22 Kazaa or Morpheus http server detection Peer-to-Peer 2003/11/13 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 1.3 Corrected the plugin structure and added the accuracy values in 1.3 tcp 1214 open|send GET / HTTP/1.0\n\n|sleep|close|pattern_exists X-Kazaa-Username: 97 This plugin was written with the ATK Attack Editor. http://www.securiteam.com/securitynews/5UP0L2K55W.html Kazaa and Morpheus peer-to-peer clients Configuration Kazaa and Morpheus are very popular peer-to-peer software to sharing files. An open http server on port tcp/1214 and the returning banner may indicate the existence web service. This kind of software may be illegal in the environment. Disable the peer-to-peer software if not allowed nor needed. If it should run then filter incoming traffic on port tcp/1214 to prevent unwanted access to the web service. 15 minutes Yes http://www.securiteam.com/securitynews/5UP0L2K55W.html Yes Yes Medium 6 8 4 5 Serious Nessus is able to do the same check. The check is also possible with a telnet client or the NetCat utility. 10751 Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427 http://www.computec.ch