RE: Did IDSes detect the SQL worm?
From: Gonzalez, Albert (albert.gonzalez@eds.com)
Date: 01/29/03
- Previous message: kyle.r.maxwell@verizon.com: "Re: SQLSlammer Worm & IDSs"
- Maybe in reply to: Todd Heberlein: "Did IDSes detect the SQL worm?"
- Next in thread: Garritano,Robert: "RE: Did IDSes detect the SQL worm?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Gonzalez, Albert" <albert.gonzalez@eds.com> To: focus-ids@securityfocus.com Date: Wed, 29 Jan 2003 14:15:14 -0500
RealSecure did pick up the worms activity. Snort didn't
because there was no signature at the time of the worm started
spreading. Though they did respond very quickly. Our Dragon
sensors aren't correctly running, so I can't verify them
Cheers!
Alberto Gonzalez
-----Original Message-----
From: Todd Heberlein [mailto:todd_heberlein@mac.com]
Sent: Tuesday, January 28, 2003 6:42 PM
To: focus-ids@securityfocus.com
Subject: Did IDSes detect the SQL worm?
Much has been made about the fact that the vulnerability exploited by
the MS-SQL worm has been known about for six months. So not only
should users have been aware of it, but IDS vendors should have been
aware of it.
Here is my question: Other than an IDS reporting an unusual amount of
traffic to port 1434, did any report the specific nature of the attack?
In other words, did any IDS report that the packet appears to attack a
vulnerability identified by CAN-2002-0649?
Thanks,
Todd
- Next message: Thierry Evangelista: "RE: SQLSlammer Worm & IDSs"
- Previous message: kyle.r.maxwell@verizon.com: "Re: SQLSlammer Worm & IDSs"
- Maybe in reply to: Todd Heberlein: "Did IDSes detect the SQL worm?"
- Next in thread: Garritano,Robert: "RE: Did IDSes detect the SQL worm?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|