Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Trojan Port Lists - Any Value?

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 3 Posters 726 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P Offline
      pfBasic Banned
      last edited by

      Is there any value to these lists? I see them every now and then on the web but never an updated list.

      Is this useless or worth blocking or logging the ports?

      https://www.sans.org/security-resources/idfaq/which-backdoors-live-on-which-ports/8/4

      1 Reply Last reply Reply Quote 0
      • K Offline
        kpa
        last edited by

        I'd say almost useless because you'll never identify the trojan traffic based on just the port numbers because anyone can write a port scanner probing the listed ports but it would be just port scan. You'll need more tools such as IP blocklists of known botnets etc.

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator
          last edited by

          Those sorts of list are only good in a sense if you are seeing traffic from say one of your hosts on odd ball ports and and trying to figure out what it "could" be..

          As kpa mentions seeing traffic on known used backdoor ports to IPs on bad lists should for sure raise some eyebrows to the nature of the traffic for sure.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.11.1 | Lab VMs 2.8.1, 25.11.1

          1 Reply Last reply Reply Quote 0
          • P Offline
            pfBasic Banned
            last edited by

            OK, that makes sense thank you both. I setup rules with aliases to pass but log them just out of curiosity.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.