[Snort-sigs] Storm worm rule

Paul Schmehl pauls at ...1311...
Wed Feb 13 16:58:28 EST 2008


--On Wednesday, February 13, 2008 13:54:13 -0800 Matt Jonkman 
<jonkman at ...829...> wrote:

> We've had this one covered in emerging threats sigs (botht he regular
> edonkey and the encrypted ones) for a very long time now.
>
> Were you running these, and if so were they not hitting?
>

No, I don't run the emerging threats rules.  I tried searching for storm worm 
on your site, but I didn't find rules that address this particular packet sig. 
Perhaps I'm not searching correctly?

-- 
Paul Schmehl (pauls at ...1311...)
Senior Information Security Analyst
The University of Texas at Dallas
http://www.utdallas.edu/ir/security/





More information about the Snort-sigs mailing list