XP firewall logs

From: Tim Chilton - Webtribe (tim.chilton_at_WEBTRIBE.NET)
Date: 08/17/04

  • Next message: Brian K. Dore': "Warning: SP2 doesn't deploy silently with SUS"
    Date:         Tue, 17 Aug 2004 21:09:42 +0100
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Does anyone have any ideas why MS decided to put the firewall log files in
    the c:\windows directory as a straight text file rather than using the event
    logs (ie a new firewall log)

    Think the logic through

    The OS directory is not supposed to be used for temporary files (and I
    include logs in this). How are we supposed to secure the OS areas if it
    creates logs there !??

    File based logs require NBT ports open so that you can read them remotely,
    this limits the effectiveness of the firewall.

    If event logs were in use, central management via MOM would be possible and
    all the standard event log handling tools could be used.

    Regards

    Tim

    -----
    NTBugtraq Editor's Note:

    Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you'll have to copy their email address out of the message and place it in your TO: field.
    -----


  • Next message: Brian K. Dore': "Warning: SP2 doesn't deploy silently with SUS"

    Relevant Pages

    • Re: is someone hacking me?
      ... I see similar entries in our firewall log but we do not allow forwarding to ... Also there's no FTP server running on any of our systems. ... Other stuff that files the firewall logs here are NETBIOS-NS probes. ...
      (comp.os.linux.security)
    • Re: Black Ice and Hackers :-)
      ... In your firewall log, do you ... If your alerts are say at ... Thank you for your concern.Allowed logs show nothing except, ... probably easier) to get into my ISP server and get info on clients from ...
      (comp.security.firewalls)
    • Re: XP firewall logs
      ... The default location of the firewall log can be changed. ... agree it would have been nice to see it as an event log. ... admins forward the logs to a syslog server if needed. ... How are we supposed to secure ...
      (NT-Bugtraq)
    • Re: logfiles
      ... In the event logs at least. ... But your firewall log should trap ... track access, then you aren't going to be able to track access very ... Jeff ...
      (microsoft.public.windows.server.networking)
    • Re: pfirewall.log
      ... firewall log to a DIFFERENT filename, ... On our XP machines, we audit the logs pretty regularly since there are 3 XP ... We name the log file MMYY.log on ...
      (microsoft.public.windowsxp.security_admin)