[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] PortSentry/LogCheck & Security Hardening Update 2.0.1



 >
 > After examing the details of the patch, it
 > > appears that this is very similar to the PortSentry/LogSentry apps.


I'm not an expert, that said:

I've noticed that portsentry works well in conjunction (after 3 days of watching) with the SHP.

I notice that the SHP port scanning tool gets triggered where the Portsentry app does not.

Portsentry seems to be in charge, with the SHP taking second seat.

Port sentry actively blocks (I know I'm getting scanned all day every day by my logs). The messages I have received from the SHP app have provided three alerts since install - all of them have been in reaction to standard name service queries (and from a machine on my local network -- which raised some concerns for me, but I checked and all seems well on offending machine).


--
"yup, yup, yup"