ignore security and it'll go away

snort-ids.trinoo.txt

snort-ids.trinoo.txt
Posted Dec 14, 1999
Authored by Stefan Aeschbacher | Site aeschbacher.ch

Rules for the Snort IDS to detect trinoo. This rules work only as long as the ports/passwords/protocol aren't changed.

tags | denial of service, protocol
MD5 | 2b91a4c5ad5bfa7061b5a1c62f4c8d2e

snort-ids.trinoo.txt

Change Mirror Download
Hi
here are some snort rules which could show the presence of a trin00
network
in the observed IP-range. This rules work only as long as the
ports/passwords/protocol aren't changed.
The rules are not tested, they rely on the paper of Dave Dittrich posted
in Bugtraq (for more information
see this great paper). If you have programs using high numbered UDP
ports some of the rules will give false alarm.
Another way to identify trin00 would be the search for the packets that
contain one of the daemon or master
commands. Unfortunately most of them are strings which are common on a
network (e.g. quit, help) but some of
them could be used to detect trin00. If you see several of this alerts,
there's probably an attack running, that's
more or less the only time this rules can detect trin00.

# Trin00 commands are sent
alert tcp any any -> 192.168.1.0/24 27665 (msg:"Trin00: Attacker to
Master";)
alert tcp any any -> 192.168.1.0/24 27665 (msg:"Trin00: Attacker to
Master (default startup pass detected!)"; content:"betaalmo";))
alert tcp any any -> 192.168.1.0/24 27665 (msg:"Trin00: Attacker to
Master (default mdie pass detected!)"; content:"killme";))
alert udp any any -> 192.168.1.0/24 27444 (msg:"Trin00: Master to
Daemon";)
alert udp any any -> 192.168.1.0/24 27444 (msg:"Trin00: Master to Daemon
(default pass detected!)"; content:"l44adsl";)
alert udp any any -> 192.168.1.0/24 31335 (msg:"Trin00: Daemon to
Master";)
alert udp any any -> 192.168.1.0/24 31335 (msg:"Trin00: Daemon to Master
(*HELLO* detected)"; content:"*HELLO*";)
alert udp any any -> 192.168.1.0/24 31335 (msg:"Trin00: Daemon to Master
(PONG detected)"; content:"PONG";)
alert udp any any -> 192.168.1.0/24 31335 (msg:"Trin00: Daemon to Master
(message detected)"; content:"l44";)

Stefan Aeschbacher
--
Stefan Aeschbacher
Federal Institute of Technology Where do you want to go today?
Lausanne Switzerland
http://www.aeschbacher.ch/stefan - NOT in your direction! -

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close