<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Difference a year makes, good news, bad news in Security</title>
<link>http://www.dslreports.com/forum/r12866346</link>
<description></description>
<language>en</language>
<pubDate>Sat, 05 Dec 2009 00:28:49 EDT</pubDate>
<lastBuildDate>Sat, 05 Dec 2009 00:28:49 EDT</lastBuildDate>

<item>
<title>Re: Difference a year makes, good news, bad news</title>
<link>http://www.dslreports.com/forum/remark,12875897</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : So I got to thinking about this and want to see how each month looked in terms of scans/attacks and the number of unique scanning systems.  The chart is rather interesting as we are doing much better then we were and there has not been a major new worm exploit since Sasser (last May) and even then Korgo did a much better job then Sasser did in terms of owning the internet.<br><br>The number of scans and attacks is on the decline (minor bump due to those lovely new unsecured Christmas computers), but we are doing better.  I would venture to say that the release of SP2 had a very noticeable effect on reducing malware traffic on the net.  I also believe that SP2 has also changed how malware authors generate IPs in their worms as they now use very localized scans and depend on email to actually distribute malware around the internet.  Gone are the days (or at least no one is releasing such worms) when worms like SQL Slammer would  own the internet after being started on a single system and then spreading out from there.  I would be willing to bet that the bots which were used against DSLReports where initially sent out as email attachments and then once they infected a system they scanned the local netblock for additional recruits but didn't tend to scan outside their local netblock.<br><br>Keep it up gang as we might have turned a corner on internet security and things are getting better.  I suspect there are a few more speed bumps ahead and by no means is it time to break out the bubbly and declare victory, but for the first time we are reducing the onslaught of attacks.<br><br>Blake<br>if your not running a firewall, what are you running???<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/12875897?c=788339&ret=L2ZvcnVtL3IxMjg2NjM0Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="26924 bytes" WIDTH=600 HEIGHT=434 SRC="/r0/download/788339.thumb600~ce2694efe70379b70f8d46878ddd4cec/Review.gif/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12875897</guid>
<pubDate>Thu, 10 Mar 2005 04:45:25 EDT</pubDate>
</item>

<item>
<title>Re: Difference a year makes, good news, bad news</title>
<link>http://www.dslreports.com/forum/remark,12874031</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : Comparing the Port 445 traffic from Feb/2004 as above, 61% of inbound 445 traffic was from my local netblock (x.*.*.*) and of that 73% was from my local netblock (x.x.*.*).  So it might be said that worms have also become more focused in 2005 on local netblocks then they were in 2004.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/12874031?c=788187&ret=L2ZvcnVtL3IxMjg2NjM0Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="9132 bytes" WIDTH=600 HEIGHT=222 SRC="/r0/download/788187.thumb600~b4306eb1b91ef22855c98017c2399abe/2004a.gif/thumb.jpg" ALT="Click for full size"></A><br>*.*.*.*</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/12874031?c=788188&ret=L2ZvcnVtL3IxMjg2NjM0Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="8667 bytes" WIDTH=600 HEIGHT=222 SRC="/r0/download/788188.thumb600~1b5ca0924acbd95280c1ee817a5831ab/2004b.gif/thumb.jpg" ALT="Click for full size"></A><br>x.*.*.*</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/12874031?c=788189&ret=L2ZvcnVtL3IxMjg2NjM0Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="13264 bytes" WIDTH=600 HEIGHT=222 SRC="/r0/download/788189.thumb600~9936aed85e7e4ab71ce43fda78d4528e/2004c.gif/thumb.jpg" ALT="Click for full size"></A><br>x.x.*.*</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12874031</guid>
<pubDate>Wed, 09 Mar 2005 22:20:52 EDT</pubDate>
</item>

