[<prev] [next>] [day] [month] [year] [list]
Message-ID: <43BDE579.4030206@linuxwiz.net>
Date: Fri Jan 6 03:35:46 2006
From: jeremy at linuxwiz.net (Gaddis, Jeremy L.)
Subject: Monitoring for Sober.Y with Squid and swatch
Here's an article I just wrote up real quick on how to monitor for
Sober.Y HTTP activity (set to begin at midnight 06-Jan-2006) using the
Squid proxy server and swatch.
Example configurations are provided. These are the swatch config
entries that I am using for monitoring Squid's access.log files for
(some of?) the hosts that Sober.Y is known to utilize and send alerts to
my e-mail and company pager.
I took the hosts from SANS' list on ISC. If there are any hosts that
I've missed, please do let me know.
The article can be found at http://www.jeremygaddis.com/
Thanks,
-j
--
Jeremy L. Gaddis, GCWN, Linux+, Network+
LinuxWiz Consulting
http://www.linuxwiz.net/
Powered by blists - more mailing lists