Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Rules » Backdoor.nibu.j

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Backdoor.nibu.j


Posted by yjones on March 31, 2005 09:23:13

It seems like I've looked all over google and found plenty of information
on what this virus does once infected, but I can find nothing about how it is transmitted or how to detect it. A few bloggers blame "vulnerabilites in MSIE" but I can find no further details. I figure if it's coming across the network through MSIE somehow, snort will come up with a rule for it. Is there already a
snort rule for this that's called something else? I couldn't find it using the search.