|
Re: Warning -- floods of Allaple worm alerts.... sid:200329(2-5): msg#00122security.ids.snort.bleedingsnort
I monitor about 35 networks. Two of them are getting lots of hits, the rest are not. I see 197 unique hosts sending out the traffic. It's gotta be 'bot traffic. So our choices are send a letter to the owning ISP or shun them. or do nothing. for me the only relevant question is, "bot or not?" If it really becomes overwhelming I might turn off the inbound probes and the outbound replies. Is there any chance this is not bot traffic? jp Quoting Matt Jonkman <jonkman-WwB1pFISwSkm7effSn6vN9HuzzzSOjJt@xxxxxxxxxxxxxxxx>: I've seen an increase, but not near that scale. It would seem to be an
------------------------------------------------- Email solutions, MS Exchange alternatives and extrication, security services, systems integration. Contact: services-MMNQ1ylbVXZN8Ch2cx6nig@xxxxxxxxxxxxxxxx |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: Warning -- floods of Allaple worm alerts.... sid:200329(2-5): 00122, Matt Jonkman |
|---|---|
| Next by Date: | Re: Warning -- floods of Allaple worm alerts.... sid:200329(2-5): 00122, Matt Jonkman |
| Previous by Thread: | Re: Warning -- floods of Allaple worm alerts.... sid:200329(2-5)i: 00122, Matt Jonkman |
| Next by Thread: | Re: Warning -- floods of Allaple worm alerts.... sid:200329(2-5): 00122, Matt Jonkman |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |