PDA

View Full Version : Plugin for Logging and DShield?


MJ1
02-17-2003, 05:42 AM
I was reviewing Outpost Firewall and noticed some deficits that could be improved with plugins:

Is anyone interested in writing a plugin for DShield? You can learn more about DShield and obtain specs at http://www.dshield.org -- basically, the DShield network is an public-oriented early warning system. DShield captures firewall logs from network members to help determine what sort of attacks are happening around the Internet. For instance, DShield can help early detection of worms and trojans, etc. Membership in the network is open to anybody with a supported firewall. Unfortunately, Outpost is one of the few that are not supported, because nobody has written the software to obtain log info and transmit it to the DShield network. Anybody interested in writing such a plug in?

Also, is there any interest in somebody writing a more robust logging plugin in general for shield ? I notice that if I shutdown the firewall and and restart it, then the logs are wiped clean. There's no attack history to look at. Not that I can find anyway. Am I missing something? Or is there simply a lot of room for much better logging and log archiving?

RISC OS
02-17-2003, 01:03 PM
On the tool bar is a button called filter by time. Alter this and your logs will return!

I think most plugin writers create a plugin to suit their needs so unless someone you know can code c++, uses DShield and Outpost then your probably out of luck, sorry.

Maybe you should suggest it to PC Flank, they have created a plugin and have plans to create more so they may be interested in creating such a plugin.

MJ1
02-17-2003, 01:28 PM
No it doesn't work that way on the system I tested. For example, if I select Attack Detection, I saw log entries. But if I shut down Outpost and then restart it, the entries are gone. If I select "All" from the log filter button, still no entries. Why? Shouldn't there be a history available even if I stop the software and restart it? Where is it?

RISC OS
02-17-2003, 11:03 PM
Sorry MJ1,

I always thought all logs could use the Time filter but Attack Detection on my system too doesn't seem to keep it's logs either.

I think this a flaw maybe in the logging system and perhapes has been fixed in version 2's logging which is supposed to be much better.