Snort mailing list archives

RE: Preventing Attacks


From: "Hicks, John" <JHicks () JUSTICE GC CA>
Date: Wed, 26 Jun 2002 09:38:02 -0400

From your snippits I'll guess that your running Win32 ...
 
If I'm_Wrong Then Ignore

My best solution would be to use one of the BlackIce products according to
workstation or server and use the 'Auto-Block' feature of IDSCenter to write
attacking ip's to the blackice firewall.ini.

End If
 
hth,
 
John

-----Original Message-----
From: David Alexandre M. de Carvalho [mailto:david () medusa ubi pt]
Sent: Tuesday, June 25, 2002 9:40 AM
To: snort-users () lists sourceforge net
Subject: [Snort-users] Preventing Attacks


Hi all !

I've installed SNORT a few months ago to monitor some network activity.
Lately I've noted several messages in the log file, something like:

WEB-IIS cmd.exe [**] [Classification: Web Application Attack] .....
WEB-IIS ISAPI .ida attempt [**] [Classification: Web Application Attack]
.....

SCAN Proxy attempt [**] [Classification: Attempted information leak]
ICMP superscan echo [**] [Classification: Attempted information leak]

WEB-IIS CodeRed v2 root.exe access [**] [Classification: Web Application
Attack] .....


I installed the machines with maximum security, some firewall configuration,
etc
Can anyone help with this ? Any ideas ?
Thanks.
David Carvalho












Current thread: