roxanne.tsui
Level 1
Level 1
Member since ‎12-03-2003
‎08-18-2017

User Statistics

  • 14 Posts
  • 0 Solutions
  • 5 Helpful votes Given
  • 0 Helpful votes Received
Recent Badges
First Discussion
5 Discussion Posts
10 Discussion Posts
1 Reply
5 Replies

User Activity

Hi, do we have a signature for the blackworm, or instructions for creating a custom signature to detect it. (http://isc.sans.org/blackworm) Thanks.
Hi, is there a command in IDS V4 which would show the serial number of the sensor, similiar to the show idprom for switches? Thanks.
In IPS V5 Inline Mode, should the second interface (where a packet comes out) of a paired interface be configured as a span port or a regular port? Where can I find more info about this? Thanks.
I used the idsDbCompact utility to compact the SecMon database which took a few hours. After the compaction, I cannot find in the database any alerts generated by the sensors during the compaction period. Is there a way to recover/retrieve those al...
We noticed that some of the events triggered by signature 4003 (Nmap UDP Port Sweep) look like responses from external DNS servers. The signature description also mentioned about this scenario. We wish to understand why the signature cannot track c...
Community Statistics
Member Since ‎12-03-2003 07:52 AM
Date Last Visited ‎08-18-2017 03:51 AM
Posts 14
Helpful Votes Given To