Incident response Questions


Dos attack
I have been receiving security alert messages from our firewall nearly everyday. e.g TCP Packet – Source:144.120.8.89,39341 Destination:192.168.1.1,25 – [DOS] TCP Packet – Source:210.7.0.36,3473 Destination:210.7.12.23,135 – [DOS] Thu, 2006-10-19 16:30:03 – UDP Packet – Source:192.168.1.111,1443 Destination:202.62.124.238,53 – [Any(ALL) match] can someone help me… Thanks in advance Wanz.

Answer Question   |  July 8, 2009  4:36 PM
Access control, Application security, backdoors, Biometrics, Browsers, Compliance, configuration, CRM, Current threats, Database, Digital certificates, Disaster Recovery, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

telnet, ssh, and vpn fail on completely open pix
We are setting up a pix internally in our net. The network behind it is a private range but we aren’t doing NAT. The outside address is public and we want external users to VPN to it to reach the private net. My management station is outside of the firewall and I can manage the [...]

Answer Question   |  October 9, 2006  6:09 PM
Firewalls, Forensics, Incident response, Intrusion management, Network security, VPN, Wireless
asked by:
0 pts.

asked by:
0 pts.

Sub-lease to include non-Domain members
The CEO of my company has asked me to look into some options for accomodating a request by a Non-profit to rent some of our unused office space. For the sake of this question, we have a single floor office and all cubes and offices are wired for voice and data and punched down in [...]

Answer Question   |  September 18, 2006  4:07 PM
Bandwidth, DataCenter, Firewalls, Forensics, Hardware, Incident response, Intrusion management, Network monitoring, Network security, Networking, Project management, Routers, Security, VPN, Wireless
asked by:
0 pts.

Monitoring the Network
Hi, I have multiple remote sites. I would like to monitor the network and analyze the traffic and its performance in general. For example, how the bandwidth is consumed, if certain activities are unnecessary and how to improve the networks performance by blocking through the firewall like peer-to-peer applications, etc. I am using check point [...]

Answer Question   |  October 24, 2008  12:51 AM
3Com, Availability, Bandwidth, Benchmarking, Cisco, Data analysis, Fault isolation, Firewalls, Forensics, Foundry, Incident response, Intrusion management, Network applications management, Network management software, Network monitoring, Network security, Network testing, Networking, Performance management, Protocol analysis, Remote management, Security, VPN, Wireless
asked by:
100 pts.

VPN & CISCO 2610 setup
Hello Sir/Madam, I cannot access our VPN from the internet outside our organization. I am using Cisco 2610 Router with IOS v12.3. And i created the access-list for the inbound and outbound connections. I have mentioned the access-list below and also i mapped a static IP address with the VPN server’s IP so it can [...]

Answer Question   |  November 28, 2007  1:25 AM
Availability, Cisco, DataCenter, Desktops, Firewalls, Forensics, Incident response, Intrusion management, Management, Microsoft Windows, Network security, Networking, OS, Security, Servers, SQL Server, VPN, Wireless
asked by:
0 pts.

asked by:
0 pts.

asked by:
0 pts.

SonicWall TZ170 std VPN SBS 2003
I can establish an VPN connection to my TZ170, but can’t access my SBS2003 server (can’t ping). My Sonicwall global VPN client ip 192.168.168.x TZ170 ip 192.168.168.x my external nic on server 192.168.168.x my internal nic on server 192.168.1.x The external nic is plugged into TZ170 and my internal nic and workstations are plugged into [...]

Answer Question   |  August 7, 2006  7:17 AM
Desktops, Firewalls, Forensics, Incident response, Intrusion management, Management, Microsoft Windows, Network security, OS, Security, Servers, SQL Server, VPN, Wireless
asked by:
20 pts.

Installation and updates
Howdy folks, Tryin to keep things going around here….need some advice. I have Win2003 servers and Active Directory…..single domain….approx. 100 client computers…..one location. Am upgrading all computers from Office XP to Office 2003. My project: Install Office 2003 and all updates remotely without going to each machine. My progress: I tried the method of creating [...]

Answer Question   |  April 23, 2008  9:36 PM
Access control, Active Directory, Application security, backdoors, Bandwidth, Browsers, Cabling, Cisco, Compliance, configuration, CRM, Current threats, Database, DataCenter, Desktop management applications, Desktops, Development, DHCP, Disaster Recovery, Distribution/logistics applications, DNS, Encryption, Ethernet, Exchange, filtering, Firewalls, Forensics, General Directories, Hacking, Hardware, Help Desk, Hubs, human factors, Incident response, Instant Messaging, Intrusion management, Lotus Domino, Management, Microsoft Office, Microsoft Operations Manager, Microsoft Systems Management Server, Microsoft Windows, Network applications management, Network management software, Network monitoring, Network protocols, Network security, Networking, Networking services, OS, Patch management, patching, PEN testing, Platform Security, Policies, Project management, Protocol analysis, Remote management, Risk management, Routers, Secure Coding, Security, Security Program Management, Servers, Software, Software testing, Spyware, SQL Server, SSL/TLS, Switches, Systems management software, TCP, Tech support, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

Network Connection Freezes
For some reason, at random, among 20 PCs on my network, in the morning or during the day, the network connection stops responding for both intranet and internet communications. The only solution thus far is to remove the NIC from the Device Manager, reboot the PC, and let Windows XP Pro find the network card [...]

Answer Question   |  September 1, 2010  11:31 AM
3Com, Access, Access control, Active Directory, Application security, Availability, Avaya, backdoors, Bandwidth, Bind, Biometrics, Browsers, Cabling, Cisco, Compliance, configuration, CRM, Current threats, Database, DataCenter, Dell, Desktops, DHCP, Digital certificates, Disaster Recovery, DNS, Encryption, Enterasys, Ethernet, Exchange, FDDI, filtering, Firewalls, Forensics, Foundry, Frame Relay, General Directories, H.323, Hacking, Hardware, Hewlett-Packard, Hubs, human factors, Identity & Access Management, Incident response, Instant Messaging, Interoperability, Intrusion management, IPv4, IPv6, Juniper Networks, LDAP, Lotus Domino, Lucent, Management, Microprocessors, Microsoft Office, Microsoft Windows, MPLS, NetBIOS, Network monitoring, Network protocols, Network security, Networking, Networking services, NFS, NIC, Nortel, Novell IPX/SPX, Novell NDS, OS, Patch management, patching, PEN testing, Performance management, Ping, Platform Security, Policies, Printers, provisioning, Risk management, Routers, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, SIP, Software, Spyware, SQL Server, SSL/TLS, Switches, TCP, Tech support, Trojans, Viruses, VPN, vulnerability management, Web security, WINS, Wireless, worms
asked by:
0 pts.

Tracking the computer or source of an email
system: Ex 2003 back-end cluster, Ex 2003 Network Load Balanced Front end. Hi there, A user’s account has become comprimised. They have since changed their password, but there are a few mails sent from their account that they did not send. Is it possible to find out the source ie PC hostname or IP address [...]

Answer Question   |  August 11, 2011  3:55 AM
Application security, Biometrics, Database, Digital certificates, Encryption, Exchange, Exchange security, Firewalls, Forensics, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, provisioning, Secure Coding, Security tokens, Single sign-on, VPN, Wireless
asked by:
0 pts.

Change Telnet port in Linux (Debian)
Hello everybody. I’m not a Linux expert, and am looking for a way to securely communicate with a Linux machine via Telnet. To avoid sending user and pwd without encryption I’m going to open a ssh tunnel (with putty or plink) forwarding port 22 (ssh) on the linux machine to another port, in which the [...]

Answer Question   |  July 19, 2006  11:13 AM
Firewalls, Forensics, Incident response, Intrusion management, Linux, Network protocols, Network security, Networking, TCP, VPN, Wireless
asked by:
63,535 pts.

Passwords
Hi all, What do you recommend for initial password issue, that is, provided a new user with a password for the first time without compromising it. I find the entire help desk giving password initially or sysadmins doing that is not save enough even though the user will be prompted to change it at first [...]

Answer Question   |  November 24, 2007  8:11 AM
Access control, Application security, backdoors, Biometrics, Browsers, Business/IT alignment, Compliance, configuration, CRM, Current threats, Database, Digital certificates, Disaster Recovery, Encryption, Exchange, Exchange security, filtering, Firewalls, Forensics, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

asked by:
0 pts.

Laptop Security…
Hi, I am the head of my department and by the nature of the job I hold some confidential information on my laptop. How do I ensure that 1. Nobody can access any files on my laptop from the LAN or the internet (not even sys admins) 2. If somebody tries to access, can I [...]

Answer Question   |  June 27, 2006  9:31 AM
Access control, Application security, backdoors, Biometrics, Browsers, Compliance, configuration, CRM, Current threats, Database, DataCenter, Digital certificates, Disaster Recovery, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Identity & Access Management, Incident response, Instant Messaging, Intrusion management, Network security, patching, PEN testing, Platform Security, Policies, provisioning, Risk management, Secure Coding, Security, Security Program Management, Security tokens, Servers, Single sign-on, Spyware, SSL/TLS, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.

runnunig application from the web….
Hi, I have an application server that is in my network and is a stand alone server,and I have ISA server 2004 in my domain with an valid IP address. Which access rule I should add to Isa that some external users can running application from the interner by typing our valid ip addressApplication Name(for [...]

Answer Question   |  June 26, 2006  5:18 PM
Access control, Browsers, filtering, Firewalls, Forensics, Incident response, Intrusion management, Network security, Networking, Security, Servers, SSL/TLS, VPN, Web security, Wireless
asked by:
265 pts.

Opinions about firewalls and VPN
I currently have watchguard firewalls and IPSec tunnels between them and the other watchguard firewalls. We also have remote users VPN into the firewall for access to our network. Our firewalls are fine but we haven’t been that happy with the support over the last 5 or so years. We are joining together with another [...]

Answer Question   |  June 28, 2006  9:56 AM
Active Directory, Application security, Budgeting, Cabling, Cisco, Database, Dell, Desktops, DHCP, DNS, Encryption, Exchange, Firewalls, Forensics, Foundry, Hardware, Hubs, Incident response, Instant Messaging, Intrusion management, Juniper Networks, Management, Microsoft Windows, Network security, Networking, Networking services, OS, Project management, Routers, Secure Coding, Security, Servers, SQL Server, Switches, VPN, Wireless
asked by:
0 pts.

How to Block Chat in the Network
Dear All, I am wrting this mail to you all, to know if any you have been successfull in Blocking Chats on your networks, and if so, then how have you acheived it? Could you please tell me which Ports to Block for MSN, Yahoo, Rediff, ICQ, Skype. I am using a NetAPPs Net Cache [...]

Answer Question   |  February 25, 2010  4:13 AM
Application security, Database, DataCenter, Encryption, Exchange, Firewalls, Forensics, Incident response, Instant Messaging, Intrusion management, Network security, Secure Coding, VPN, Wireless
asked by:
0 pts.

Local LAN Vulnerabilities and Open Ports NAT
QUESTION: How someone would go about exploiting a vulnerability within a LAN sitting behind a router running NAT/NAPT…where would you start? Hacking the open port? Routing Tables? Accessing remote administration on the modem? (disable NAT)?? bah… MY SYSTEM/SETUP: I have 1 XP SP2 Machine running providing PPTP VPN connections and a Webcam Security System (webcamxp) [...]

Answer Question   |  May 26, 2006  7:43 PM
Access control, Application security, backdoors, Browsers, configuration, Current threats, Database, Encryption, Exchange, filtering, Firewalls, Forensics, Hacking, human factors, Incident response, Instant Messaging, Intrusion management, Network security, Networking, patching, PEN testing, Platform Security, Secure Coding, Security, Servers, Spyware, SSL/TLS, Tech support, Trojans, Viruses, VPN, vulnerability management, Web security, Wireless, worms
asked by:
0 pts.