« Filefix Professional 2009 Cryptanalysis | Main | BotnetWeb: A Collection of Heterogeneous Botnets.. »

2009.03.31

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d835018afd53ef01156e9e7b6c970c

Listed below are links to weblogs that reference Conficker: Catch Me If You Can...:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

No Andrew, the above mentions the rules are only for variants A and B. Variant C no longer uses MS08-067 or any other type of active exploit.

Will your snort rules also detect conficker.c? I am assuming they will. Am I correct in my assumption?

The comments to this entry are closed.