|
-
January 11th, 2003, 03:33 AM
#1
To properly defend you must attack
I am an IDS analyst and in my research studies I have come away with one inescapable conclusion. You must know how to pull off all the attempted hacks you see to be able to
properly recognize them, and obviously stop them.
Just looking at tcpdump/ethereal/... logs isn't enough you "must" know what to look for and
be able to recognize things. I would be interested to hear your thoughts.
-
January 11th, 2003, 03:50 AM
#2
I agree with you, don. Knowing how an attack works and how to succesfully pull it off is the greatest advantage you can have while protecting your system from it, in my opinion. If you think that a well-known hole in windows, for example, is being exploited on your system, you must know how it works and what to seal, or in this case where to get the patch 
Regards,
Silentstalker
-{[ Joe ]}- ( [email protected])
http://www.nitesecurity.com
[shadow]I\'m Just A Soldier In This War Against Ignorance.[/shadow]
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|