RE: Assessing Your Malware Exposure with Snort
"Mark E. Donaldson" <[email protected]> Sat, 19 Feb 2005 10:48:16 -0800
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Organization | Bandwidthco |
| Message-ID | <[email protected]> |
Thanks. These are great and error-free. I've got them running on five sensors without a single adjust required. -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of [email protected] Sent: Tuesday, February 15, 2005 8:39 AM To: [email protected] Subject: [Intrusions] Assessing Your Malware Exposure with Snort I have written a few thousand Snort rules that are intended to detect successful HTTP communication with hosts known to be evil. They look for domain names in the Host string so they are not subject to evasion by changing IP addresses. If you would like to give them a try you can grab them from http://www.kgb.to/malware.html . ******************* N O T I C E ******************* The information contained in this e-mail, and in any accompanying documents, may constitute confidential and/or legally privileged information. The information is intended only for use by the designated recipient. If you are not the intended recipient (or responsible for the delivery of the message to the intended recipient), you are hereby notified that any dissemination, distribution, copying, or other use of, or taking of any action in reliance on this e-mail is strictly prohibited. If you have received this e-mail communication in error, please notify the sender immediately and delete the message from your system. *************************************************** _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions ######################################################## This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. [email protected] MailScanner at bandwidthco.com is for your absolute protection. ######################################################## ######################################################## This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. [email protected] MailScanner at bandwidthco.com is for your absolute protection. ######################################################## _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions