Re: [fw-wiz] Log checking?

From: Adrian Grigorof (adrian_at_grigorof.com)
Date: 09/29/04

  • Next message: Ben Nagy: "RE: [fw-wiz] Log checking?"
    To: "Paul D. Robertson" <paul@compuwar.net>, <firewall-wizards@honor.icsalabs.com>
    Date: Tue, 28 Sep 2004 23:56:39 -0400
    
    

    We use the FireGen "IP Forensics" analysis
    (http://www.eventid.net/firegen/ipforensics_report.asp) to see what kind of
    traffic various applications generate. You can learn many things (for
    example, what a certain IM application does at startup, what is the Google
    bar recording in regards to the sites that you visit etc...) Quite often, we
    discover configuration problems (i.e. DNS requests against servers long
    gone).

    Regards,

    Adrian Grigorof

    ----- Original Message -----
    From: "Paul D. Robertson" <paul@compuwar.net>
    To: <firewall-wizards@honor.icsalabs.com>
    Sent: Tuesday, September 28, 2004 4:05 PM
    Subject: [fw-wiz] Log checking?

    [...]

    > I'm just wondering if the subset of folks who actually look at their
    > firewalls mostly looks at denied traffic only, or if it's a common
    > practice to look at the permitted stuff too? If so, what sorts of things
    > are you using, and are you finding anything interesting?
    [...]

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Ben Nagy: "RE: [fw-wiz] Log checking?"

    Relevant Pages

    • Re: removing "virtual memory too low" message
      ... > I don't see the virtual memory error anymore on my system. ... > first registry entry takes care of it. ... > Regards. ... >> available physical memory to run more applications, ...
      (microsoft.public.windowsxp.embedded)
    • Re: Windows 2000 Pro - Workstation service wont start.
      ... Thanks and regards, ... >You could try to unistall Client for Microsoft Networks ... >probably would fix it and while it should preserve your ... >> backing up applications and reinstalling the OS again, ...
      (microsoft.public.win2000.networking)
    • Re: Build database (Web) application or GUI without coding
      ... Have you had a look at CodeCharge Studio ... Regards ... David Montgomery ... > Can someone tell me if there is an applications that can build a good GUI ...
      (microsoft.public.access.dataaccess.pages)
    • Re: read/write loop MS Access
      ... Maybe because Access has been declared obsolete as DB backend for ... applications for a while ... Hope you can help - I can't see the wood for the trees any more. ...
      (microsoft.public.dotnet.languages.vb)
    • Re: HDD from old computer configured as USB disk....how do I
      ... Regards, ... Richard Urban ... > installing the application on more than one computer. ... > | Even though you install applications to a USB hard drive ...
      (microsoft.public.windowsxp.hardware)