Using snort to detect if your users are doing interesting things?

Jeroen Massar jeroen at unfix.org
Fri Jun 10 10:02:31 UTC 2005


On Thu, 2005-06-09 at 23:29 +0300, Kim Onnel wrote:
> How about project Darknet and sinkholes and monitoring dark ip space,
> worms and botnets usually scans blindly right and left, so there is a
> good chance you will get a glimpse on infected hosts if thats what you
> want, i catch infected hosts by looking at apache access logs and i
> see alot of scans,

Read the following interesting article:
http://www.spectrum.ieee.org/WEBONLY/publicfeature/may05/0505worm.html

Greets,
 Jeroen

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 240 bytes
Desc: This is a digitally signed message part
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20050610/803946e6/attachment.sig>


More information about the NANOG mailing list