Cyber InfoCICyber Info
Powered by
near-sapphireN
Cyber Info•3y ago•
2 replies
near-sapphire

Snort Struggles: How to detect the FTP service name?

I am muddling through learning Snort and feeling a bit daft. I'm trying to write a rule that allows me to detect the FTP service name used in a .pcap.

I analyzed the .pcap with
sudo snort -c local.rules -A full -l . -r ftp-png-gif.pcap
sudo snort -c local.rules -A full -l . -r ftp-png-gif.pcap


I looked up some ways to find the ftp service name and I found a few like
sudo snort -r snort.log.1671731339 -X -n 10
sudo snort -r snort.log.1671731339 -X -n 10
which would probably do the trick, but I'm not sure why. I get that -X has something do the preprocessor, but I'm not sure why this outputs anything with FTP, or how to find where the FTP service name is in the output.
Cyber Info banner
Cyber InfoJoin
At Cyber Info, we strive to empower every individual with easy access to cybersecurity education
183,284Members
Resources

Similar Threads

Was this page helpful?
Recent Announcements

Similar Threads

need help for ftp access to a website
flashbangFflashbang / ❓︱support-requests
8mo ago
How to link the keycap back?
robyvisualsRrobyvisuals / ❓︱support-requests
2y ago
Host Name resolution
tanlockTtanlock / ❓︱support-requests
3y ago
How to start a Red Team career in the US?
Lion.ShelbyLLion.Shelby / ❓︱support-requests
3w ago