Bluehost.com Web Hosting $6.95

[Snort-users] New Sasser Worm Signatures

This is a discussion on [Snort-users] New Sasser Worm Signatures within the Snort forums, part of the System Security and Security Related category; Hi Everyone- I'm testing a Snort Sensor off of a cable modem running version 2.1.1 for the ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-11-2004
Alan
 
Posts: n/a
Default [Snort-users] New Sasser Worm Signatures

Hi Everyone-

I'm testing a Snort Sensor off of a cable modem running version 2.1.1 for
the past few weeks. I'm using IDS Policy Manager and using their
snortrules-current.zip, which I assume, is Snort.org's
snortrules-snapshot-CURRENT.tar.gz. I have the latest rules for the Sasser
worm and I've noticed I have not been hit once from it. Is this unusual? I
figured after reading how fast the worm is spreading I would have at least
seen it hit the sensor a few times. Could it be that my ISP is filtering the
worm somehow? To be honest I don't even see a wide variety of attacks on my
sensor. The most common are Slammer, ShellCode NOOPS, WEB-IIS unicode
directory traversal attempts and Code Red. That's about it. I know the
sensor is functioning properly, if I hit it with the CIS scanner alerts go
off like crazy but because I'm using the sensor to collect data on attacks
it's kind of disappointing not to see a greater variety of attacks. Is there
something I might be doing wrong that might not allow my Snort not to pick
up certain attacks? Any feedback would be greatly appreciated.




Thanks in advance!


Alan

I'm doing a (free) operating system (just a hobby, won't be big and
professional like gnu) for 386(486) AT clones.

Linus (torvalds@kruuna.helsinki.fi)
Date: 1991-08-25 23:12:08 PST




-------------------------------------------------------
This SF.Net email is sponsored by Sleepycat Software
Learn developer strategies Cisco, Motorola, Ericsson & Lucent use to
deliver higher performing products faster, at low TCO.
http://www.sleepycat.com/telcomwpreg...rom=osdnemail3
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 11:23 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0