Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Securityfocus article: Forensic Log Parsing with Microsoft's LogParser

From: <oded(at)catholic.org>
Date: Tue Jul 29 2003 - 03:55:10 EDT


Very nice article indeed. Salutes to Mark.

I'd like to address just one more issue Mark seemed to have skipped - Attacks originating from a dial-up user.

The thing is that dial-up attackers will most likely change there IP from time to time, especially if their attempts last more than a couple of hours.

In this case, upon finding a suspicious ip, you might want to go to www.iana.org or www.ripe.net, and lookup the suspicios ip. This will get you the ISP of the attacker, and its allocated IP range. You can then modify the queries to group by the source ip's netmasked by the ISP range, or select only the ip's of the ISP and find suspicious activity from other IP's belonging to that ISP.

I apologize for not specifying the exact queries as mark did. This is due to the fact that I don't have the logs or tools infront of me. Sorry...

Well, those were my 2 cents,
Ta.

> This may be of interest to this list.


This email was sent using FREE Catholic Online Webmail. http://webmail.catholic.org/ Received on Tue Jul 29 09:30:51 2003

Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:54 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library