Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email email@example.com
[ISSForum] Signature Configuration File Change
From: Jochen Wargulski (Wargulskit-online.de)
Date: Thu Dec 16 2004 - 14:36:16 CST
I have a question about one BlackIce Signature.
In the documentations stands if the firewall.ini oder the intrution.ini
would be change that blackice would trigger this event.
But in a company where i work. We have about 400 clients but this event
is not trigger when we change the policy or the profile.
Is it possible that ISS only means the autoblocker (autoprotector) that
would trigger this event when it would be change?
An other question is the importance of the signature. I am not realy
shure but is this event very important because some users use their
notebook in different networks (different ip addresses) ? When they
arrive in the office and blackice send the event to the siteprotector
console i do not knwo if the user was the traget or the source of an
attack why the network card work in promiscous mode.
Can somebody help me?
ISSForum mailing list
TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo/issforum
To contact the ISSForum Moderator, send email to mod-issforumiss.net
The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 Barfield Road, Atlanta, Georgia, USA 30328.