Re: IDS and Spywares

From: Eric Grejda (eric.grejda_at_sunrocket.com)
Date: 10/10/05

  • Next message: Jay Archibald: "Re: IDS and Spywares"
    Date: Mon, 10 Oct 2005 09:41:52 -0400
    To: neelabhsharma1@gmail.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Andrew Plato wrote:
    | A lot of the commercial ones do. TippingPoint has quite a few spyware
    | signatures. ISS has some. Don't know about Symantec or Cisco.
    |
    | Some AV will detect spyware, but not all. And even then, AV tends not to
    | be very good at blocking communication of already installed spyware.

    The Bleeding Snort ruleset (http://www.bleedingsnort.com/) detects quite
    a few spyware agents, in my experience.

    Speaking for myself and not my employers, as always.

    - --
    Eric Grejda
    System Administrator, Sunrocket - http://www.sunrocket.com/

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.7 (GNU/Linux)

    iD8DBQFDSm+eHJJGEDZR+J8RAnKhAJ9elxllcXTX//bhnwg5Yk0iqvRaAwCfTPGM
    uS82zf7pE5/UDJgDTUqbn/s=
    =K/gh
    -----END PGP SIGNATURE-----

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------


  • Next message: Jay Archibald: "Re: IDS and Spywares"

    Relevant Pages

    • Re: computer shuts down without error or warning
      ... If not a cooling problem, I'd suspect spyware or virus infection. ... without updating signatures, definitely not perfect. ... They're all free - and most pretty small, so they download quickly enough. ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: how to restore device drivers
      ... What does Device Manager say about these devices? ... Has she run a full antivirus scan with updated ... signatures and checked for spyware and trojans? ...
      (microsoft.public.windowsxp.device_driver.dev)
    • RE: Spyware & Registry changes
      ... you can always try removing it manually. ... After all, anti-spyware bots ... search for signatures, so you won't get in their way i suppose. ... > onto my laptop after formatting HD,it is now identifying spyware it can't ...
      (microsoft.public.security)
    • RE: Spyware drama!
      ... You could add signatures to an IDS/IPS/IDP system that detects the use of ... Spyware, and then hunt down the offending machine. ... signatures to their products now. ...
      (Security-Basics)
    • Re: how to develop adware or spyware
      ... Basically you must have a database of all the ad-ware and spyware you want ... to detect, the name (or may be signatures) of the files they use, the ... files or registry keys, and remove them. ...
      (microsoft.public.dotnet.languages.csharp)