All of lore.kernel.org
 help / color / mirror / Atom feed
* Classifying W32/MyDoom.A
@ 2004-01-29 18:06 Eliot, GLI wireless tech support
  2004-01-30  5:46 ` Ray Leach
  0 siblings, 1 reply; 3+ messages in thread
From: Eliot, GLI wireless tech support @ 2004-01-29 18:06 UTC (permalink / raw)
  To: netfilter

Has anyone come up with a ruleset for classifying a random TCP or
specific SMTP connection as being the W32/MyDoom.A virus?

For instance, it spreads two ways:

1) Through email
2) Through Kazaa

I want to be able to take a TCP stream (like a Kazaa download) and match
it against a rule that would flag the packets with a specific MARK value
if it is the MyDoom.A virus being transferred. I would also like a
ruleset that would match if it is being transferred through SMTP. 

Anyone have any ideas how to do this without too many false positives?
(IE a document on the web that describes the characteristics of
MyDoom.A). 

Eliot Gable
iSWAT Leader
Internet Service Without Any Telephones
Great Lakes Internet, Inc.
112 N Howard Ave
Croswell, MI 48422
(810) 679-3395



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2004-01-30  5:46 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-01-29 18:06 Classifying W32/MyDoom.A Eliot, GLI wireless tech support
2004-01-30  5:46 ` Ray Leach
2004-01-30  5:41   ` Daniel Chemko

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.