Hmm. Spose there are a few sites on the net where you can search for p2p ports(Look at
http://www.portsdb.org/bin/portsdb.c...ol=ANY&String= ,where String is any of p2p, peer, shar(e) etc etc.), else just tag logging onto all traffic xcept for the usual 21,22,25,80,8021,8080's for a while. Stuff like Morpheus and Kazaa are around the 1200's (IIRC) and Gnutella is around 6000's.
*Maybe Snort has handshake signatures for some apps?