10/27/2008
emerging threats writes 32 Snort detection rules for MS08-067
"Emerging Threats is an open source community project. Through the support of our community we are able to produce the fastest moving and most diverse Snort Signature set and firewall rules available. Matt Jonkman is the founder of this project. Our content is free to use by any user or organization, commercial or private. We only ask that when you detect new threats in your environment or write new rules suitable for public release that you share that intelligence with the community at large. We update these rulesets several times a day and highly recommend you update at least twice a week to stay up to date. "
So if they have to write 32 rules to detect any use of this vulnerability than this is bigger than imagined. But when we remember that the vulnerability was handmade (it was professional work) than that shouldn't surprise you.
If you don't have cash, you should look at snort as an IDS (just don't want to see everything all the time, take one step at a time)
11:43 | Permalink | Comments (0) | Email this
|
|
del.icio.us
|
|
Digg |
Facebook




Post a comment