22
Kazaa or Morpheus http server detection
Peer-to-Peer
2003/11/13
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.3
Corrected the plugin structure and added the accuracy values in 1.3
tcp
1214
open|send GET / HTTP/1.0\n\n|sleep|close|pattern_exists X-Kazaa-Username:
97
This plugin was written with the ATK Attack Editor.
http://www.securiteam.com/securitynews/5UP0L2K55W.html
Kazaa and Morpheus peer-to-peer clients
Configuration
Kazaa and Morpheus are very popular peer-to-peer software to sharing files. An open http server on port tcp/1214 and the returning banner may indicate the existence web service. This kind of software may be illegal in the environment.
Disable the peer-to-peer software if not allowed nor needed. If it should run then filter incoming traffic on port tcp/1214 to prevent unwanted access to the web service.
15 minutes
Yes
http://www.securiteam.com/securitynews/5UP0L2K55W.html
Yes
Yes
Medium
6
8
4
5
Serious
Nessus is able to do the same check. The check is also possible with a telnet client or the NetCat utility.
10751
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.computec.ch