Wondering what to do about all the intrusions you find in your firewall log?

From: Ed (ED@nowhere.com)
Date: 03/31/03


From: "Ed" <ED@nowhere.com>
Date: Mon, 31 Mar 2003 05:36:22 GMT

This is for the information of new people.

Wondering what to do about all the intrusions you find in your firewall
log?

There are two free sites that will process them for you:

1. www.dshield.org
It uses your firewall logs to generate statistics on worm and hacker
activity on the internet.

2. www.mynetwatchman.com
It processes your firewall logs together with those of other people and
companies, filters out false alarms, and notifies the internet service
providers or administrators of the infected computers that they have a
problem.

Both do a a bit of the other's specialty. You can submit you logs to both
if you like. I submit my logs to mynetwatchman for action, and to dshield
for industry statistics gathering.

Instructions are on their sites.

The more people participate, the more quickly infected computers, zombie
computers, and hackers can be fixed.

A useful site for networking advice is www.broadbandreports.com.



Relevant Pages

  • Re: Strange WAN Activity
    ... > firewall logs for a possible TCP FIN scan that keeps ... > company's intranet server IP and its port 80 across our ... > My firewall is a Sonicwall Pro 200 and I'm running W2K ... It's difficult to be sure without inspecting the web server for signs of ...
    (microsoft.public.win2000.security)
  • Re: Winvnc hack! [25 KB]
    ... came in from a service such as IIS that logs IP address. ... Check your IIS ... Some firewall software such as ... You can also use the NETSTAT -A command that comes with Windows to look at ...
    (microsoft.public.win2000.security)
  • RE: [fw-wiz] Log checking?
    ... tend to evaluate where and what logging is important in a different light. ... I've been happy to analyze a year's worth of firewall denied logs, ... have denied firewall traffic logs or denied logs with any relevant data. ...
    (Firewall-Wizards)
  • Re: false portscan alarm
    ... What is the reason of that treffic? ... and the browser and/or the "personal firewall" had decided to close those ... which each have a local source port above 1024 opened outgoing to port 80 ... I've had a dig through my own PIX logs, and while there is nothing for today ...
    (comp.security.firewalls)
  • Re: SOHO firewall dropping incoming 443 connections - incorrect state
    ... I take it this sample snip of your logs is from a single session? ... client host connecting to the firewall was a single host. ... because of the nature of HTTPS requests it uses a different ephemeral ...
    (comp.security.firewalls)