Greetings!

Devon Harding - GTHLA wrote:
I noticed in my log, I have out going http request from my DMZ web servers
that are being rejected (by my 'any - any -any reject' rule)
No one is on this machine, how are these requests being initiated? Is this a
hack attempt?
Probably worse: most servers I've seen showing that behaviour were
infected with a worm. Just plug a sniffer into your DMZ and capture some
of the HTTP requests. The URLs tell quite a bit. Just compare to worm
signatures (e.g. as in http://www.zerodeux.net/projects/wormstat/).

Bye

Volker Tanger
IT-Security Consulting

--
discon gmbh
Wrangelstra�e 100
D-10997 Berlin

fon    +49 30 6104-3307
fax    +49 30 6104-3461

[EMAIL PROTECTED]
http://www.discon.de/

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to