1832287 Members
1936 Online
110041 Solutions
New Discussion

Probe detection

 
SOLVED
Go to solution
Ed Hon
Regular Advisor

Probe detection

We have Unix and NT in house, and the Code Red worm has detected on our LAN. It doesn't infect Unix but it can get hit with probes from infected machines on the network. The NT Admins use some software called BlackICE to detect probing on the NT servers. Is there something for HP-UX to detect network probes?
1 REPLY 1
Ralf Hildebrandt
Valued Contributor
Solution

Re: Probe detection

You can use snort, an excellent free tool:
www.snort.org
I've been using it for about 1 year now. It's based on libpcap (www.tcpdump.org).

Postfix/BIND/Security/IDS/Scanner, you name it...