Detecting trojans on random ports with encrypted traffic...
From: Clint Byrum (cbyrum@spamaps.org)Date: 10/23/02
- Previous message: Rob Shein: "RE: Changes in IDS Companies?"
- Next in thread: Carey, Steve T ISD: "RE: Detecting trojans on random ports with encrypted traffic..."
- Reply: Carey, Steve T ISD: "RE: Detecting trojans on random ports with encrypted traffic..."
- Reply: Clint Byrum: "Re: Detecting trojans on random ports with encrypted traffic..."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: Clint Byrum <cbyrum@spamaps.org> To: focus-ids@securityfocus.com Date: 23 Oct 2002 13:55:07 -0700
Ok so, we can obviously see sub7 on port 27374 with its known signature
patterns. But then they go and run it on a different port. And then they
go and encrypt things(I don't know if sub7 can do this, but for instance
BO or something else).
The scenario is, a user brings a floppy disk with a trojan on it to the
location, and puts the trojan on another user's computer. They then sit
back and watch the keylogging/passwords/etc.etc.
So, is this what SPADE is supposed to handle? I mean.. currently the
only solution I have come up with is to designate subnets that are not
supposed to be talking to eachother, and alert on peer to peer traffic.
But this isn't always possible, and this doesn't cover traffic where the
trojan is on a server.
Is there any hope to detect this situation?
- Previous message: Rob Shein: "RE: Changes in IDS Companies?"
- Next in thread: Carey, Steve T ISD: "RE: Detecting trojans on random ports with encrypted traffic..."
- Reply: Carey, Steve T ISD: "RE: Detecting trojans on random ports with encrypted traffic..."
- Reply: Clint Byrum: "Re: Detecting trojans on random ports with encrypted traffic..."
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|