Kiran,

Thanks for your reply, but I wanted to see an actual snip from someone's IPCOP 
IDS to see EXACTLY what I should look for, I've got many hits on these ports 
but not sure if its the blaster worn or not.




On Sun, 17 Aug 2003 11:58 am, Kiran wrote:
> http://www.cert.org/advisories/CA-2003-20.html
>
> this describes it best.
>
> On Sat, 2003-08-16 at 12:38, Gavin wrote:
> > I've got a few M$ boxes running 2000 and XP behind my IPcop firewall, all
> > my boxes are patched.. I've been checking my logs for anything pertaining
> > to the blaster worm but "I THINK" there is nothing showing..I've got
> > snort  active but I'm not "REALLY" sure what to look for!! if any of you
> > experts are using ipcop and your logs show hits. could you show me a snip
> > so I know what to look for..
> >
> > Thank you

-- 
Gavin
c/o GES
Fukushimaken, Fukushima City
Nankodai 2-34-1
Zip:960
Japan
Register Linux user # 199685
Sent 2u on a M$ free system!!


Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com

Reply via email to