-
Notifications
You must be signed in to change notification settings - Fork 27
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Assess P2P protocol implementation #9
Comments
I hope to be able to get a .pcap from a ZeuS P2P variant to do some analysis. |
Let me know if you have issues getting a PCAP, I have access to this sort of stuff :) |
Andrea, are you currently working on this task or investigating it? |
I've got two different PCAPs from nearly 3 weeks ago, they're mostly UDP traffic with some minor TCP one on high ports. Unfortunately I haven't found out some time to analyze them more in-depth, but I hope to have something ready by the end of next week. |
if you have some time, you can run the through http://www.netzob.org/ would be interesting if we get any usable information from it. |
I'm working on it using netzob. Hopefully I'll end up with at least a decent wireshark dissector. |
Let me know if you get any usable information. I can also share PCAP's if you need. |
Moving this to milestone 1.1 as we haven't decided how we want to proceed regarding P2P protocol support |
Ok, I'm sorry for the delays. |
No rush. |
Brilliant work done by the CERT Polska here: http://www.cert.pl/PDF/2013-06-p2p-rap_en.pdf |
Have a look into various bots using P2P protocols for communication. What do we need to have in place so one can replicated the communication?
The text was updated successfully, but these errors were encountered: