Skip to content

starbase1/spyportcheker

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Surveillance Script to Catch any TCP Traffic coming Through as SSH Is Someone at the Backdoor? You suspect that someone is trying to open SSH session into your workstation and decided to set up a surveillance script to catch any TCP traffic Coming Through as SSH.

POC

  1. In order to catch Ssh Traffic you need to monitor port 22
  2. since we are only testing locally, you need to change Interface option
  3. you can test script by opening a terminal window and execute ssh localhost. (It probably won't succeed unless you have an SSH server running but it will generate SSH Traffic)
  4. Analyze The dump file with wireshark and Also decrypt via tcpdump -r (pcap file)

About

Surveillance Script

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages