Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




Security Incidents mailing list archives

Re: gw.ocg-corp.com
From: Christian Vogel <chris () obelix hedonism cx>
Date: Tue, 14 May 2002 00:18:52 +0200

Hi,

gw.ocg-corp.com - - [12/May/2002:20:29:08 -0400] "GET / HTTP/1.0" 200 18141 "-" "Opera/6.01 larbin2.6.2 () 
unspecified mail"
gw.ocg-corp.com - - [12/May/2002:20:31:04 -0400] "GET / HTTP/1.0" 200 18141 "-" "WinampMPEG/2.00 larbin () 
unspecified mail"

it's usually much better to use the IP-address in logfiles as the
reverse-lookup can

  1.) be spoofed (as this seems to be the case) when the
      logfile-writing program does not perform the
      secure 2-way lookups (ip->name, name->ips, ip is in ips)

  2.) change over time. Usually the netblock-ownership is more
      persistent.

(for apache: Set HostNameLookups to off which is the recommended
 setting anyway, setting it to "double" will do the 2-way lookup)

  Chris


-- 
With whispering winds / Our Martian future awaits / Like buds under snow
-- adrianhon on the kuro5hin.org Textad Haiku Contest

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]