[logs] SonicWall firewall log Question....

From: Luke Cats (lcatsat_private)
Date: Tue May 28 2002 - 13:16:24 PDT

  • Next message: Bill Rhodes: "[logs] Remote logging to SQL DB with sysklogd-sql"

    Hello all,
    
    Can anyone advise me why an internal IP address is being noted as the
    destination IP during a dropped NetBus and SubSeven attack. This internal IP
    192.168.X.X happens to be the Private IP of the exchange server. Was this
    configured through the software or is something else happening.
    
    Warm Regards- Luke
    
      Clear your mind of can't.
       - Samuel Johnson
    ****************************************************************************
    ***********************
    
    This message is for the named person's use only.  It may contain
    confidential, proprietary or legally privileged information. No right to
    confidential or privileged treatment of this message is waived or lost by
    any error in transmission.  If you have received this message in error,
    please immediately notify the sender by e-mail or by telephone at 212 981
    6540, delete the message and all copies from your system and destroy any
    hard copies.  You must not, directly or indirectly, use, disclose,
    distribute, print or copy any part of this message if you are not the
    intended recipient.
    
    ****************************************************************************
    ************************
    
    
    

    --------------------------------------------------------------------- To unsubscribe, e-mail: loganalysis-unsubscribeat_private For additional commands, e-mail: loganalysis-helpat_private



    This archive was generated by hypermail 2b30 : Wed May 29 2002 - 00:24:02 PDT