IDS mailing list archives

OSSEC DC++ Attacks


From: Orlando Leon <orlando () sbw com>
Date: Thu, 22 Jan 2009 22:29:01 -0800

This is an old vulnerability but it is still present to this day.
About month ago we experience this type of attack we were able to stop
it usingour load balancers in order to perform deep packet inspection
and blocked the attack, the attack was not that large and did not
saturate our bandwidth.
I would like any available information on how to stop these type of
attacks other than to pay for some overpriced service.
We currently use OSSEC in portions of our network.
Is there a way to stop these type of attacks using OSSEC active response rules.
Regards
Orlando Leon



Current thread: