> When you install a name server on the box where Squid is and
> change /etc/resolv.conf you can see all queries of Squid
> (provided that no other software runs on the box).
Doesn't have to be on the same box as squid either.
It's still the NS logging not squid.
Amos
>
> -Marcus
>
> Thomas Raef
Well I have no idea what the name of the Trojan horse was.
But, our DNS server was down.
And I still had DNS querys over the network.
I thought that was strange. But I thought.. "Oh Well"
So, some time later on some PCs started to show Trojan behavior.
(Minesweeper autostarting etc)
I thought, oh
Hi Robin,
Robin-Vossen wrote:
Hello,
I wonder is there a way to log all DNS requests that go out of our network
with Squid.
Since I noticed that we had a Trojan Horse on our Company Network.
And well it didnt send it self the data out.
It did send DNS Querys to there DNS Server..
And a Firewall
Ok, damn.. :(
I just have to find something else to do that then..
Thanks for telling me :(
traef06 wrote:
>
>> Hello,
>> I wonder is there a way to log all DNS requests that go out of our
> network
>> with Squid.
>> Since I noticed that we had a Trojan Horse on our Company Network.
>> And we
When you install a name server on the box where Squid is and
change /etc/resolv.conf you can see all queries of Squid
(provided that no other software runs on the box).
-Marcus
Thomas Raef wrote:
Hello,
I wonder is there a way to log all DNS requests that go out of our
network
with Squid.
Sin
> Hello,
> I wonder is there a way to log all DNS requests that go out of our
network
> with Squid.
> Since I noticed that we had a Trojan Horse on our Company Network.
> And well it didnt send it self the data out.
> It did send DNS Querys to there DNS Server..
> And a Firewall doesnt detect that.
Hello,
I wonder is there a way to log all DNS requests that go out of our network
with Squid.
Since I noticed that we had a Trojan Horse on our Company Network.
And well it didnt send it self the data out.
It did send DNS Querys to there DNS Server..
And a Firewall doesnt detect that.
Is there a w