To report a botnet PRIVATELY please email: [EMAIL PROTECTED]
----------
On Fri, 2006-03-03 at 19:27 -0800, John Draper wrote:
> That's always been a problem....  finding good and effective Snort 
> rules.  Although Snort has a good
> collection of rules, we need a more refined list of rules for detecting 
> the bots.  Does anyone know of
> a good set of snort rules for detecting them?

The BleedingSnort IRC sigs have worked well for us. Are they not
effective in your environment?

Regards,
Frank

-- 
It is said that the Internet is a public utility. As such, it is best
compared to a sewer. A big, fat pipe with a bunch of crap sloshing
against your ports.

Attachment: signature.asc
Description: This is a digitally signed message part

_______________________________________________
botnets mailing list
To report a botnet PRIVATELY please email: [EMAIL PROTECTED]
http://www.whitestar.linuxbox.org/mailman/listinfo/botnets

Reply via email to