Rules for the Snort IDS to detect trinoo. This rules work only as long as the ports/passwords/protocol aren't changed.
2b91a4c5ad5bfa7061b5a1c62f4c8d2eResults of the Distributed-Systems Intruder Tools Workshop (Nov 2-4, 1999). Several distributed intruder tools are in widespread use now, and the technology is maturing. As a result, a single command from an attacker can result in tens of thousands of concurrent attacks.
b69cb60c78ff79ee69d4513e534245f9Blitznet launches a distributed syn flood attack with spoofed source IP, without logging.
c58067ac29321e40ba72d357c136f798Trinoo daemon source - Implements a distributed denial of service attack. Controlled via UDP.
a7d1bda7617f17b021617ae3c782fc6eA new model of computer penetration: distributed metastasis, increases the possible depth of penetration for an attacker, while minimizing the possibility of detection. Distributed Metastasis is a non-trivial methodology for computer penetration, based on an agent based approach, which points to a requirement for more sophisticated attack detection methods and software to detect highly skilled attackers.
f60d02052189d8734d7fffdbc76eb779Saltine Cracker v1.05 is a TCP/IP Distributed Network Password Auditing Tool for NTHASH (MD4) and POSIX LibDES Crypt(3) passwords. With the incorporated cross-compatiblity, you can audit Win9X/NT client passwords attached to POSIX servers and vice-versa.
dd7b4dc6f6572dac714e538eda547ab2Slurpie v2.0b - Slurpie is a passwd file cracker similar to CrackerJack and John the Ripper except that it runs in a distributed environment. It supports file based and generated dictionary comparison.
820b4bf746e0a1297516ddd4a83958dbThe following is an analysis of the "Tribe Flood Network", or "TFN", by Mixter. TFN is ai powerful distributed attack tool and backdoor currently being developed and tested on a large number of compromised Unix systems on the Internet. TFN source available here.
5e83210b7399408c0735c3ea14cdfe35The following is an analysis of the DoS Project's "trinoo" (a.k.a. "trin00") master/slave programs, which implement a distributed network denial of service tool. Trinoo daemons were originally found in binary form on a number of Solaris 2.x systems, and probably being set up on hundreds, perhaps thousands, of systems on the Internet that are being compromised by remote buffer overrun exploitation.
850306089225ee486a29ed60b7f5dd71