Re: PLEASE HELP - USENET/Proxy Security Question

From: Thunder$truck (nealbailey_at_hotmail.com)
Date: 05/15/03


Date: 15 May 2003 12:24:22 -0500


 Luckily, I spoke with a systems administrator today and got him to allow me
to review the proxy logs for the last week. I told him it was for a
forensics course I'm taking. I spent hours reviewing the logs and it appears
that the routing (for the newsgroups) is done by the Usenet
provider. I saw clearly that my machine name was being logged and the IP
address to the news server was being logged as well but no sight
of the groups I've actually visited. I found the cache shares on the proxy
and it appears to only apply to http-web traffic.
I know there is a higher tier of administrators off-site that monitor
general events for hundreds of outfits but for
now it seems it's all clear. As for SMS, my company does not monitor
employees for the sake of investigating them, the remote control utility
(SMS) is used
for trouble-shooting with end-users.

TS

"Leythos" <void@nowhere.com> wrote in message
news:MPG.192d5baf3d161305989a7f@news-server.columbus.rr.com...
> In article <3ec2ae2a$0$49169$45beb828@newscene.com>,
> santyclaws@northpole.net says...
> > Question: (excuse my ignorance) How does MS Proxy (the WinSock Variety)
log
> > or monitor
> > Usenet activity? My network at work has amazing bandwidth (800KBPS+) and
> > I've begun using
> > it to connect to a third party Usenet provider from my work machine to
> > download mp3's, pictures,
> > and short video clips. My biggest concerns are, While connected to this
> > third party Usenet server
> > is the name of the group I'm connected to being broadcast anywhere? I've
run
> [SNIP]
>
> I've seen a BUNCH of people fired for this type of activity. The first
> thing they will do is determine who's using the pipe and for how long,
> then they will determine where you are connecting to. Once they see that
> you are connecting to a third-party news server, and that you've
> disabled the remote monitoring software, they may well fire you.
>
> MP3/Video, third party server, disabling remote monitoring application
> installed by your company - If it was my shop you would be fired. It's
> clear that you already understand what you are doing is WRONG, so, ask
> yourself if it's worth the price of your job!
>
>
> --
> --
> spamfree999@rrohio.com
> (Remove 999 to reply to me)



Relevant Pages

  • Re: OT - P2P
    ... Most people will send such logs to /dev/null after a few days. ... There are many legal P2P downloads available, ... the ISP is responsible for them. ... Oh, BTW, sorry, but monitoring news server use is exactly the same as web ...
    (rec.autos.sport.f1)
  • Re: Help need with monitor issues ( error code 10, hardware issues)
    ... I have tried simply setting it up by connecting the VGA cable to the comm ... If you power up the monitor with no cables connected to comp then you get a picture, square grid that flashes black and white. ... The guy who sold me the touchscreen said to change the video card settings to 800x600 pixels as the screen resolution may be too big for the touchscreen.......have tried doing this in display settings but to no avail. ...
    (microsoft.public.windowsxp.hardware)
  • Re: Help - How to read article when cursor changes to hand
    ... logs how *many* articles were accessed (with the NNTP ... other News server software may work ... of the headers mentioned are host specific. ...
    (news.software.readers)
  • Re: X fails to start - Intel i810 (845) - etch + testing
    ... the Xorg logs on my wife's machine and confirmed that it does *NOT* ... getting a bad mode setting that's not compatible with your monitor. ... 1280x1024 blah blah blah ...
    (Debian-User)
  • Re: Installer does not recognize my monitor
    ... panel>display>settings>and change the pixel slider from 1280 by 768 to 1024 ... how are you connecting your ... The display is listed as a plug and play standard monitor. ... > want to change the monitor I just want to update the Nvidia graphics driver. ...
    (microsoft.public.windows.mediacenter)