Assessing Your Malware Exposure with Snort
[email protected] Tue, 15 Feb 2005 10:39:21 -0600
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <OF080C0832.3305BA5B-ON86256FA9.005B5569-86256FA9.005B7DBF@fbol.com> |
I have written a few thousand Snort rules that are intended to detect successful HTTP communication with hosts known to be evil. They look for domain names in the Host string so they are not subject to evasion by changing IP addresses. If you would like to give them a try you can grab them from http://www.kgb.to/malware.html . ******************* N O T I C E ******************* The information contained in this e-mail, and in any accompanying documents, may constitute confidential and/or legally privileged information. The information is intended only for use by the designated recipient. If you are not the intended recipient (or responsible for the delivery of the message to the intended recipient), you are hereby notified that any dissemination, distribution, copying, or other use of, or taking of any action in reliance on this e-mail is strictly prohibited. If you have received this e-mail communication in error, please notify the sender immediately and delete the message from your system. *************************************************** _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions