Re: Attacks and Logs

From: Maxx Pollare (notmaxxpollare@deadspam.com)
Date: 08/02/02


From: Maxx Pollare <notmaxxpollare@deadspam.com>
Date: 2 Aug 2002 14:15:58 GMT


"Jean-Daniel Mālet" wrote in the message
<news:aie2c4$eqr$1@wanadoo.fr>

 [compacted]
> Hi!! Is it possible, by finely scannings the firewall's logs
> (or others methods), to detect an attack that the firewall has
> not detected himself? I dont need any details, I just want to
> know if it's possible.

That depends on the program/router/Nat & the logs...

If the log is just a record of "net traffic", finding a missed attack is
a pointless process. Your more likely to find more false positives then
actual attacks. Just achieve the files for later use & trust that the
firewall knows what it's doing.

(It's tough to do, I should know....)

-- 
Maxxwell C.G. Pollare - Insomnia is my drug of choice...

Spamail: maxxpollare@hotmail.com



Relevant Pages

  • RE: Trace of 139 attack?
    ... Subject: Trace of 139 attack? ... The Administrator account can be locked out if too many ... deleting the logs he cannot do it. ...
    (Focus-Microsoft)
  • RE: Trace of 139 attack?
    ... Subject: Trace of 139 attack? ... > deleting the logs he cannot do it. ... > If this box of yours is a web server to the world, ... > use it as file server with NetBIOS shares 'n stuff. ...
    (Focus-Microsoft)
  • Re: FTP server Service denial attack
    ... I did check the logs, it only happens for certain time ... Enabling Windows firewall on my server will do any good ... attack is from hijacked computers as the IP is allways ... With a decent IDS or firewall. ...
    (microsoft.public.inetserver.iis.ftp)
  • detecting a DDOS attack
    ... type of attack on our firewalls, though I've never heard of an attack ... behind the firewall, but I don't administer the firewall itself) don't ... I have been examining web server ... logs, and mail logs, and I scrutinize the output from LogWatch. ...
    (RedHat)
  • FW: Trace of 139 attack?
    ... Subject: Trace of 139 attack? ... The Administrator account can be locked out if too many ... deleting the logs he cannot do it. ... use it as file server with NetBIOS shares 'n stuff. ...
    (Focus-Microsoft)