Bluehost.com Web Hosting $6.95

RE: [Snort-users] NetSky worm signature definition...!!!

This is a discussion on RE: [Snort-users] NetSky worm signature definition...!!! within the Snort forums, part of the System Security and Security Related category; Having a portion that is a mass mailer, you'll see it come in on port 25 for sure . . . Using ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-19-2004
Tim Hergert
 
Posts: n/a
Default RE: [Snort-users] NetSky worm signature definition...!!!

Having a portion that is a mass mailer, you'll see it come in on port 25 for
sure . . .

Using Matt Kettler's suggestion, I quickly kluged together a rule using the
clam av signature
http://www.clamav.net/

However, the old Klez detection rule seems to be triggered by NetSky, and
the log times seem to correlate exactly with the logs from the antivirus
software on the mail server.

alert tcp $EXTERNAL_NET any -> $SMTP_SERVERS 25 (msg:"VIRUS Klez Incoming";
flow:to_server,established; dsize:>120;content:"MIME";
content:"VGhpcyBwcm9"; classtype:misc-activity; sid:1800; rev:3;)

Seems to work well for me, but maybe I'm just lucky.


-----Original Message-----
From: Semerjian, Ohanes [mailto:ohanes.semerjian@au.mci.com]
Sent: February 18, 2004 8:23 PM
To: snort-users@lists.sourceforge.net
Subject: [Snort-users] NetSky worm signature definition...!!!


Hello all,
Just was wondering if any one had this latest worm signature defined or know
it works (like which port, protocol it uses )
Best Regards
Ohanes Semerjian


-------------------------------------------------------
SF.Net is sponsored by: Speed Start Your Linux Apps Now.
Build and deploy apps & Web services for Linux with
a free DVD software kit from IBM. Click Now!
http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 12:51 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0