Kiran, Thanks for your reply, but I wanted to see an actual snip from someone's IPCOP IDS to see EXACTLY what I should look for, I've got many hits on these ports but not sure if its the blaster worn or not.
On Sun, 17 Aug 2003 11:58 am, Kiran wrote: > http://www.cert.org/advisories/CA-2003-20.html > > this describes it best. > > On Sat, 2003-08-16 at 12:38, Gavin wrote: > > I've got a few M$ boxes running 2000 and XP behind my IPcop firewall, all > > my boxes are patched.. I've been checking my logs for anything pertaining > > to the blaster worm but "I THINK" there is nothing showing..I've got > > snort active but I'm not "REALLY" sure what to look for!! if any of you > > experts are using ipcop and your logs show hits. could you show me a snip > > so I know what to look for.. > > > > Thank you -- Gavin c/o GES Fukushimaken, Fukushima City Nankodai 2-34-1 Zip:960 Japan Register Linux user # 199685 Sent 2u on a M$ free system!!
Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com
