THIS IS A TEST INSTANCE. Feel free to ask and answer questions, but take care to avoid triggering too many notifications.
0

I need help to analyze slammer.pcap

Hi!

I just want some help or guide to analyze or understand the slammer.pcap exercise file provided by Wireshark page.

Link

c332560@urhen.com's avatar
1
[email protected]
asked 2019-09-01 02:20:51 +0000
Guy Harris's avatar
19.9k
Guy Harris
updated 2019-09-01 03:39:23 +0000
edit flag offensive 0 remove flag close merge delete

Comments

add a comment see more comments

1 Answer

0

post your pcap file , or we dont know what you talking

hackslash's avatar
1
hackslash
answered 2019-09-01 07:13:55 +0000
edit flag offensive 0 remove flag delete link

Comments

Presumably they're referring to the "slammer.pcap" file on the Wireshark Wiki's Sample Captures page. The description of that capture is "Slammer worm sending a DCE RPC packet.". The Web searches I've done show a "Slammer" worm that attacks via SQL, not DCE RPC, so I'm not sure what that packet indicates. It's also not an "exercise" in the sense of, for example, an exercise in a training course.

Guy Harris's avatar Guy Harris (2019-09-01 07:37:24 +0000) edit

One way to look at this (under linux at least) would be to use the Snort post-dissector (https://wiki.wireshark.org/Snort) with the emerging-threats rules (https://rules.emergingthreats.net/ope...) and open slammer.pcap. Then, you should see that one or more alerts fired and: - what rule(s) caused the alert(s) to be detected - where in the packet the content or pcre fields were found (and where they occur in the normal dissection) - clickable links to web-pages describing the snort rule and the threat it is thought to represent

This is admittedly be not-straightforward, especially if you are not already familiar with snort, but I am pretty sure I did this for this exact capture file once before.

MartinM's avatar MartinM (2019-09-02 22:13:14 +0000) edit
add a comment see more comments

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account. This space is reserved only for answers. If you would like to engage in a discussion, please instead post a comment under the question or an answer that you would like to discuss.

Add Answer