[Snort-users] W32.MyDoom.M at ...4138...

Murray, Todd Todd.Murray at ...12036...
Tue Jul 27 11:41:35 EDT 2004


Does anyone have a tested snort rule for the latest variant of MyDoom?  I
googled it and only found older rules watching for the attack against
sco.com.  I'm still learning about rules and how to write them so any help
would be appreciated.  If anyone has specific tools or sites they find
useful in providing the info needed to write rules for virus's that'd be a
great help too.
 
Todd Murray
 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20040727/ee05d1bd/attachment.html>


More information about the Snort-users mailing list