Place an ids in front of the server and write a rule for the traffic
signature.

Paul B.
Sent with Android

On Feb 23, 2010 3:25 PM, "Matt Sprague" <mspra...@readytechs.com> wrote:

The user could also be running the command inline somehow or deleting the
file when they log off.   Check who was logged onto the server at the time
of the attack to narrow down your search.  I like the split the users idea,
though it could be several iterations to narrow down the culprit.


-----Original Message-----
From: Ronald Cotoni [mailto:seti...@gmail.com]
Sent: Tuesday, February ...

Reply via email to