TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------
I was reviewing the logs of my server and checking the email,
it notifies the following message (also was displayed on the
engine console):
'PmapDump' event detected by the RealSecure engine at 'server'.
Details:
Source Address: 24.x.x.x
Source Port: 828
Source MAC Address: 00:xx:xx:xx:xx:xx
Destination Address: ip my range
Destination Port: Portmap (111)
Time: Thu Jan 13 20:03:11 CST 2000
Protocol: TCP (6)
Priority: high
Actions mask: 0x245
How can i know if the ENGINE, killed the attack when it was
detected, in the policies i have checked the kill option for the
RPC Attack, also checked the email notification, i was notified
by email, but i don`t know if the ENGINE really killed the attack?
Is there a way to know that the attack was killed succesfully.
Tkz, From Mexico.