IDS mailing list archives
RE: Did IDSes detect the SQL worm?
From: "Garritano,Robert" <Robert.Garritano () cna com>
Date: Fri, 31 Jan 2003 10:04:09 -0600
I concur, ISS did a great job picking up this signature! -----Original Message----- From: Gonzalez, Albert [mailto:albert.gonzalez () eds com] Sent: Wednesday, January 29, 2003 1:15 PM To: focus-ids () securityfocus com Subject: RE: Did IDSes detect the SQL worm? RealSecure did pick up the worms activity. Snort didn't because there was no signature at the time of the worm started spreading. Though they did respond very quickly. Our Dragon sensors aren't correctly running, so I can't verify them Cheers! Alberto Gonzalez -----Original Message----- From: Todd Heberlein [mailto:todd_heberlein () mac com] Sent: Tuesday, January 28, 2003 6:42 PM To: focus-ids () securityfocus com Subject: Did IDSes detect the SQL worm? Much has been made about the fact that the vulnerability exploited by the MS-SQL worm has been known about for six months. So not only should users have been aware of it, but IDS vendors should have been aware of it. Here is my question: Other than an IDS reporting an unusual amount of traffic to port 1434, did any report the specific nature of the attack? In other words, did any IDS report that the packet appears to attack a vulnerability identified by CAN-2002-0649? Thanks, Todd
Current thread:
- RE: Did IDSes detect the SQL worm? Cathleen_M_Brackin (Jan 30)
- <Possible follow-ups>
- Re: Did IDSes detect the SQL worm? Kurt Seifried (Jan 31)
- RE: Did IDSes detect the SQL worm? Garritano,Robert (Jan 31)