You can subscribe to this list here.
| 2002 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(3) |
Nov
(7) |
Dec
(7) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2003 |
Jan
(1) |
Feb
(4) |
Mar
(1) |
Apr
(4) |
May
(4) |
Jun
(1) |
Jul
(1) |
Aug
(5) |
Sep
(1) |
Oct
(2) |
Nov
(2) |
Dec
|
| 2004 |
Jan
(2) |
Feb
(2) |
Mar
(4) |
Apr
(3) |
May
(1) |
Jun
(2) |
Jul
(2) |
Aug
(6) |
Sep
(6) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2005 |
Jan
(6) |
Feb
(7) |
Mar
(5) |
Apr
|
May
(12) |
Jun
(2) |
Jul
(5) |
Aug
|
Sep
(1) |
Oct
(4) |
Nov
|
Dec
(3) |
| 2006 |
Jan
|
Feb
(5) |
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2007 |
Jan
|
Feb
|
Mar
(6) |
Apr
(2) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(3) |
Dec
(7) |
| 2008 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(1) |
Sep
|
Oct
(5) |
Nov
(2) |
Dec
|
| 2009 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(2) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2010 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2011 |
Jan
|
Feb
|
Mar
|
Apr
(3) |
May
(1) |
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2012 |
Jan
|
Feb
|
Mar
(3) |
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2013 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(1) |
Oct
|
Nov
|
Dec
|
| 2017 |
Jan
|
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Brown, M. <Mic...@In...> - 2005-02-21 06:35:47
|
dGhlIGZlZWRfZGIucGwgc2NyaXB0IGp1c3QgdGFpbHMgeW91ciBmaXJld2FsbCBsb2cgZmlsZSBh bmQgaW5zZXJ0cyB0aGUgZW50cmllcyBpbnRvIHRoZSBEQi4gdGhlcmUncyBub3RoaW5nIGVsc2Ug b3V0c2lkZSBvZiB0aGF0Li4uIGlmIHN5c2xvZyB3YXMgcmVzdGFydGVkIHlvdSBtaWdodCBoYXZl IHRvIHJlc3RhcnQgdGhlIGZlZWRfZGIgc2NyaXB0IHRvIHJlKG9wZW4pIHRoZSBmaWxlLiBJIG15 c2VsZiBzZXQgdXAgYSBzY3JpcHQgdG8ga2lsbCB0aGUgcHJvY2VzcywgcmVuYW1lIHRoZSBsb2cg ZmlsZSBhbmQgcmVzdGFydCBldmVyeXRoaW5nIGJhY2suLi4gDQogDQpNaWNoYWVsDQoNCgktLS0t LU9yaWdpbmFsIE1lc3NhZ2UtLS0tLSANCglGcm9tOiBNaWNoYWVsIExhY2NldHRpIFttYWlsdG86 bWljaGFlbEBzMmctbGltaXRlZC5jb21dIA0KCVNlbnQ6IFN1biAyLzIwLzIwMDUgMTE6MzYgUE0g DQoJVG86IGlwdGFibGVsb2ctdXNlcnNAbGlzdHMuc291cmNlZm9yZ2UubmV0IA0KCUNjOiANCglT dWJqZWN0OiBbSXB0YWJsZWxvZy11c2Vyc10gSGFuZGxpbmcgdmFyaWFibGUgbG9nIG5hbWVzPw0K CQ0KCQ0KDQoJSSd2ZSBiZWVuIHVzaW5nIHN5c2xvZy1uZyB0byBtYW5hZ2UgbXkgbG9ncywgYW5k IGhhdmUgaXQgZ2VuZXJhdGluZyBhIG5ldyANCglmaXJld2FsbCBsb2cgb24gYSBkYWlseSBiYXNp cy4gIERvZXMgSVBUYWJsZXMgbG9nIGhhbmRsZSB0aGlzIHNpdHVhdGlvbiwgb3IgDQoJd291bGQg c29tZSBwb2tpbmcgYW5kIHByb2RkaW5nIGJlIHJlcXVpcmVkIHRvIGdldCBpdCB0byB3b3JrPyAN Cg0KCU1pa2UgDQoNCg0KCS0tIA0KCS0tLS0tLS0tLS0tLS0tLS0tLS0tLVsgQ2lwaGlyZSBTaWdu YXR1cmUgXS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0gDQoJRnJvbTogbWljaGFlbEBzMmctbGltaXRl ZC5jb20gc2lnbmVkIGVtYWlsIGJvZHkgKDE3NiBjaGFyYWN0ZXJzKSANCglEYXRlOiBvbiAyMSBG ZWJydWFyeSAyMDA1IGF0IDA0OjM1OjU3IFVUQyANCglUbzogICBpcHRhYmxlbG9nLXVzZXJzQGxp c3RzLnNvdXJjZWZvcmdlLm5ldCANCgktLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tIA0KCTogQ2lwaGlyZSBoYXMgc2VjdXJlZCB0 aGlzIGVtYWlsIGFnYWluc3QgaWRlbnRpdHkgdGhlZnQuIA0KCTogRnJlZSBkb3dubG9hZCBhdCB3 d3cuY2lwaGlyZS5jb20uIFRoZSBnYXJibGVkIGxpbmVzIA0KCTogYmVsb3cgYXJlIHRoZSBzZW5k ZXIncyB2ZXJpZmlhYmxlIGRpZ2l0YWwgc2lnbmF0dXJlLiANCgktLS0tLS0tLS0tLS0tLS0tLS0t LS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tIA0KCTAwZkFBQUFB RUFBQUF0WlJsQ3NBQUFBQm9DQUFJQUFnQUNBQ0NGMkp3TDhGU1oxMkpIamFxaTRrZVdjaDBTdTEg DQoJdExZa3dHSEZlNmRibC9KZ0VBTVU1SFppM2JiQ0d6SHVCUk9nYWNnOGY3dlhsVGRGc3FFRDNG Z3BsZzhnOXdBNSANCglwT2x1SVFqUkVFL1EwelhWcjVhWFlMNEdrbG1xWmZCUTg5QXZHZkdRPT0g DQoJLS0tLS0tLS0tLS0tLS0tLS0tWyBFbmQgQ2lwaGlyZSBTaWduZWQgTWVzc2FnZSBdLS0tLS0t LS0tLS0tLS0tLSANCg0KDQoNCg0KCS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0t LS0tLS0tLS0tLS0tLS0tLS0tLS0gDQoJU0YgZW1haWwgaXMgc3BvbnNvcmVkIGJ5IC0gVGhlIElU IFByb2R1Y3QgR3VpZGUgDQoJUmVhZCBob25lc3QgJiBjYW5kaWQgcmV2aWV3cyBvbiBodW5kcmVk cyBvZiBJVCBQcm9kdWN0cyBmcm9tIHJlYWwgdXNlcnMuIA0KCURpc2NvdmVyIHdoaWNoIHByb2R1 Y3RzIHRydWx5IGxpdmUgdXAgdG8gdGhlIGh5cGUuIFN0YXJ0IHJlYWRpbmcgbm93LiANCglodHRw Oi8vYWRzLm9zZG4uY29tLz9hZF9pZD02NTk1JmFsbG9jX2lkPTE0Mzk2Jm9wPWNsaWNrIA0KCV9f X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fIA0KCUlwdGFibGVs b2ctdXNlcnMgbWFpbGluZyBsaXN0IA0KCUlwdGFibGVsb2ctdXNlcnNAbGlzdHMuc291cmNlZm9y Z2UubmV0IA0KCWh0dHBzOi8vbGlzdHMuc291cmNlZm9yZ2UubmV0L2xpc3RzL2xpc3RpbmZvL2lw dGFibGVsb2ctdXNlcnMgDQoNCg== |
|
From: Michael L. <mi...@s2...> - 2005-02-21 04:36:07
|
I've been using syslog-ng to manage my logs, and have it generating a new firewall log on a daily basis. Does IPTables log handle this situation, or would some poking and prodding be required to get it to work? Mike -- ---------------------[ Ciphire Signature ]---------------------- From: mi...@s2... signed email body (176 characters) Date: on 21 February 2005 at 04:35:57 UTC To: ipt...@li... ---------------------------------------------------------------- : Ciphire has secured this email against identity theft. : Free download at www.ciphire.com. The garbled lines : below are the sender's verifiable digital signature. ---------------------------------------------------------------- 00fAAAAAEAAAAtZRlCsAAAABoCAAIAAgACACCF2JwL8FSZ12JHjaqi4keWch0Su1 tLYkwGHFe6dbl/JgEAMU5HZi3bbCGzHuBROgacg8f7vXlTdFsqED3Fgplg8g9wA5 pOluIQjREE/Q0zXVr5aXYL4GklmqZfBQ89AvGfGQ== ------------------[ End Ciphire Signed Message ]---------------- |
|
From: Brown, M. <Mic...@In...> - 2005-02-08 05:56:47
|
cnVuIHRoaXMgc2FtZSBjb21tYW5kDQovdXNyL2Jpbi9wZXJsIC91c3IvbG9jYWwvYmluL2ZlZWRf ZGItc2hvcmV3YWxsLnBsIC0tYmFja2dyb3VuZA0KIA0Kd2l0aG91dCB0aGUgLS1iYWNrZ3JvdW5k DQovdXNyL2Jpbi9wZXJsIC91c3IvbG9jYWwvYmluL2ZlZWRfZGItc2hvcmV3YWxsLnBsDQogDQph bmQgc2VlIHdoYXQgZXJyb3JzIGl0IGdlbmVyYXRlcw0KIA0KTWljaGFlbA0KDQoJLS0tLS1Pcmln aW5hbCBNZXNzYWdlLS0tLS0gDQoJRnJvbTogRmVhdGkgVW5pdmVyc2l0eSAtIE5ldGFkbWluIFtt YWlsdG86bmV0YWRtaW5AZmVhdGl1LmVkdS5waF0gDQoJU2VudDogTW9uIDIvNy8yMDA1IDEwOjQ2 IFBNIA0KCVRvOiBpcHRhYmxlbG9nLXVzZXJzQGxpc3RzLnNvdXJjZWZvcmdlLm5ldCANCglDYzog DQoJU3ViamVjdDogW0lwdGFibGVsb2ctdXNlcnNdIEhlbHAgbWUNCgkNCgkNCg0KCUd1eXMsIA0K DQoNCglJIGhhdmUgcHJvYmxlbXMgc2V0dGluZy11cCAgbXkgZmVlZGVycyB1bmRlciBGZWRvcmEg Q29yZSAzIGFuZCBSSDkgDQoNCglNYWNoaW5lIDE6IFNob3Jld2FsbCAmIEZlZWRlcnMgKEZlZG9y YSBDb3JlIDMpIDE3Mi4yMy4xLjEgDQoJTWFjaGluZSAyOiBXZWIgJiBNeVNxbCAoUkg5KSAxNzIu MjMuMS40IA0KDQoJLS0gVW5kZXIgTWFjaGluZSAxIChmZWVkX2RiLXNob3Jld2FsbC5wbCkgLS0t IA0KDQoJbXkgJGRzbiA9ICdEQkk6bXlzcWw6aXB0YWJsZXM6MTcyLjIzLjEuNCc7IA0KCW15ICRk Yl91c2VyX25hbWUgPSAnaXB0YWJsZXNfYWRtaW4nOyANCglteSAkZGJfcGFzc3dvcmQgPSAneHh4 eHgnOyANCglteSAkbG9nX2ZpbGUgPSAnL3Zhci9sb2cvbWVzc2FnZXMnOyANCglteSAkcGlkX2Zp bGUgPSAiL3Zhci9ydW4vaXB0YWJsZWxvZy5waWQiOyANCg0KCS0tLS0tLS0tLS0tLS0tLS0tLS0t LS0tLSANCglUaGUgc2VydmljZSBvZiBpcHRhYmxlbG9nIGlzIHVwIA0KCShyb290ICAgICAxMzY2 NyAgMC4wICAwLjggIDkzODggNDQ2NCA/ICAgICAgICBTICAgIDExOjQ2ICAgMDowMCANCgkvdXNy L2Jpbi9wZXJsIC91c3IvbG9jYWwvYmluL2ZlZWRfZGItc2hvcmV3YWxsLnBsIC0tYmFja2dyb3Vu ZCkgDQoNCglidXQgbXkgRmVlZGVycyBvZiBkYXRhYmFzZSBkaWRuJ3QgdXBkYXRpbmcgbXkgbXlz cWwgc2VydmVyIDooIA0KDQoJUGxlYXNlIGhlbHAgbWUuLi4gDQoNCglCb2JieSANCg0KDQoNCg0K CS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0g DQoJU0YgZW1haWwgaXMgc3BvbnNvcmVkIGJ5IC0gVGhlIElUIFByb2R1Y3QgR3VpZGUgDQoJUmVh ZCBob25lc3QgJiBjYW5kaWQgcmV2aWV3cyBvbiBodW5kcmVkcyBvZiBJVCBQcm9kdWN0cyBmcm9t IHJlYWwgdXNlcnMuIA0KCURpc2NvdmVyIHdoaWNoIHByb2R1Y3RzIHRydWx5IGxpdmUgdXAgdG8g dGhlIGh5cGUuIFN0YXJ0IHJlYWRpbmcgbm93LiANCglodHRwOi8vYWRzLm9zZG4uY29tLz9hZF9p ZD02NTk1JmFsbG9jX2lkPTE0Mzk2Jm9wPWNsaWNrIA0KCV9fX19fX19fX19fX19fX19fX19fX19f X19fX19fX19fX19fX19fX19fX19fX19fIA0KCUlwdGFibGVsb2ctdXNlcnMgbWFpbGluZyBsaXN0 IA0KCUlwdGFibGVsb2ctdXNlcnNAbGlzdHMuc291cmNlZm9yZ2UubmV0IA0KCWh0dHBzOi8vbGlz dHMuc291cmNlZm9yZ2UubmV0L2xpc3RzL2xpc3RpbmZvL2lwdGFibGVsb2ctdXNlcnMgDQoNCg== |
|
From: Stephen D. <ste...@gm...> - 2005-02-08 04:02:50
|
Bobby, You need to troubleshoot why it is not updating your mysql database. Try using command line to access your mysql db from the feeder machine. I remember having a problem with the password format not being accepted by the version of mysql that i was using. If you find that is the case look up +mysql +oldpassword on google. sgdailey On Tue, 8 Feb 2005 11:46:32 +0800, Feati University - Netadmin <net...@fe...> wrote: > Guys, > > I have problems setting-up my feeders under Fedora Core 3 and RH9 > > Machine 1: Shorewall & Feeders (Fedora Core 3) 172.23.1.1 > Machine 2: Web & MySql (RH9) 172.23.1.4 > > -- Under Machine 1 (feed_db-shorewall.pl) --- > > my $dsn = 'DBI:mysql:iptables:172.23.1.4'; > my $db_user_name = 'iptables_admin'; > my $db_password = 'xxxxx'; > my $log_file = '/var/log/messages'; > my $pid_file = "/var/run/iptablelog.pid"; > > ------------------------ > The service of iptablelog is up > (root 13667 0.0 0.8 9388 4464 ? S 11:46 0:00 > /usr/bin/perl /usr/local/bin/feed_db-shorewall.pl --background) > > but my Feeders of database didn't updating my mysql server :( > > Please help me... > > Bobby > > ------------------------------------------------------- > SF email is sponsored by - The IT Product Guide > Read honest & candid reviews on hundreds of IT Products from real users. > Discover which products truly live up to the hype. Start reading now. > http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click > _______________________________________________ > Iptablelog-users mailing list > Ipt...@li... > https://lists.sourceforge.net/lists/listinfo/iptablelog-users > |
|
From: Feati U. - N. <net...@fe...> - 2005-02-08 03:46:43
|
Guys, I have problems setting-up my feeders under Fedora Core 3 and RH9 Machine 1: Shorewall & Feeders (Fedora Core 3) 172.23.1.1 Machine 2: Web & MySql (RH9) 172.23.1.4 -- Under Machine 1 (feed_db-shorewall.pl) --- my $dsn = 'DBI:mysql:iptables:172.23.1.4'; my $db_user_name = 'iptables_admin'; my $db_password = 'xxxxx'; my $log_file = '/var/log/messages'; my $pid_file = "/var/run/iptablelog.pid"; ------------------------ The service of iptablelog is up (root 13667 0.0 0.8 9388 4464 ? S 11:46 0:00 /usr/bin/perl /usr/local/bin/feed_db-shorewall.pl --background) but my Feeders of database didn't updating my mysql server :( Please help me... Bobby |
|
From: Kalpin E. S. <ka...@so...> - 2005-02-07 11:11:08
|
Hello iptablelog-users, I am installing iptablelog analyzer but seems not update. How can I solve this problem ? I am using RedHat Fedora Core 2. Thank you. -- Best regards, Kalpin mailto:ka...@so... |
|
From: Brown, M. <Mic...@In...> - 2005-01-31 19:24:38
|
This works pretty good, I changed mine 3 weeks ago and my system is running pretty smooth... (with 15 firewalls reporting to it). This month so far I have 18,339,864 entries in the database from all the firewalls (man I can't wait until tonight when I drop the db and create a new one for next month). My next goal is to make the web site/database faster. From the middle of the month to the end, the website gets slow doing queries. I even changed my beginning page to just list the last 60 entries. I move the original page to index2 and enabled all the report modules (that takes forever to load).=20 Btw it's definitely not the box as it is a dual xeon 733mhz with 2gigs of memory and scsi drives. Good work on finding the Memoize! Michael=20 -----Original Message----- From: sgdailey [mailto:sgd...@ro...]=20 Sent: Tuesday, January 04, 2005 12:58 AM To: ipt...@li... Subject: [Iptablelog-users] Memoize Test Its going great with Memoize, I hit it with heavy scans from a couple of different places at the same time and it doesn't fall behind whatsoever. My=20 cpu usage goes up but that's because I'm running openwrt on a linksys=20 router. (limited ram, 200 MHz proc). Thanks again for posting your tip. sgdailey=20 ------------------------------------------------------- The SF.Net email is sponsored by: Beat the post-holiday blues Get a FREE limited edition SourceForge.net t-shirt from ThinkGeek. It's fun and FREE -- well, almost....http://www.thinkgeek.com/sfshirt _______________________________________________ Iptablelog-users mailing list Ipt...@li... https://lists.sourceforge.net/lists/listinfo/iptablelog-users |
|
From: Robert S. <ip...@ba...> - 2005-01-04 19:30:07
|
Dear Gege, Thank you for the e-mail, I am sorry to hear about the hardware failure - these things do happen at the most inconvenient time. As you say the site is now up. I hope that getting the new machine operational does not cause you too much trouble. How are things in France? Regards Rob On Tue, 2005-01-04 at 19:09, gege wrote: > Dear Robert, > > The web site was down, following a hardware failure during my Xmas > holydays, I have found a temporary solution, but expect some > availability problems during the next few weeks till a new machine is > operationnal > > Sorry for this > > Gege > > Robert Slade wrote: > > Hiya, > > > > I have not been able to get into the web site - > > http://www.gege.org/iptables/ > > > > For server days now. Yesterday I got connection refused, today it just > > times out. > > > > Rob > > > > > > > > ------------------------------------------------------- > > The SF.Net email is sponsored by: Beat the post-holiday blues > > Get a FREE limited edition SourceForge.net t-shirt from ThinkGeek. > > It's fun and FREE -- well, almost....http://www.thinkgeek.com/sfshirt > > _______________________________________________ > > Iptablelog-users mailing list > > Ipt...@li... > > https://lists.sourceforge.net/lists/listinfo/iptablelog-users > > > > |
|
From: gege <ge...@ge...> - 2005-01-04 19:09:56
|
Dear Robert, The web site was down, following a hardware failure during my Xmas holydays, I have found a temporary solution, but expect some availability problems during the next few weeks till a new machine is operationnal Sorry for this Gege Robert Slade wrote: > Hiya, > > I have not been able to get into the web site - > http://www.gege.org/iptables/ > > For server days now. Yesterday I got connection refused, today it just > times out. > > Rob > > > > ------------------------------------------------------- > The SF.Net email is sponsored by: Beat the post-holiday blues > Get a FREE limited edition SourceForge.net t-shirt from ThinkGeek. > It's fun and FREE -- well, almost....http://www.thinkgeek.com/sfshirt > _______________________________________________ > Iptablelog-users mailing list > Ipt...@li... > https://lists.sourceforge.net/lists/listinfo/iptablelog-users > |
|
From: sgdailey <sgd...@ro...> - 2005-01-04 05:57:59
|
Its going great with Memoize, I hit it with heavy scans from a couple of different places at the same time and it doesn't fall behind whatsoever. My cpu usage goes up but that's because I'm running openwrt on a linksys router. (limited ram, 200 MHz proc). Thanks again for posting your tip. sgdailey |
|
From: Robert S. <ip...@ba...> - 2005-01-03 17:04:58
|
Hiya, I have not been able to get into the web site - http://www.gege.org/iptables/ For server days now. Yesterday I got connection refused, today it just times out. Rob |
|
From: Michael B. <Mic...@In...> - 2005-01-03 16:19:34
|
How did your test work out?=20 Thanks, Michael=20 -----Original Message----- From: sgdailey [mailto:sgd...@ro...]=20 Sent: Wednesday, December 29, 2004 6:30 PM To: ipt...@li... Subject: [Iptablelog-users] Using Memoize to speed up DNS Thanks to Michael Brown for pointing me in the right direction on the delay I was experiencing in the web page updates. I have modified feed_db.pl a little bit to use memoize to speed up name lookups. Memoize is a Perl module and can be downloaded here. http://perl.plover.com/Memoize/Memoize-1.01.tar.gz Memoize will cache results of a function, next time that function is called it will see if the arguments already have a cached result and if so will simply use the cached results instead of calling the function again. Here are the changes I made to feed_db.pl line 30 or so looks like this: use Socket; just add these next three lines under that line: use Memoize; memoize 'mygethostbyaddr'; sub mygethostbyaddr { gethostbyaddr(@_) }; I haven't tested it extensively yet but I'm hoping it wont continuously look up a host that has probed a thousand ports. I am about to flood the log and see how it handles it. I will post results. Thanks again to Michael Brown sgdailey ------------------------------------------------------- The SF.Net email is sponsored by: Beat the post-holiday blues Get a FREE limited edition SourceForge.net t-shirt from ThinkGeek. It's fun and FREE -- well, almost....http://www.thinkgeek.com/sfshirt _______________________________________________ Iptablelog-users mailing list Ipt...@li... https://lists.sourceforge.net/lists/listinfo/iptablelog-users |
|
From: sgdailey <sgd...@ro...> - 2004-12-30 00:12:59
|
I jumped the gun on my last mail and instead of explaining what I did wrong I will simply restart with the working version. Sorry I don't know Perl and I should have tested first. So to use memoize correctly to cut down on the lag time caused from numerous name lookups during heavy scans I did the following. Download the Perl module memoize from: http://perl.plover.com/Memoize/Memoize-1.01.tar.gz install according to README file then modify the feed_db.pl script as follows: Add the following lines after line 28; use Memoize; memoize 'mygethostbyaddr'; sub mygethostbyaddr { gethostbyaddr( $_[0], $_[1] ) }; so that line 28 through 31 looks like so: use Socket; use Memoize; memoize 'mygethostbyaddr'; sub mygethostbyaddr { gethostbyaddr( $_[0], $_[1] ) }; next find the section where name lookups occur from Michael Browns posting; my($iaddr) = inet_aton($entry{'SRC'}); my($host_name) = gethostbyaddr($iaddr, AF_INET); if (defined($host_name)) { $entry{"SRC_NAME"}=$host_name; } else { $entry{"SRC_NAME"}="unknown"; } and change it to read; my($iaddr) = inet_aton($entry{'SRC'}); my($host_name) = mygethostbyaddr($iaddr, AF_INET); if (defined($host_name)) { $entry{"SRC_NAME"}=$host_name; } else { $entry{"SRC_NAME"}="unknown"; } the only change is to add "my" in front of gethostbyaddr, this will now call the function you pasted in the first step. you can also do this for the Destination address lookup section which looks like; my($iaddr) = inet_aton($entry{'DST'}); my($host_name) = gethostbyaddr($iaddr, AF_INET); if (defined($host_name)) { $entry{"DST_NAME"}=$host_name; } else { $entry{"DST_NAME"}="unknown"; } should now look like my($iaddr) = inet_aton($entry{'DST'}); my($host_name) = mygethostbyaddr($iaddr, AF_INET); if (defined($host_name)) { $entry{"DST_NAME"}=$host_name; } else { $entry{"DST_NAME"}="unknown"; } again only adds "my" in front of the gethostbyaddr I leave that section commented out as per Michael Browns Posting because I don't need name resolution on Destinations which I already know. Sorry about the earlier email sgdailey |
|
From: sgdailey <sgd...@ro...> - 2004-12-29 23:29:48
|
Thanks to Michael Brown for pointing me in the right direction on the delay I was experiencing in the web page updates. I have modified feed_db.pl a little bit to use memoize to speed up name lookups. Memoize is a Perl module and can be downloaded here. http://perl.plover.com/Memoize/Memoize-1.01.tar.gz Memoize will cache results of a function, next time that function is called it will see if the arguments already have a cached result and if so will simply use the cached results instead of calling the function again. Here are the changes I made to feed_db.pl line 30 or so looks like this: use Socket; just add these next three lines under that line: use Memoize; memoize 'mygethostbyaddr'; sub mygethostbyaddr { gethostbyaddr(@_) }; I haven't tested it extensively yet but I'm hoping it wont continuously look up a host that has probed a thousand ports. I am about to flood the log and see how it handles it. I will post results. Thanks again to Michael Brown sgdailey |
|
From: Daniel T. <ju...@fu...> - 2004-10-12 03:04:34
|
I'd suggest checking out the newer code in CVS. It uses ulogd to get the data into the database which should be more reliable and more standard. If you want to wait for a new release, there should be one this month. Daniel Tarbuck Alan wrote: >Has anyone got this program working on Fedora Core 2.. >I have it working on RHE but I cannot get it to work on Fedora Core 2.. The webpage comes up but the log file is empty.. my log file in var/log/ is growing but it is not being transfered into the mysql log file so the logs.MYD file is 0... any ideas.. > > > > |
|
From: Alan <tw...@al...> - 2004-10-12 02:55:03
|
Has anyone got this program working on Fedora Core 2..=20 I have it working on RHE but I cannot get it to work on Fedora Core 2.. = The webpage comes up but the log file is empty.. my log file in var/log/ = is growing but it is not being transfered into the mysql log file so the = logs.MYD file is 0... any ideas..=20 |
|
From: Daniel T. <ta...@fu...> - 2004-09-28 16:56:49
|
There is a new version of the program in cvs. It used ulogd instead of a perl script to populate the mysql table. It might be worthwile to have a look at it, since new development on the project will be based on this version. The start-stop script for ulogd should be more reliable (as it will be distirbution specific and maintained by your distributor). The database schema are not compatible and there isn't (as of now) a script to convert the old logs to the new format. There should be a new release in the next few weeks. Daniel Tarbuck Jer...@al... wrote: >ben a écrit : > > >>maku bex wrote: >> >> >>>Starting iptables logfile analyzer: >>>/etc/rc.d/iptablelog: line 22: start-stop-daemon: >>>command not found >>> >>> >>you probably don't have the start-stop-daemon istalled. I got the debian >>package that it comes in and compiled it. the whole package didn't >>compile but startstop demon did, and it works fine on my slackware box. >>just google for start-stop-daemon. >> >> > >If you have a redhat based distribution, you can also use the >startup script by Eric Moret >See http://sourceforge.net/mailarchive/message.php?msg_id=3617182 > >It works fine on my sme-server (rh 7.3) >JJL > > >------------------------------------------------------- >This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170 >Project Admins to receive an Apple iPod Mini FREE for your judgement on >who ports your project to Linux PPC the best. Sponsored by IBM. >Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php >_______________________________________________ >Iptablelog-users mailing list >Ipt...@li... >https://lists.sourceforge.net/lists/listinfo/iptablelog-users > > |
|
From: <Jer...@al...> - 2004-09-28 07:27:21
|
ben a =E9crit : >=20 > maku bex wrote: > >Starting iptables logfile analyzer: > >/etc/rc.d/iptablelog: line 22: start-stop-daemon: > >command not found > > you probably don't have the start-stop-daemon istalled. I got the debian > package that it comes in and compiled it. the whole package didn't > compile but startstop demon did, and it works fine on my slackware box. > just google for start-stop-daemon. If you have a redhat based distribution, you can also use the startup script by Eric Moret See http://sourceforge.net/mailarchive/message.php?msg=5Fid=3D3617182 It works fine on my sme-server (rh 7.3) JJL |
|
From: ben <be...@po...> - 2004-09-28 07:11:01
|
maku bex wrote: >when i run...... >/etc/rc.d/iptablelog start > >it gives me the error : >Starting iptables logfile analyzer: >/etc/rc.d/iptablelog: line 22: start-stop-daemon: >command not found > >how to fix this problem..? > > > > > >__________________________________ >Do you Yahoo!? >New and Improved Yahoo! Mail - 100MB free storage! >http://promotions.yahoo.com/new_mail > > >------------------------------------------------------- >This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170 >Project Admins to receive an Apple iPod Mini FREE for your judgement on >who ports your project to Linux PPC the best. Sponsored by IBM. >Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php >_______________________________________________ >Iptablelog-users mailing list >Ipt...@li... >https://lists.sourceforge.net/lists/listinfo/iptablelog-users > > > > you probably don't have the start-stop-daemon istalled. I got the debian package that it comes in and compiled it. the whole package didn't compile but startstop demon did, and it works fine on my slackware box. just google for start-stop-daemon. |
|
From: maku b. <mak...@ya...> - 2004-09-28 06:51:14
|
when i run...... /etc/rc.d/iptablelog start it gives me the error : Starting iptables logfile analyzer: /etc/rc.d/iptablelog: line 22: start-stop-daemon: command not found how to fix this problem..? __________________________________ Do you Yahoo!? New and Improved Yahoo! Mail - 100MB free storage! http://promotions.yahoo.com/new_mail |
|
From: Michael B. <Mic...@In...> - 2004-09-24 15:56:17
|
Just a simple error on the install docs=20 Change this: create temporary tables on iptables.* iptables_user@localhost identified by 'xxx'; to this: create temporary tables on iptables.* to iptables_user@localhost identified by 'xxx'; it is missing the "to" right before the user Thanks, Michael -----Original Message----- From: Aslan Carlos [mailto:asl...@gm...]=20 Sent: Friday, September 24, 2004 10:33 AM To: ipt...@li... Subject: [Iptablelog-users] Problems With MySQL Hi!, I've try install the IpTablesLog, but I'd have a problem, in mysql. look the message erro: mysql> create temporary tables on iptables.* iptables_user@localhost identified by 'xxx'; ERROR 1064: You have an error in your SQL syntax near 'tables on iptables.* iptables_user@localhost identified by 'xxx' at line 1 but jump this step and continue the install this don't give more errors, but i access iptables main the page show with one problem, she don't show the Packets Droped, but in my /tmp have some archives with logs .. Please Help me, Sorry, I try do my best in my words, but I don't use English frequentily. No More, Thanks! Aslan Carlos=20 Linux Professional Engineer Brazilian =3D) ------------------------------------------------------- This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170 Project Admins to receive an Apple iPod Mini FREE for your judgement on who ports your project to Linux PPC the best. Sponsored by IBM. Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php _______________________________________________ Iptablelog-users mailing list Ipt...@li... https://lists.sourceforge.net/lists/listinfo/iptablelog-users |
|
From: Aslan C. <asl...@gm...> - 2004-09-24 14:33:11
|
Hi!, I've try install the IpTablesLog, but I'd have a problem, in mysql. look the message erro: mysql> create temporary tables on iptables.* iptables_user@localhost identified by 'xxx'; ERROR 1064: You have an error in your SQL syntax near 'tables on iptables.* iptables_user@localhost identified by 'xxx' at line 1 but jump this step and continue the install this don't give more errors, but i access iptables main the page show with one problem, she don't show the Packets Droped, but in my /tmp have some archives with logs .. Please Help me, Sorry, I try do my best in my words, but I don't use English frequentily. No More, Thanks! Aslan Carlos Linux Professional Engineer Brazilian =) |
|
From: Michael B. <Mic...@In...> - 2004-08-04 15:10:05
|
All,
=20
I made a change the feed_db.pl script. I started noticing after a period
of time (2-3 hours to 1 day) the web page would not report the current
entries in the firewall logs and I thought the perl script hung up or
stop; so I would stop/start the script over and over again. This seemed
to fix it as it would start inserting and showing the current firewall
log entries. After repeatedly doing this, I stopped the script from
running in the background so I could see where it fails. Finds out that
the script never fails, but actually starts to perform poorly due to all
the reverse dns lookups. This part of the perl script and function of
socket:=20
=20
my($iaddr) =3D inet_aton($entry{'DST'});
my($host_name) =3D gethostbyaddr($iaddr, AF_INET);
=20
is what does the reverse lookups for the source and destination ip
addresses. I get a lot of hits on my firewalls and the perl script would
just get further and further behind. 9am this morning, the script was
just now processing yesterdays entries at 2pm... so I made a change to
the script. Since I know the destination IP Addresses I changed the
script so that it would not perform reverse lookups on the destination
IP addresses. This changed made a world of difference, now the perl
script lags only 2-4 minutes behind and sometimes it shows current.=20
=20
I changed this (line 138 - feed_db.pl):
my($iaddr) =3D inet_aton($entry{'DST'});
my($host_name) =3D gethostbyaddr($iaddr, AF_INET);
if (defined($host_name)) { $entry{"DST_NAME"}=3D$host_name; } else {
$entry{"DST_NAME"}=3D"unknown"; }
=20
To this:
#my($iaddr) =3D inet_aton($entry{'DST'});
#my($host_name) =3D gethostbyaddr($iaddr, AF_INET);
#if (defined($host_name)) { $entry{"DST_NAME"}=3D$host_name; } else {
$entry{"DST_NAME"}=3D"unknown"; }
=20
$entry{"DST_NAME"}=3D"unknown";
=20
It would be better to cache the dns entries and use them later, but this
was quick and dirty for me.
=20
Thanks,
Michael Brown
Corporate Security Analyst
InterCept Corporate Security Services
Phone: 770.840.3918
Fax: 678.418.4797
A-Key: 1007-0101
=20
|
|
From: Michael B. <Mic...@In...> - 2004-08-04 14:58:39
|
All,
In a much needed solution, I made a few changes to
iptableslogs for what I needed immediately. Daniel Tarbuck is currently
re-writing the software, but until he releases that, I figured everyone
could use these updates as well. I have quite a few firewalls reporting
back to 1 database and needed some extra functionality. =20
=20
I tar'd up the files I changed and made them available here:=20
https://www.newdaysol.com/iptable-update.tar : MD5 Hash
f97ad5eebcdf25f8b51c10ea78e38c2b
=20
=20
Changes:
Created Modules/TopDestinations.php
Index.php / Elems.php
Added the current date and time on the right
above the top menu bar
Added a search function that will search all the
tables for what you are looking for and put the results in the=20
same tabulated format as the main page.=20
Added a TopDestination Modules that displays the
Top destination host, just like the Top Source hosts
Added a HTTP-Equiv=3DREFRESH to make the page
refresh every 30 seconds
=20
I don't plan on creating too much as Daniel will soon release his work,
but any modifications I do, I will share them with everyone.
=20
Thanks,
Michael
|
|
From: Salvatore B. <sa...@pi...> - 2004-08-03 10:21:05
|
Hi, I am happy if you update to me when the new software is ready !! =
good work !! :)
bye.
----------
=20
Salvatore.
----- Original Message -----=20
From: "Daniel Tarbuck" <ta...@fu...>
To: <ipt...@li...>
Sent: Tuesday, August 03, 2004 6:37 AM
Subject: Re: [Iptablelog-users] reporting
>=20
> I am working on a re-write of the software.
>=20
> I have dropped the perl script (log parser) in favour of ulogd and =
added
> some Reporting and Admin functionality. I am cleaning things up and =
will
> probably release a fork of this project (after contacting the author) =
in the
> near future.
>=20
>=20
>=20
> Daniel Tarbuck
>=20
>=20
> Salvatore Basso wrote:
>=20
> >Hi, also I would want to know if the project is still alive, I have =
approximately 10 installation of iptables and if the=20
> >project is finish I must unfortunately change to software :(
> >thanks.
> >
> >----------
> > =20
> > Salvatore.
> >
> >
> >----- Original Message -----=20
> >From: "Michael Brown" <Mic...@In...>
> >To: <ipt...@li...>
> >Sent: Monday, August 02, 2004 4:48 PM
> >Subject: [Iptablelog-users] reporting
> >
> >
> >Has anyone modified their instance to include reporting, show more
> >details and a query field? I've already changed mine to include
> >"TopDestination" stats on the right toolbar underneath "TopHosts" and =
I
> >am about to get more stats and queries underway... There haven't been
> >much development on this project and I am willing to help "revive" it =
or
> >contribute to it..
> >
> >=20
> >
> >Thanks,
> >
> >Michael=20
> >
> >=20
> >
> >
> >---
> >[This E-mail scanned for viruses by Declude Virus]
> >
> >
> >
> >-------------------------------------------------------
> >This SF.Net email is sponsored by OSTG. Have you noticed the changes =
on
> >Linux.com, ITManagersJournal and NewsForge in the past few weeks? =
Now,
> >one more big change to announce. We are now OSTG- Open Source =
Technology
> >Group. Come see the changes on the new OSTG site. www.ostg.com
> >_______________________________________________
> >Iptablelog-users mailing list
> >Ipt...@li...
> >https://lists.sourceforge.net/lists/listinfo/iptablelog-users
> > =20
> >
>
---
[This E-mail scanned for viruses by Declude Virus]
|