Detect Bugbear worm with snort

From: Elijah Savage (
Date: 10/03/02

From: "Elijah Savage" <>
Date: Thu, 3 Oct 2002 11:52:12 -0400

Is there a way to detect this worm with snort to see how often it is
traversing our network?

Relevant Pages

  • Re: unidentified DOS "bad traffic" -- SOLVED
    ... The Win2K machine in question was a victim of the W32.HLLW.Deloder worm ... which is a CERT advisory (you can get it at CERT instead ... A particular host has been completely flooding the network ... My Snort output on this trace was filled ...
  • [REVS] Curious Yellow: The First Coordinated Worm Design
    ... The Warhol worm design began the theoretical discussion of so-called ... very quick infection of the network. ... Warhol superworm is to pre-scan the network for vulnerable targets. ... The method for nominating a worm to attack a target is easy. ...
  • CERT Advisory CA-2001-23
    ... We believe the worm will begin propagating again on ... susceptible to the vulnerability described in CA-2001-13 Buffer ... time required to infect all vulnerable IIS servers with this worm ... and egress filtering should be implemented at the network edge. ...
  • Re: Windows based (H)IDS
    ... It may seems so obvious that snort library is very ... Security but it is a commercial product. ... > softwares can be added to the ... > over a network. ...
  • RE: Increasing ICMP Echo Requests
    ... internal network. ... Bruce Martins wrote: ... MSBLAST worm did, then ... **FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo ...