This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi I need samples of differnt worms' traffic capture, that I can use them safely. Any body knows where I can find something like that?? and what procedures should be taken when I handle some traces like these??or even any other forum where I can ask . There are two sample captures in wireshark.org, I'm interested in slammer.pcap but I tried once to download it and there was a warning of opening this file, what I should do when I work with such files safely, I have a program that has to detect the scanning activity of worms and I need a capture to try it with to know if it is working with. Thanks

asked 07 Dec '12, 03:15

Leena's gravatar image

Leena
51171821
accept rate: 0%

Sample captures in wireshark.org don't agree with what I'm looking for,the first one contains a packet of the worm, and the other is containing a packet showing an anomaly which is not what I'm looking for, I need a trace showing the scanning activity of the worm. I googled it too much but with no result!!!!!

(07 Dec '12, 08:00) Leena

Why don't you simply trace a nmap scan or s.th. similar or what exactly do you mean with "scanning activity of a worm"?!

(07 Dec '12, 08:10) Landi

Before worm break out it first scans either random ip addresses or sequential ones to get some vulnerable targets and then complete attack, I just need real examples because it looks more persuasive and maybe I could found other works on them to compare with mine to identify the advantages and disadvantages of the program,and maintain factors such as speed and other capabilities. It is a research work

(07 Dec '12, 09:47) Leena

As you are trying to build an IPS (based on your question history), I recommend this:

http://www.iscx.ca/datasets

UPDATE:

These datasets might be interesting as well.

http://www.caida.org/data/passive/passive_2012_dataset.xml

Regards
Kurt

permanent link

answered 07 Dec '12, 09:58

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%

edited 08 Dec '12, 01:15

Thanks a lot Kurt, I'll check it. May God Bless you

(07 Dec '12, 10:31) Leena

good luck.

If a supplied answer resolves your question can you please "accept" it by clicking the checkmark icon next to it. This highlights good answers for the benefit of subsequent users with the same or similar questions.

(07 Dec '12, 12:11) Kurt Knochner ♦

Sure,I won't forget.

(07 Dec '12, 17:45) Leena

There is also a link that contains a list of public pcap files for download http://www.netresec.com/?page=PcapFiles It may help who needs pcap repositories. Thanks Kurt you are always helping

(17 Dec '12, 02:26) Leena
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×1,620
×549
×36

question asked: 07 Dec '12, 03:15

question was seen: 4,233 times

last updated: 17 Dec '12, 02:34

p​o​w​e​r​e​d by O​S​Q​A