Greetings! Devon Harding - GTHLA wrote:
I noticed in my log, I have out going http request from my DMZ web servers that are being rejected (by my 'any - any -any reject' rule) No one is on this machine, how are these requests being initiated? Is this a hack attempt?
Probably worse: most servers I've seen showing that behaviour were infected with a worm. Just plug a sniffer into your DMZ and capture some of the HTTP requests. The URLs tell quite a bit. Just compare to worm signatures (e.g. as in http://www.zerodeux.net/projects/wormstat/).
Bye Volker Tanger IT-Security Consulting -- discon gmbh Wrangelstra�e 100 D-10997 Berlin fon +49 30 6104-3307 fax +49 30 6104-3461 [EMAIL PROTECTED] http://www.discon.de/ ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
