Jump to content

deeek

Members
  • Posts

    12
  • Joined

  • Last visited

Reputation

0 Neutral

About deeek

  1. Personally, I would check to see if you have been DDoS'd (perhaps unintentionally). We had a situation a couple of years ago where we had some clients on our network who we believe were part of a botnet. We noticed some odd activity coming from them and then afterwards we would get DDoS'd quite heavily. If you have the ability to check bandwidth statistics from your ISP that would be telling. What we ended up doing is separating our students onto a completely separate network, ISP and Smoothwall device and then we implemented a DDoS protection device from Radware to protect our primary network. Not sure what's going on with your time service. You may want to contact Smoothwall support for that. Let me know if you need any more info.
  2. We are getting this message quite often emanating from our DNS servers (they use Google's DNS servers for lookup, 8.8.8.8), not necessarily from particular clients. What IP address does it say that it's contacting? The users could be using custom DNS entries which might be getting tagged as suspicious. I have yet to find any conclusive evidence that this is anything but a 'keep an eye out for some suspicious activity' type of message. Has anyone else had these messages, or know where we can get more information for Snort events?
  3. That should be a fairly straightforward update. It didn't cause us too much grief.
  4. Ok, cool. I'm on Carisbrooke-5. You?
  5. koltz, I'm in the same boat as you. Were you able to figure this out?
×
×
  • Create New...