Rubin's Homepage
Who's Online
 
Main Menu
Home
About
Required Reading
Short Fiction
Tech Zone
Politics
Movies
Contact Me
Dugg Stories
Gallery
--External Links--
The Nate Report!
Login Form





Lost Password?










Get Firefox

Get my gnupg public key

 

		  
	Home 
Snort DNS lookup rules Print
Thursday, 10 November 2005
As a part of my job I monitor the ResNet of a university for drones (trojan infections that 'phone home' somewhere allowing a cracker control of the infected system).

I created a tool today to convert a list of domain names which known trojans phone home to, to snort rules which alert on the DNS query. The generated rules are not a guarantee of infection (there are ways to trick people into resolving a trojans phone home address), however they work well as a sign to watch for evil traffic from a network host.

 
< Prev   Next >
Latest Photos
Current Weather
Weather at Minneapolis-St. Paul International Airport, MN - via NOAA's National Weather Service
NOAA - National Weather Service
Go to top of page