Re: block a user from deleting their temp internet files

From: Herb Martin (news_at_LearnQuick.com)
Date: 03/30/05


Date: Tue, 29 Mar 2005 17:13:42 -0600

The log might be generated with SNORT -- a free
intrusion detection system but it can be used to
log most any traffic or even to alert you when
certain (illegal/undesirable) traffic is generated.

Runs fine on Windows or Linux either one.

-- 
Herb Martin
"Alan" <Alan@discussions.microsoft.com> wrote in message
news:4F3198E2-5D14-448C-9061-35482FAD8559@microsoft.com...
> Maybe this sounds too simple but how about running a script that copies
their
> history and temp files to a secure partition in which they don't have
rights
> to? Or better yet start interviewing other people....


Relevant Pages

  • Re: block a user from deleting their temp internet files
    ... The log might be generated with SNORT -- a free ... intrusion detection system but it can be used to ... log most any traffic or even to alert you when ... > history and temp files to a secure partition in which they don't have ...
    (microsoft.public.windowsxp.security_admin)
  • [UNIX] Buffer Overflow in Snort RPC Preprocessor
    ... A buffer overflow has been found in the Snort RPC normalization routines ... The first option will alert on any RPC fragmented record it finds. ... current packet length. ...
    (Securiteam)
  • unidentified DOS "bad traffic"
    ... A particular host has been completely flooding the network with ... My Snort output on ... I've read up on the Snort signature that generates this alert (SID ... So, I know of no exploit, no virus, no known malicious destination (which ...
    (Incidents)
  • Re[2]: Snort problem.
    ... JF> This isn't the snort mailing list, but here is something to help... ... Initializing Preprocessors! ... command line overrides rules file alert plugin! ...
    (FreeBSD-Security)
  • cerebus 1.2 beta data analysis tool
    ... What is CEREBUS? ... CEREBUS is a text-based full screen alert analysis system for Snort ... I got tired of futzing with statically compiling curses, ...
    (Focus-IDS)

Loading