Snort mailing list archives

W32.MyDoom.M@mm


From: "Murray, Todd" <Todd.Murray () adidasus com>
Date: Tue, 27 Jul 2004 11:40:48 -0700

Does anyone have a tested snort rule for the latest variant of MyDoom?  I
googled it and only found older rules watching for the attack against
sco.com.  I'm still learning about rules and how to write them so any help
would be appreciated.  If anyone has specific tools or sites they find
useful in providing the info needed to write rules for virus's that'd be a
great help too.
 
Todd Murray
 

Current thread: