[Dshield] Snort-Ruleset for Sobig

John D. lists at webcrunchers.com
Sat Aug 23 04:17:37 GMT 2003

>This is a rule-set I whipped up to monitor internal traffic. It is by
>known sobig ports and the decrypted list of IPs posted on


Where is this ruleset?    I looked for it in the enclosed URL,  but just
saw the original article.


More information about the list mailing list