On Wed, 30 May 2007, Dave Ellingsberg wrote:
> B.) how do you find this host? In an edu setting we are open and many
> connections come and go from all parts of the world, and we have to
> allow them both ways on 80. So say from a firewall log built messsage
> how can I tell this is passwords and not normal web traffic?
I use dsniff and urlsnarf to see what the traffic is:
http://www.monkey.org/~dugsong/dsniff/
http://www.monkey.org/~dugsong/dsniff/faq.html
IPAudit shows traffic, host counts, and other interesting data on what's
going across your network.
http://ipaudit.sourceforge.net/images/ipaudit-web/ipaudit-home.png
Remote host counts will clearly show infected internal hosts that are
scanning hosts outside. I've gone up and told people their boxes were
infected before they notice them slowing down.
While this isn't directly logging, these tools allow me to see patterns in
the traffic and after watching for a week or so, you know what your
"normal" traffic patterns are and can investigate oddities (through logs
or other means).
Scott
Scott Delinger, Ph.D. [email protected]
IT Administrator http://www.chem.ualberta.ca/~scott
Dept of Chemistry, University of Alberta
Edmonton, Alberta, Canada T6G 2G2
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.