Firewall Forensics
- 0
- Add a Comment
Firewall Forensics
http://www.robertgraham.com/pubs/firewall-seen.html
Forensics. The word will forever bring to the surface images of Thomas Naguchi answering questions from Marcia Clark and Jack Klugman as Quincy. By the time a medical forensics expert is called in, it’s usually too late - the victim’s already dead.
But firewall forensics can point a Linux user to potential holes before your system is completely exploited. The Firewall Forensics page is a great resource for evaluating your firewall logs and making changes based on what you’re seeing in those logs. The page includes a comprehensive table outlining TCP/UDP probes of your machine. This, by itself, would justify a quick visit to the site. But Firewall Forensics doesn’t stop there. It also includes details on source ports, DNS packets, X probes, ICMP, and many other types of firewall probes and attacks.
This is definitely a page to take some time with. If you absorb the information and put it into action on your Linux box, you may never need a Linux Quincy.
