Why dont you build a snort signature for it first (what bleeding or VRT dont have one yet???)? Seeing how you guys run snort on your network ;)
So chalk it up guys, they use snort and McAfee, care to tell us your firewall types? Maybe an admin pw or something?
Cheers,
Michael Holstein CISSP GCIA Cleveland State University _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/