[Snort-sigs] Storm worm rule
pauls at ...1311...
Wed Feb 13 16:58:28 EST 2008
--On Wednesday, February 13, 2008 13:54:13 -0800 Matt Jonkman
<jonkman at ...829...> wrote:
> We've had this one covered in emerging threats sigs (botht he regular
> edonkey and the encrypted ones) for a very long time now.
> Were you running these, and if so were they not hitting?
No, I don't run the emerging threats rules. I tried searching for storm worm
on your site, but I didn't find rules that address this particular packet sig.
Perhaps I'm not searching correctly?
Paul Schmehl (pauls at ...1311...)
Senior Information Security Analyst
The University of Texas at Dallas
More information about the Snort-sigs