Snort mailing list archives

RE: Cod Red HELP!!!!


From: Nigel Morse <N.Morse () hyperknowledge com>
Date: Tue, 7 Aug 2001 15:55:40 +0100

 
Try to use the string match figure of iptables inside your firewall so
you can drop any packets that contain default.ida string.

But is the default.ida string isn't in the syn packet - by the time that
string arrives your connection is open and the server just has to respond
with a page not found (as it's a UNIX server I'm guessing it's not running
IIS ;) ) - blocking the packet leaves the connection open.  I don't know
ennough about this stuff to know if it's better to let the packet run and
close the connection or block it and leave it open till it times out.

Cheers
Nigel

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: