Snort mailing list archives

What to do with CodeRed(II) logged hosts ?


From: ks () schuricht de
Date: Mon, 6 Aug 2001 11:59:19 +0200

Hi,

our logfiles grow an grow more cause we get massive 'Code Red' Attacks
to our network. Its not really a problem (i've written a small script that
denies
all access from source ip that seems to be infected by CodeRed I + II).
Also
our machines are patched (until next hack ;).

But what i do with hosts infected (at this time i only reject all traffic
from them)?

Exists there a database with all infected hosts so that we can help the
administrators of them ?

Thanks!

Best regards,
  Kai.

--
Abt. eBusiness / Entwicklung
D. Schuricht GmbH & Co. KG
http://www.schuricht.de



_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: