Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Assess P2P protocol implementation #9

Open
glaslos opened this issue Oct 2, 2012 · 11 comments
Open

Assess P2P protocol implementation #9

glaslos opened this issue Oct 2, 2012 · 11 comments
Labels

Comments

@glaslos
Copy link
Member

glaslos commented Oct 2, 2012

Have a look into various bots using P2P protocols for communication. What do we need to have in place so one can replicated the communication?

@adepasquale
Copy link
Member

I hope to be able to get a .pcap from a ZeuS P2P variant to do some analysis.

@glaslos
Copy link
Member Author

glaslos commented Jan 7, 2013

Let me know if you have issues getting a PCAP, I have access to this sort of stuff :)

@pjlantz
Copy link
Contributor

pjlantz commented Jan 31, 2013

Andrea, are you currently working on this task or investigating it?
Just to be sure we do not work on the same stuff. Same question regarding HTTP protocol task.

@adepasquale
Copy link
Member

I've got two different PCAPs from nearly 3 weeks ago, they're mostly UDP traffic with some minor TCP one on high ports. Unfortunately I haven't found out some time to analyze them more in-depth, but I hope to have something ready by the end of next week.

@glaslos
Copy link
Member Author

glaslos commented Feb 28, 2013

if you have some time, you can run the through http://www.netzob.org/ would be interesting if we get any usable information from it.

@ghost ghost assigned adepasquale Mar 4, 2013
@adepasquale
Copy link
Member

I'm working on it using netzob. Hopefully I'll end up with at least a decent wireshark dissector.

@glaslos
Copy link
Member Author

glaslos commented Mar 5, 2013

Let me know if you get any usable information. I can also share PCAP's if you need.

@glaslos
Copy link
Member Author

glaslos commented Apr 17, 2013

Moving this to milestone 1.1 as we haven't decided how we want to proceed regarding P2P protocol support

@adepasquale
Copy link
Member

Ok, I'm sorry for the delays.

@glaslos
Copy link
Member Author

glaslos commented Apr 17, 2013

No rush.

@adepasquale
Copy link
Member

Brilliant work done by the CERT Polska here: http://www.cert.pl/PDF/2013-06-p2p-rap_en.pdf

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants