OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: strange windows behaviour.

From: Jeff Kell (jeff-kellutc.edu)
Date: Tue Oct 07 2003 - 12:42:44 CDT


John Sage wrote:

> From: Paul Russell <prussellnd.edu>

> In the past ten days, we have had five incidents in which
> student-owned computers in our residence hall network (ResNet) were
> used to send large quantities of spam.

If you keep PIX logs (we try to, though the volume is incredible) you
can look for connections inbound to the host spewing the spam. You can
even get a 1-for-1 connection list (sometimes) showing the incoming
proxy feed (from the REAL criminal) and the outgoing spam.

Of course, for you high-bandwidth folks logging is probably not an
option :-)

Jeff

---------------------------------------------------------------------------
----------------------------------------------------------------------------