Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-sigs] Listeningpost IP |
|---|---|
| Date: | Sat, 29 Dec 2007 16:06:49 -0500 |
Because of a couple private requests, we're also reviving the spyware listeningpost at emerging threats. That's also down while the bleeding infrastructure has been taken offline. For those of you using David Glosser's DNS-BH (malware-domains.com) and want to point your spyware hits to the Spyware Listening Post, please use the following IP: 75.125.225.163 This also is resolved by listeningpost.emergingthreats.net. If you're nat familiar, this is a listening webserver that just logs the domain requested, URL, and user agent. We then have been feeding this to some normalizing scripts and have written a huge number of the spyware snort sigs from that data. In emerging threats we're going to expand that data mining in a number of ways. We'll be using that data to help make some smaller lists of more active domains, some advance warning for new fast flux domains, and hopefully some additional C&C tracking for http based botnets. First off though we're going to try to get some top 20 type lists of most active spyware, most active domains, oldest/newest c&c, etc. Eventually, if things go as anticipated, we may even be able to expand this to an auto-notify service if you register your source IPs to get a report of what came at us, and what likely infections we'd seen. More as we get there though! Matt -- -------------------------------------------- Matthew Jonkman Emerging Threats US Phone 765-429-0398 US Fax 312-264-0205 AUS Fax 61-29-4750-026 http://www.emergingthreats.net -------------------------------------------- PGP: http://www.jonkmans.com/mattjonkman.asc ------------------------------------------------------------------------- This SF.net email is sponsored by: Microsoft Defy all challenges. Microsoft(R) Visual Studio 2005. http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/ _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Snort-sigs] Replicating the Bleeding Rulesets, Matt Jonkman |
|---|---|
| Next by Date: | [Snort-sigs] Emerging Threats Daily Signature Changes, emerging |
| Previous by Thread: | [Snort-sigs] Replicating the Bleeding Rulesets, Matt Jonkman |
| Next by Thread: | [Snort-sigs] Emerging Threats Daily Signature Changes, emerging |
| Indexes: | [Date] [Thread] [Top] [All Lists] |