To report a botnet PRIVATELY please email: [EMAIL PROTECTED] ---------- At 12:11 AM -0600 3/4/06, Frank Knobbe wrote: >To report a botnet PRIVATELY please email: [EMAIL PROTECTED] >---------- >Content-Type: multipart/signed; micalg=pgp-sha1; > protocol="application/pgp-signature"; > boundary="=-OhFzKHb2zH5hSSp3AKBv" > >On Fri, 2006-03-03 at 19:27 -0800, John Draper wrote: >> That's always been a problem.... finding good and effective Snort >> rules. Although Snort has a good >> collection of rules, we need a more refined list of rules for detecting >> the bots. Does anyone know of >> a good set of snort rules for detecting them? > >The BleedingSnort IRC sigs have worked well for us. Are they not >effective in your environment?
Frank, Guess I must be blind ;-) What ruleset grouping are they in? Tom -- Tom Shaw - Chief Engineer, OITC <[EMAIL PROTECTED]>, http://www.oitc.com/ US Phone Numbers: 321-984-3714, 321-729-6258(fax), 321-258-2475(cell/voice mail,pager) Text Paging: http://www.oitc.com/Pager/sendmessage.html AIM/iChat: [EMAIL PROTECTED] Google Talk: [EMAIL PROTECTED] skype: trshaw _______________________________________________ botnets mailing list To report a botnet PRIVATELY please email: [EMAIL PROTECTED] http://www.whitestar.linuxbox.org/mailman/listinfo/botnets
