Snort mailing list archives

Re: What to do with CodeRed(II) logged hosts ?


From: Ryan Russell <ryan () securityfocus com>
Date: Mon, 6 Aug 2001 08:57:28 -0600 (MDT)

On Mon, 6 Aug 2001 ks () schuricht de wrote:

But what i do with hosts infected (at this time i only reject all traffic
from them)?


Send the logs to aris-report () securityfocus com, we're notifying infected
sites.  It would be helpful if the logs could be reduced a bit... we need
the IP address of the attacker, date, time, and timezone all on one line.

                                        Ryan


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: