Solved

BLACKICE SERVER and Auto-Blocking

Posted on 2003-11-09
4
298 Views
Last Modified: 2010-04-11
Hi,
The Blackice server has an Auto-Block feature.
The auto-block, block only some types of known attacks.

We edit the .ini files and we add new entries to configuration, but, we need to make this entries with Auto-Block feature.

Is it possible to include some other attack types in Auto-Block feature?

Thanks for any help.
0
Comment
Question by:ipsystems
  • 3
4 Comments
 
LVL 18

Expert Comment

by:chicagoan
ID: 9712208
The auto-blocking feature will adjust firewall settings when it detects serious attacks. Therefore, if a hacker wanted to kick you off a server, the hacker could simply spoof attacks at your computer from the server. The auto-blocking feature would (in theory) then block all further access to the server in question. In order to guard against this, the product only triggers auto-blocking on attacks that are difficult/impossible to spoof. For a list of intrusions that trigger auto-blocking, please look in the file "issuelist.csv" in column 4. Note that you can edit this file yourself in order to cause auto-blocking to occur on attacks that you are concerned about
0
 
LVL 18

Expert Comment

by:chicagoan
ID: 9803991
Does that help?
Can you come back and close the question or post further comment?
0
 

Author Comment

by:ipsystems
ID: 9804008

Hi,
Yes I discover how to block the listed issues with IP|RST but I need to personalize new "customized attack types" to fit my needs....

I try to put other issues and rulez in issuelist.csv and Blackice.ini with a unique number...but sometimes it does not work....

I am trying to block File Downlods from some types and block Http_Posts or containing some words that I consider and trying to attack...


0
 
LVL 18

Accepted Solution

by:
chicagoan earned 500 total points
ID: 9804033
I'm not sure you can customize blackice in that fashion.
I think what you're looking for is going to have to proxy http for you so that you can examine the http requests.
Have you looked at urlscan?
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tools/urlscan.asp

btw: you have about 15 questions open in EE...
0

Featured Post

Get up to 2TB FREE CLOUD per backup license!

An exclusive Black Friday offer just for Expert Exchange audience! Buy any of our top-rated backup solutions & get up to 2TB free cloud per system! Perform local & cloud backup in the same step, and restore instantly—anytime, anywhere. Grab this deal now before it disappears!

Join & Write a Comment

This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
Nothing in an HTTP request can be trusted, including HTTP headers and form data.  A form token is a tool that can be used to guard against request forgeries (CSRF).  This article shows an improved approach to form tokens, making it more difficult to…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now