|
|||||||||||
|
[Snort-sigs] sig for recent massive ICMP scans
From: SoloNet Newsfeed <newsfeed(at)solo.net>
Date: Thu Sep 25 2003 - 16:43:37 EDT I've seen that the packet size is always 106 bytes, this payload are is always 64. They scan the next netblock after hitting the .10 and .50 IPs of the previous class C which is the actual target of the scan. Header size is also 20 bytes. alert icmp $EXTERNAL_NET any -> $HOME_NET any (msg:"ICMP PING
Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs Received on Thu Sep 25 17:42:24 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:35 EDT |
||||||||||
|
|||||||||||