|
Re: Stormy P2P bot Sigs -- may be SKYPE ?: msg#00185security.ids.snort.bleedingsnort
>From the pcaps we've been seeing, it looked to us like it was using ICQ for C&C. I don't know if there are variants, or which ones we're using. Something to look at... Dave Killion, CISSP On 1/28/07, Russell Fulton <r.fulton-1/NbpDiVQt6SYBAHRPvY1A@xxxxxxxxxxxxxxxx> wrote:
-- Dave Killion, CISSP Contributing Author, Configuring NetScreen Firewalls _______________________________________________ Bleeding-sigs mailing list Bleeding-sigs-WwB1pFISwSkm7effSn6vN9HuzzzSOjJt@xxxxxxxxxxxxxxxx http://lists.bleedingthreats.net/cgi-bin/mailman/listinfo/bleeding-sigs |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: Stormy P2P bot Sigs -- may be SKYPE ?: 00185, Matt Jonkman |
|---|---|
| Next by Date: | Re: Stormy P2P bot Sigs -- may be SKYPE ?: 00185, Matt Jonkman |
| Previous by Thread: | Re: Stormy P2P bot Sigs -- may be SKYPE ?i: 00185, Russell Fulton |
| Next by Thread: | Re: Stormy P2P bot Sigs -- may be SKYPE ?: 00185, Matt Jonkman |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |