Recently Viewed: Question4 > Question5 > Question6 > Question7 > Question8
Question8
Question N8

If you'd obtain such firewall logs from a production system, what source IPs or groups of such IPs you'd focus on as a highest threat?


Things To Look At


The common item to look for when reviewing log files is anything that appears out of the ordinary.
- CERT Coordination Center, Intrusion Detection Checklist



Dani@NL: what a question ! It really depends.... it depends on WHAT runs on them. Importance of Vulnerabilty you have. Assestment to know WHAT is vulnerable to what .... so then I know what to watch... but that is not an optin in our case, as we don't know in advance the LayoutHoney. We had to figure it partially out.


We might concentrate on outbound connection first, thus.
Sign of compromise, usually. OutgSYN - NotInbound

Also strange patterns are interesting to us.

The slow and 'strange' activities like those described in Question3 Question4 and Question6 often will be scary, but it will be impossible to actually trace it to something concerete, unfortunately.

So we have to decide where to concentrate to maximize efficency.

Here are some of the nodes which attracted us first.
They are not necessarily the right things to look at. They are just what WE looked at first. We did not want to lie in this SotM, so we did not always correct our mistakes. Eventually we explain our mistakes, but it has been important to make them to reach some conclusions.
"Sbagliando s'impara" is an italian way of saying.


Some Attackers:
62.126.79.x - The Mark of the Illuminati - a particular group of those messenger spammers - we loved NUMBERS in this challenge !
217.219.118.194 (5 packets to port 5 from Iran)
69.133.57.67 - Four packets to DstPort2 ... and that's it! :)
DailyFeb8 - We see some outbound connections



Related Pages
Timeline
Investigations
NotInbound
OutgSYN