[Dshield] Can someone please explain W32Nimda.A@mm(html) virus?

John Draper crunch at shopip.com
Wed Sep 11 19:52:21 GMT 2002


>There are situations where the content that triggers a rule can
>legitimately be in, say, an email.

But Emails have a specific port (110 or 25).   So the rule can be written with that in mind.

But then,  it's what you do with it,  once you detect the anomaly thats important.

John





More information about the list mailing list