<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDS and MYDOOM.BB in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ids-and-mydoom-bb/m-p/328009#M97062</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the sensor healthy? Is it generating any other alarms? What antivirus software are you using on the email server? What exactly is the antivirus software identifying the suspect attachments as? Do you have any  file samples that you could provide? Please email me directly at &lt;A href="mailto:mcerha@cisco.com"&gt;mcerha@cisco.com&lt;/A&gt; if privacy is a concern. If you send a live virus sample, please put it in a password protected ZIP archive before sending.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Feb 2005 22:36:16 GMT</pubDate>
    <dc:creator>mcerha</dc:creator>
    <dc:date>2005-02-17T22:36:16Z</dc:date>
    <item>
      <title>IDS and MYDOOM.BB</title>
      <link>https://community.cisco.com/t5/network-security/ids-and-mydoom-bb/m-p/328008#M97060</link>
      <description>&lt;P&gt;I have an Exchange server that is getting bombarded with MYDOOM.BB viruses.  The server virus software is detecting these, but we would like to determine the source.  However, my IDS 4215 which is monitoring that network segment is not alarming at all.  I have it updated with the S145 updates that are supposed to detect MYDOOM.BB virus activity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas as to what's going on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Dave&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:17:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-and-mydoom-bb/m-p/328008#M97060</guid>
      <dc:creator>davemit</dc:creator>
      <dc:date>2019-03-10T09:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: IDS and MYDOOM.BB</title>
      <link>https://community.cisco.com/t5/network-security/ids-and-mydoom-bb/m-p/328009#M97062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the sensor healthy? Is it generating any other alarms? What antivirus software are you using on the email server? What exactly is the antivirus software identifying the suspect attachments as? Do you have any  file samples that you could provide? Please email me directly at &lt;A href="mailto:mcerha@cisco.com"&gt;mcerha@cisco.com&lt;/A&gt; if privacy is a concern. If you send a live virus sample, please put it in a password protected ZIP archive before sending.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Feb 2005 22:36:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-and-mydoom-bb/m-p/328009#M97062</guid>
      <dc:creator>mcerha</dc:creator>
      <dc:date>2005-02-17T22:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: IDS and MYDOOM.BB</title>
      <link>https://community.cisco.com/t5/network-security/ids-and-mydoom-bb/m-p/328010#M97063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The signatures in S145 detect the pif and zip file formats associated with the virus Trend Micro identifies as MyDoom.BB.  Other virus vendors may label a different variant as MyDoom.BB.  Also, can you confirm that the sensor is seeing both sides of the traffic to your sensor?  Can you provide a traffic sample that we can use to research this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2005 00:25:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-and-mydoom-bb/m-p/328010#M97063</guid>
      <dc:creator>micballa</dc:creator>
      <dc:date>2005-02-18T00:25:14Z</dc:date>
    </item>
  </channel>
</rss>

