Ethereal-users: Re: [Ethereal-users] spyware\malware\viruses

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Andrew Hood <ajhood@xxxxxxxxx>
Date: Mon, 06 Feb 2006 20:54:24 +1100
Jon Miller wrote:
> Does anyone know where I can get traces of spyware\malware and
> various viruses.  I ask because I need to know what to look for on
> the wire.  We are currently having issues where the network comes to
> a halt for about 2-5 minutes at least 2-4 times a day.  I can look at
> the server stats (NetWare 6) and on most of these incidents see
> nothing unusal taking place.  This makes me think there is some
> process on a workstation or 2 that is causing this to happen.  I've
> check for jabbering, and cannot see anything.  Any ideas would be
> greatly appreciated.

You'd probably do better with something like snort.

http://www.snort.org/

-- 
There's no point in being grown up if you can't be childish sometimes.
                -- Dr. Who