Snort mailing list archives

Re: Code Red and port 443 (was RE: Code Red HELP!!!!)


From: Carolyn Beckman <beckman () clone concordia ca>
Date: Tue, 7 Aug 2001 16:37:46 -0400 (EDT)

On Tue, 7 Aug 2001, George D. Nincehelser wrote:

Date: Tue, 07 Aug 2001 14:19:04 -0500
From: George D. Nincehelser <george () ccitriad net>
To: Carolyn Beckman <beckman () clone concordia ca>
Cc: snort-users () lists sourceforge net
Subject: [Snort-users] Code Red and port 443 (was RE: Code Red HELP!!!!)

On a related note, does the worm every try secure web servers (e.g. on port
443)?

I don't know. I have nothing running on port443.  I would suspect
not since both the new version and the old version seem to attack
port 80.  One good reference for inforamation about the thing is
www.securityfocus.com, or is it org. I am not sure.  I have no
experience with Snort. A good place to investigate the capability
of this exploit is www.incidents.org.

If something did try to spread on an encrypted service, would Snort have any
chance of picking it up?  I would think not, but you never know...


=================================================================
        beckman () clone concordia ca
        Carolyn Beckman
=================================================================


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: