Re: Detecting software

Jim Mellander <[email protected]> Wed, 20 Nov 2019 11:54:13 -0800
Newsgroups gmane.comp.security.detection.bro
Message-ID <CADju=b5WdNx+=dM1EhddoDSiCCOc61QPAD572mozJi+-=MGW5w@mail.gmail.com>
Just to be clear, Randy's suggestions should be executed on the server
listening on port 4545, not the bro/zeek system.

On Wed, Nov 20, 2019 at 11:31 AM Randy Labaza <[email protected]> wrote:

> You might try some combination of lsof -i:4545, get the PID, then use ps
> to find the process...
> Regards.
> rl.
>
>
> On Wed, Nov 20, 2019 at 2:02 PM Vern Paxson <[email protected]> wrote:
>
>> > We have a server that bro detected with port 4545 in listening mode. Is
>> > there a way to find what software had that port opened or any specific
>> > details about it?
>>
>> Zeek doesn't provide additional insight into servers running protocols for
>> applications unknown to Zeek.  In practical terms, you could try capturing
>> a pcap of the traffic and then inspecting it using say Wireshark to see
>> if you can figure out what it is.
>>
>>                 Vern
>> _______________________________________________
>> Zeek mailing list
>> [email protected]
>> http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
>>
> _______________________________________________
> Zeek mailing list
> [email protected]
> http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek