Security Incidents mailing list archives
Re: gw.ocg-corp.com
From: Christian Vogel <chris () obelix hedonism cx>
Date: Tue, 14 May 2002 00:18:52 +0200
Hi,
gw.ocg-corp.com - - [12/May/2002:20:29:08 -0400] "GET / HTTP/1.0" 200 18141 "-" "Opera/6.01 larbin2.6.2 () unspecified mail" gw.ocg-corp.com - - [12/May/2002:20:31:04 -0400] "GET / HTTP/1.0" 200 18141 "-" "WinampMPEG/2.00 larbin () unspecified mail"
it's usually much better to use the IP-address in logfiles as the reverse-lookup can 1.) be spoofed (as this seems to be the case) when the logfile-writing program does not perform the secure 2-way lookups (ip->name, name->ips, ip is in ips) 2.) change over time. Usually the netblock-ownership is more persistent. (for apache: Set HostNameLookups to off which is the recommended setting anyway, setting it to "double" will do the 2-way lookup) Chris -- With whispering winds / Our Martian future awaits / Like buds under snow -- adrianhon on the kuro5hin.org Textad Haiku Contest ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
Current thread:
- gw.ocg-corp.com netscience (May 13)
- Re: gw.ocg-corp.com Chip McClure (May 13)
- Got 'em. (was "Re: gw.ocg-corp.com") Jay D. Dyson (May 13)
- Re: Got 'em. (was "Re: gw.ocg-corp.com") Chip McClure (May 13)
- Re: Got 'em. (was "Re: gw.ocg-corp.com") Hugo van der Kooij (May 13)
- Got 'em. (was "Re: gw.ocg-corp.com") Jay D. Dyson (May 13)
- Re: gw.ocg-corp.com Jordan K Wiens (May 13)
- Re: gw.ocg-corp.com Christian Vogel (May 13)
- Re: gw.ocg-corp.com Will Aoki (May 13)
- Re: gw.ocg-corp.com Chip McClure (May 13)