Hello Gurus,
We have a segment on which few machines have NIMDA Virus. It is propagating
to our server network.
We have placed Network Sensor (Real Secure 6.5 on Nokia Platform) on the
workstation segment. While our Desktop support team is implementing
anti-virus solution, we would like to RS Kill traffic generated by Nimda.
This variant propagates on Shared folder. Our Server are adequately
quarantine the files, however, it is the annoyance factor.
The Nimda Patten file on MU 5.3 does not recognize our Nimda infection. Is
there any way to block/traffic based on what I had described above?
The ISS Tech support mentioned that Real Secure 7.0 has what I'm looking
for, but that does not help us at this point.
We are very new to IDS (only a week into it). So please any help is greatly
appreciated.
Thanks,
_________________________________________________________________
Tired of spam? Get advanced junk mail protection with MSN 8.
http://join.msn.com/?page=features/junkmail
_______________________________________________
ISSForum mailing list
[EMAIL PROTECTED]
TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo
- RE: [ISSForum] Nimda Virus Removal John Smithson
- RE: [ISSForum] Nimda Virus Removal Larson, Jeffrey
