Page 1 of 1

new security feature

Posted: Sat Nov 08, 2003 12:21 am
by Red Squirrel
This is the best!

You might or might not know about my script that logs stuff and "autodetects" potential trouble and sets off alarms, and also checks rules such as IPs, well I just made it so it emails me as soon as there's an alarm and it looks like this:


A Status 2 alarm has been triggered at November 8, 2003, 12:09:05 am by IP: aaa.bbb.ccc.ddd.

Alarm text: "IP rule "aaa.bbb.ccc." matched with "aaa.bbb.ccc.ddd""

http://scada.iceteks.com - IceTeks Supervisory Control And Data Acquisition


.


Alarms range from status 1 to 5, 1 is something very minor. For example if I suspect someone doing something, I'll set stealth tracking/alarming on the user but not more then that, and just take a closer look at activity from any alarms that pop up, these are usually cleared off fast enough and disregarded as they are usually just false alarms and not much worry. The user in question is treated like any other user as for permissions and stuff. But a status 5 alarm is someone trying to guess passwords and such. Pround to say I only got like 3-4 of these, not more. Really, only alarms I've been getting lately are from this one IP I blocked ages ago. It is believed to be some chick at bbt who is a real B17ch. :D

With this new emailing system, I can forward the alarms to the intruder when I know for sure it's them. :lol:

Archived topic from Iceteks, old topic ID:1578, old post ID:13219

new security feature

Posted: Sat Nov 08, 2003 12:42 am
by Wren
That's very impressive, Red! :awesome:

Archived topic from Iceteks, old topic ID:1578, old post ID:13221

new security feature

Posted: Sat Nov 08, 2003 12:57 am
by manadren_it
BIG BROTHER IS WATCHING YOU!!! :lol:

nah. I'm not worried, but those who would cause harm to our little forum better take heed. :)

Archived topic from Iceteks, old topic ID:1578, old post ID:13222

new security feature

Posted: Sat Nov 08, 2003 2:55 am
by wldkos
manadren wrote: BIG BROTHER IS WATCHING YOU!!! :lol:

nah. I'm not worried, but those who would cause harm to our little forum better take heed. :)
Oh, very different from Big Brother. It's just security, not mind control.

Archived topic from Iceteks, old topic ID:1578, old post ID:13225

new security feature

Posted: Sat Nov 08, 2003 3:35 am
by Red Squirrel
manadren wrote: BIG BROTHER IS WATCHING YOU!!! :lol:

nah. I'm not worried, but those who would cause harm to our little forum better take heed. :)
Yep for sure. Normal users don't have to worry a thing. In fact, when I go through the logs all I look at is referrers, the page is too wide and I can't even see the IP unless I scroll horizontally to go see it but I never do since I have no reason to unless I see some potential dangeraus referrer such as a hacking site.

And for security well the script takes care of the tracking down of would-be trolls. It does not mean it elliminates them, it just tracks them down to get more info without me having to actually analyse the log.

A simple example of this is the guy who trolled in the shoutbox. I typed in his IP in my log system and bang, it shows all the entries in that day with that IP so I can follow his path. The user actually read a few of my articles, viewed a few threads and then started to troll in the shoutbox right after. I have a similar system for the forum, type in the username and bang, get all the entries.

The script get's pretty useful that's for sure and I'm glad I programmed it. Lot of small issues to work out but nothing serious.

Archived topic from Iceteks, old topic ID:1578, old post ID:13226

new security feature

Posted: Sat Nov 08, 2003 9:40 am
by Chris Vogel
What does Scada stand for?

Like Wren [s]said[/s] typed, that is impressive. Those meaning to do Iceteks harm better watch out!

Archived topic from Iceteks, old topic ID:1578, old post ID:13228

new security feature

Posted: Sat Nov 08, 2003 12:57 pm
by Red Squirrel
SCADA stands for Supervisory Control And Data Acquisition. When I worked in telecommunications in my placement there was a department I was with called SCADA and it was to monitor most of Ontario's circuits. If something went down, an alarm poped up, so I got the whole idea from that, and was curious myself to know what it stands for so I checked on google.

Archived topic from Iceteks, old topic ID:1578, old post ID:13230

new security feature

Posted: Sat Nov 08, 2003 2:12 pm
by manadren_it
wldkos wrote: Oh, very different from Big Brother. It's just security, not mind control.
Of course I know that, and the information red is collecting really isn't anything a person with enough knowledge and the right resources couldn't find anyway. Still if we ever did end up in a big brother situation, society in general that is, the first thing the proponents would say is that it's for security and normal people shouldn't worry. Just keep that in mind next time you hear someone speaking those words.

Archived topic from Iceteks, old topic ID:1578, old post ID:13232

new security feature

Posted: Sat Nov 08, 2003 2:46 pm
by Chris Vogel
manadren wrote:
wldkos wrote: Oh, very different from Big Brother. It's just security, not mind control.
Of course I know that, and the information red is collecting really isn't anything a person with enough knowledge and the right resources couldn't find anyway. Still if we ever did end up in a big brother situation, society in general that is, the first thing the proponents would say is that it's for security and normal people shouldn't worry. Just keep that in mind next time you hear someone speaking those words.
*Cough* Patriot Act *Cough*

Archived topic from Iceteks, old topic ID:1578, old post ID:13233