Re: cuebot-d infection method
Jeff Bryner <[email protected]>
| Newsgroups | gmane.comp.security.incidents |
|---|---|
| Message-ID | <[email protected]> |
<harlan & jayson on where to look for post-mortem packet traces> Lacking full network packet logs, one thing I did during this one was look at flow data from our network infrastructure. <disclaimer>my flowdata knowledge is limited</disclaimer> This can be misleading, however because internal flow data will capture the outgoing attack packets that may get blocked later by a firewall. There also doesn't seem to be a one to one correspondence between the flow and what the firewall blocked outgoing. (i.e., the firewall records more blocks than the flow data shows ). Does someone with more flow-data/flow-tools experience know why this may be so? Jeff. P.S. Flow-tools example queries: http://www.splintered.net/sw/flow-tools/docs/flow-tools-examples.html