Questions for any network/security admins
Results 1 to 4 of 4

Thread: Questions for any network/security admins

  1. #1
    Registered User silencio's Avatar
    Join Date
    Sep 2000
    Location
    Savannah
    Posts
    3,960

    Questions for any network/security admins

    I log my PIX messages every day (have been for a long time now). Around the middle of august I started seeing about 10meg log files (compared to 2-4 meg average) of mostly ICMP traffic. Has anyone else noticed a change like this or is someone just ddosing me? I can't imagine that they are since traffic flows fine so that would make it a pretty lame ddos attack. Also, if it were a ddos attack where would be the best place to start to remedy it? FBI or the ISP first?

    Danke

  2. #2
    Banned TripleRLtd's Avatar
    Join Date
    Aug 2003
    Location
    SW Florida...eye of the storm.
    Posts
    7,251
    Go to www.GRC.com and use the tools there.
    In fact, read up on the whole site.
    Lots of invaluable info.

  3. #3
    Registered User silencio's Avatar
    Join Date
    Sep 2000
    Location
    Savannah
    Posts
    3,960
    Thanks but I've read that. Given the way the newest round of viri and hacks work I think alot of traffic is just coming from unpatched/unprotected machines but I want to make sure.

    The logs are from my PIX 515.

  4. #4
    Registered User craigmodius's Avatar
    Join Date
    Sep 2001
    Location
    Hellmira, NY, USA
    Posts
    1,572
    I would bet on the viruses being the cause. When blaster was making it's rounds port 135 was all I saw on our firewall.

    Do you use a log analyser? Maybe it's time to get one. We use an older webtrends version. Don't know if it supports the PIX 515, but here is a log analyser that claims to support the PIX 515 log format.

    And I have no experience with the PIX 515 or that log analyser, so take that advise for what it's worth

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •