Re: Help me

From: Mitchell Rowton (mrowton_at_gmail.com)
Date: 02/28/05

  • Next message: Kurt Leum: "securing linux webserver?"
    Date: Sun, 27 Feb 2005 19:29:06 -0600
    To: Randy Johnson <randyj@holydiver.com>
    
    

    > So I make some caculation, every second, there are 16035 byte attack (I call
    > "attack" because I was not allowed.
    > Everybody help me explain this situation. I know, A request does not have
    > big capacity and my ISA server was not logged any attack!

    This sounds fishy. 16k a second in scans and other Internet trash is
    definitely possible, but it seems quite extreme for a company that had
    7gig total normal traffic.

    In addition to logging the drops, I'd go with the earlier suggestion
    to use mrtg and keep you ISP on its toes.

    --
    http://www.securitydocs.com/
    Directory of Security White Papers
    

  • Next message: Kurt Leum: "securing linux webserver?"

    Relevant Pages

    • RE: Help me
      ... my ISP give our company a report about the capacity download ... The problem is my isa server has logged at about 7GB data down/upload. ... although My isa firewall prevented almost requests from the untrust ... requests that not except (attack, scan ping ...) in a month. ...
      (Security-Basics)
    • [NT] Vulnerability Report for Windows SMB DoS
      ... cross-platform mechanism for client systems to request file services from ... In order to exploit the vulnerability a user account is needed for the ... is therefore vulnerable to a denial of service attack. ... Later in the processing of the request, at SRV.SYS+33209h another buffer ...
      (Securiteam)
    • RE: IIS log and ISA 2004
      ... requests are all sent by the IP address of the ISA Server other than the IP ... the web publishing is actually a reverse web proxy ... service will handle the request and response the remote client. ... the entry logged in the IIS Log shows that the visitor is the "ISA Server" ...
      (microsoft.public.windows.server.sbs)
    • RE: IIS log and ISA 2004
      ... > requests are all sent by the IP address of the ISA Server other than the IP ... > service will handle the request and response the remote client. ... > the entry logged in the IIS Log shows that the visitor is the "ISA Server" ...
      (microsoft.public.windows.server.sbs)
    • Re: ISAPI - Knowing if rule accepted or deny the request on POLICY_CHECK_COMPLETED
      ... An allow rule can deny if it is the last applicable rule for this traffic ... The same is true if the request matches any item in any of the exceptions ... Microsoft ISA Server Partners: Partner Hardware Solutions ...
      (microsoft.public.isa)