Firewall Wizards mailing list archives

Re: [Off Topic]: Modem data dump to log file.


From: Martin W Freiss <freiss.pad () sni de>
Date: Mon, 29 Sep 97 20:30:35 MEST

I generally do not enjoy asking off topic questions, but I really need
to know this and it is security related. How can I keep a log file of
every single byte sent and received over a modem line at the originating
computer (Windows 95 / PPP Connection).

I do know that some/most comm. programs provide for this type of
logging, but what if I'm not using such a program, and instead I use
Microsoft's Dialup Networking?

One solution to really get _every byte_ sent over a serial line, regard-
less of the protocol used, is a black box inserted into the line. I know
one product (mail me if you need the info, the name of the company
escapes me at the moment) that can log all traffic to another serial line
or via syslog, and can send SNMP traps or alert a pager when certain
(programmable) strings appear in the data stream. 

I quite like this approach for certain setups; it is very different
from the common software-only logging, which makes tampering with logs
unlikely to impossible, depending on the actual setup.

-Martin

--
 Martin Freiss, MF194   | freiss.pad () sni de | http://www.rmi.de/~marvin
 Siemens Nixdorf, CC IT Networks, Solution Team Internet/Intranet
Half male, half e-mail.  



Current thread: