Strange Alert from IDS-ET P2P eMule KAD Network Connection Request

Comments

5 comments

  • Avatar
    mastadon extinction

    NVM. I already solved this. I just went and pulled the pcaps and examined it in wireshark. its for sure MDNS. So just an FYI, If you are running suricata or snort it may trigger an alert for "ET P2P eMule KAD Network Connection Request" if your firewalla generates any MDNS messages. 

    0
    Comment actions Permalink
  • Avatar
    networker5

    How did you get the pcap from firewalla? 

    0
    Comment actions Permalink
  • Avatar
    mastadon extinction

    I didn't. I have a network security monitoring platform that functions as an ids and grabs pcaps.

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    tcpdump and wireshark can be installed on the red/blue/gold/purple if you want. 

    1
    Comment actions Permalink
  • Avatar
    networker5

    "tcpdump and wireshark can be installed on the red/blue/gold/purple if you want. "

    I have Gold. Problem is 1) just want to trace alerts or create a rule to trace. 2) ideally save a zip on device, external storage connected to device or send to server (preferably asynchronously to avoid process spikes) .  Bottom line is when I see an alert with an "upload", or even blocked traffic, just knowing that it happened or the IP address is meaningless and very tedious to lookup on "who is".

    I expect that running on all wan / lan traffic would generate large files and costly resources. 

    It's almost worse to know there may be suspicious activity but not have a way to see what is in the payload with wireshark or better something like network miner which requires fewer network skills to just see if files/passwords/etc are being uploaded. 

    I'm thrilled with the near 1G performance of Firewalla Gold and would rather not slow it down when it is smart enough to spot suspicious activity. 

    A lifetime ago I was a networking engineer but now I'm reborn into a newbie so forgive me if this already exists:)

    0
    Comment actions Permalink

Please sign in to leave a comment.