[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] BlackWorm technical information



On 1/24/06, Valdis.Kletnieks@xxxxxx <Valdis.Kletnieks@xxxxxx> wrote:
> The *interesting* question is whether it's possible to use this to count
> the *actual* number of affected machines by excluding all the rubberneckers
> that are visiting the page and hitting "refresh" to see the numbers go up.
> Maybe by looking at the Referer or User-Agent values?
>
>

That's what the Snort rule looks for, a connection to that page
without a Referer: tag. Not perfect, but it works well enough.

Mike
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/