella worms (which use deceptive names to
encourage download) and viruses may also be accidentally downloaded by a
This rule being triggered means that a GNUTella client has been detected
on your network.
Any system with a GNUTella client installed (available for most
Ease of Attack:
This rule detects the term "GNUTELLA OK" on all ports. As a result, any
email, web page, or other network content that discusses the protocol
and its messages will trigger this alert.
Depends on acceptable use policies.
Gene R Gomez (gene!AT!gomezbrothers!DOT!com)
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Snort-sigs