Re: ipfw won't log anything?

From: Eirik Seim (eirik_at_mi.uib.no)
Date: 02/08/04


Date: 8 Feb 2004 16:36:07 GMT

On Sat, 07 Feb 2004 22:44:10 -0500, Wes Groleau wrote:
> I upgraded Mac OS 10.1.5 to 10.3.2
>
> Before, I would find bad guys' traces with
>
> grep ipfw /var/log/system.log
>
> Now that command returns nothing, but I notice the existence
> of a /var/log/ipfw.log which is always empty.
>
> Seems hard to believe that the upgrade would have logging
> disabled, but .... ?
>
> I added 'log' to all my rules (both allow and deny) and
> I still get no log entries.

Do you (still) have the option IPFIREWALL_VERBOSE in your kernel?
What does 'sysctl net.inet.ip.fw.verbose' return?

- Eirik

-- 
New and exciting signature!


Relevant Pages

  • Re: ipfw wont log anything?
    ... Eirik Seim wrote: ... I would find bad guys' traces with ... >> Now that command returns nothing, but I notice the existence ...
    (comp.security.firewalls)
  • Variant or original posting to packetstormsecurity - long
    ... I know that there have been traces posted of Dave ... The exploit posted on packetstormsecurity.org gave a remote command shell to ... the attacker. ... specific target for the victim to connect back to. ...
    (Incidents)
  • Re: despair
    ... make "$ FOO BAR" a meaningful DCL command. ... if ./ is not in $PATH then the existence of foo ...
    (comp.os.vms)
  • Re: Running Standalone Lisp Programs
    ... The existence and structure of command line arguments is not a portable ... Rahul Jain ... Professional Software Developer, Amateur Quantum Mechanicist ...
    (comp.lang.lisp)
  • Re: XP Bootscreen shown instead of XP Embedded
    ... B'cos he wont see any traces of xp embedded ... untill I use "winver" command to show the version ...
    (microsoft.public.windowsxp.embedded)