Is there a universal TCP/IP responding server

MonkeyK

Golden Member
May 27, 2001
1,396
8
81
I am looking for a tool that responds to TCP/IP requests on a large number of common ports. Does something like this exist?

I hope to use it so that I can direct traffic identified as suspicious to that server and capture as much of the request info as possible.
 

mv2devnull

Golden Member
Apr 13, 2010
1,503
145
106
Linux firewall, aka netfilter, is a list of packet match rules. If a packet matches the criteria of a rule, then the rule performs an action (such as write details to a log file).

The easiest criteria is "match all", but one can narrow that down to "match all TCP packets".

Programs like SNORT can do more -- to look into the payload (content of the packet) in addition to address, etc that the netfilter focuses on.
 

MonkeyK

Golden Member
May 27, 2001
1,396
8
81
I could be completely off, because I am pretty new to this stuff, so here is what is happening...
I have a network rule that sends any DNS requests associated with Malware to a specific IP address (this is called a sinkhole). But since the IP address is not actually configured to accept the traffic, the send is never completed and it doesn't get a chance to log the URL.
I do get the IP address making the request, but I would like the sinkhole to accept the traffic so that I can capture the rest of it.
Can a tool like SNORT capture request details if nothing is configured to receive the traffic?
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |