Bluehost.com Web Hosting $6.95

Re: [Snort-users] New snort rule for WORM_NETSKY.B yet

This is a discussion on Re: [Snort-users] New snort rule for WORM_NETSKY.B yet within the Snort forums, part of the System Security and Security Related category; At 10:15 AM 2/18/2004, Snortty wrote: >This one seems to be getting ready, or already spread &...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2004
Matt Kettler
 
Posts: n/a
Default Re: [Snort-users] New snort rule for WORM_NETSKY.B yet

At 10:15 AM 2/18/2004, Snortty wrote:
>This one seems to be getting ready, or already spread
>like the last time, any rule to apply to detect it yet?


Hardly urgent, as nobody should be using snort as a first-line-of-defense
against mail worms.. That's what putting a virus scanner on your mailserver
is for.

However, it would be handy to have a signature for this things file-share
spread.

Details on the worm can be found here
http://us.mcafee.com/virusInfo/defau...virus_k=101034

The clamAV signature for this thing is:
Worm.SomeFool
(Clam)=ce366483cb540740032ca8bf6c9a2004f082736f6d6 574682bd446edb36973d
a6ff213b154df0b676f087719678ffd46fdef796f75fd65206 261640b747279fa61df5517737465616c1
f6665656cb0466da59e24739b13decaed5b1e726e206d44657 91a6174


Which is a rather long signature to be looking for in packets via snort,
but it's a start. (note that clamav signatures are just virusname=(hex
signature))

Note: the above signature is extracted from clamav daily.cvd version 134,
and thus is likely Copyrighted with GPL licensing like the rest of clamav.
You can obtain all of clamav, and it's source code from:
http://www.clamav.net/



-------------------------------------------------------
SF.Net is sponsored by: Speed Start Your Linux Apps Now.
Build and deploy apps & Web services for Linux with
a free DVD software kit from IBM. Click Now!
http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 10:22 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0