[Snort-sigs] Rules

Vanio Rogerio Santos vaniomoreira at ...12...
Tue Jul 1 05:56:01 EDT 2003


Hi,
I have installed the Snort 2.0.0 and I want to know how to make one rule to 
block traffic when I receive the following messages:

[**] [1:2003:2] MS-SQL Worm propagation attempt [**]
[Classification: Misc Attack] [Priority: 2]
07/01-09:57:47.857720 63.167.29.155:1226 -> 10.17.46.10:1434
UDP TTL:113 TOS:0x0 ID:21995 IpLen:20 DgmLen:404
Len: 376
[Xref => http://vil.nai.com/vil/content/v_99992.htm][Xref => 
http://www.securityfocus.com/bid/5311][Xref => 
http://www.securityfocus.com/bid/5310]

Thanks!

_________________________________________________________________
MSN Messenger: converse com os seus amigos online.  
http://messenger.msn.com.br





More information about the Snort-sigs mailing list