|
|
Choosing A Webhost: |
Re: Stormy P2P bot Sigs -- may be SKYPE ?: msg#00181security.ids.snort.bleedingsnort
Matt Jonkman wrote: > Ummm... that's a little scary. > > To be honest, when I was looking at those stormy variants the traffic > didn't exactly conform to edonkey, but was close. It's VERY possible it > may have been skype and I've written for the wrong protocol. > > Let me look into it and see what'll match. Anyone else seeing skype hits? > I've just followed up another machine that was getting lots of hits. This machine belongs to a senior physics professor who I have known for years. There is no Edonkey or other file sharing p2p software on the box and since it is a Mac it is unlikely to be infected with peacomm ;) and he was using SKYPE at the time of my alerts. I suspect that the p2p rules are not widely used and those that do monitor for p2p also ban SKYPE which we don't. What puzzles me is why this has just started happening -- or are these rules new? Russell.
|
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | New Web Sigs, Matt Jonkman |
|---|---|
| Next by Date: | Re: Stormy P2P bot Sigs -- may be SKYPE ?, Russell Fulton |
| Previous by Thread: | Re: Stormy P2P bot Sigs -- may be SKYPE ?, Matt Jonkman |
| Next by Thread: | Re: Stormy P2P bot Sigs -- may be SKYPE ?, Matt Jonkman |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
Free MagazinesCisco NewsReceive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business. subscribe Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field. subscribe The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business. subscribe Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company. subscribe Total Telecom Total Telecom is "The Economist of the communications industry". subscribe |