[Snort-users] Odd packets... maybe a new Trojan?

Yonah Russ yonah at ...569...
Thu Oct 26 03:04:15 EDT 2000


the deception toolkit can do this.

http://all.net/dtk/


On Wed, 25 Oct 2000, Dan Hollis wrote:

> On Wed, 25 Oct 2000, Joe McAlerney wrote:
> > This seemed to be a good explanation:
> > http://www.securityfocus.com/templates/archive.pike?list=1&mid=77042
> > If anyone finds anything else, please let me know - be it on or off the
> > list.
> 
> Anyone have honeypot/trojan daemons we can throw up easily on rpc.statd
> and 9704/tcp in order to catch these lamers?
> 
> -Dan
> 
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> http://lists.sourceforge.net/mailman/listinfo/snort-users
> 

-- 
Email:		<yonah at ...570...>
Hompage:	<http://p-yonah.jct.ac.il/>
PGP:            0x7C3C2524 <ldap://certserver.pgp.com>

"Quote me as saying I was misquoted."
				--Groucho Marx




More information about the Snort-users mailing list