<item>
<title>Re: Difference a year makes, good news, bad news</title>
<link>http://www.dslreports.com/forum/remark,12868529</link>
<description><![CDATA[<A HREF="/useremail/u/269961"><b>astirusty</b></A> : <div class="bquote"><SMALL>said by  jvmorris <A HREF="/useremail/u/360338"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR><div class="bquote"><SMALL>said by  astirusty <A HREF="/useremail/u/269961"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br><div class="bquote">If the filtering were done, I think it would allow a lot of attacks like the recent DDoS here at DSLR to be quickly minimized.  . . .  </DIV>I may be wrong, but (based on my understanding of what has just transpired here) that requires a very different kind of filtering, . . . and one with far higher overhead.  Filtering on source IP wouldn't have much impact; they were apparently valid, not spoofed, IP addresses.  Nor would filtering on destination port (TCP 80, I believe in this instance).  That would effectively cut off everyone on that netblock (infected or clean) from being able to browse the web!  </DIV>Poor (dumb) wording on my part.  I really meant "filtering" here to encompass the entire concept of egress/ingress filtering / logging at the ISPs connection to the outside world and the users to their ISP, and the idea of the ISPs cooperating together.  Additionally the partial automation of tracking down the sources of the scans/attacks and terminating their connections.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12868529</guid>
<pubDate>Wed, 09 Mar 2005 12:51:44 EDT</pubDate>
</item>

<item>
<title>Re: Difference a year makes, good news, bad news</title>
<link>http://www.dslreports.com/forum/remark,12868341</link>
<description><![CDATA[<A HREF="/useremail/u/360338"><b>jvmorris</b></A> : <div class="bquote"><SMALL>said by  astirusty <A HREF="/useremail/u/269961"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>. . . This type of filtering has been discussed at DSLR before and just recently in this thread &raquo;<A HREF="/forum/remark,12846659~mode=flat">Re: BBR DDos - going after the bad guys</A> </DIV>Sorry, I needed to take a minute and go over there and refresh my memory.  <br><br>Okay, I was talking about some really simple port-filtering on these routers (man, I wish someone would give us the name for what these things are called!).  And, specifically of outbound traffic to Port 445 (anywhere, not just on the local subnet).  I don't think there's any valid reason for outbound to Port 445, at least not in the context of ISP blocks ostensibly serving home/personal/SOHO users.  I'd need to do a bit more research, but obviously blocking outbound to Ports 135-139 is another possibility.  This, of course, would have no impact on a home/personal/SOHO user who wanted to use any of these capabilities <I>within</I> their <I>private</I> LAN.  The ISP's routers would never see this traffic.<br><br>Now, Keith (in the other thread) brings up another kind of simple filtering that could be done on these particular routers:  checking the ostensible source IP addresses to ensure that they are legitimate for that router and the subscribers that should be connected to it.  Any ISP that wanted to do this could largely eliminate the possibility that their subscribers were being used in attacks relying on spoofed IP addresses.<br><br>I <I>think</I> that both of these kinds of filters should be fairly low overhead on the router CPUs.<br><br><div class="bquote">If the filtering were done, I think it would allow a lot of attacks like the recent DDoS here at DSLR to be quickly minimized.  . . .  </DIV>I may be wrong, but (based on my understanding of what has just transpired here) that requires a very different kind of filtering, . . . and one with far higher overhead.  Filtering on source IP wouldn't have much impact; they were apparently valid, not spoofed, IP addresses.  Nor would filtering on destination port (TCP 80, I believe in this instance).  That would effectively cut off everyone on that netblock (infected or clean) from being able to browse the web!  <br><br>No, I think you'd either have to do deep-packet inspection (DPI, I think is a term coming into vogue these days) to ascertain the actual <I>contents</I> of the packet or you'd have to monitor the <I>volume</I> of packets being sent to a particular remote IP address.  I think both of these are far more CPU-intensive tasks than what Keith and I have discussed.  And the rules wouldn't be simple.  In the first case, you'd need a signature for the packets that indicated a problem (and that could literally change in a matter of hours).  I don't think there was any malicious code in the packets being used to DDoS BBR/DSLR (but I could be wrong on that, since I'm not privy to the research done).  In the second instance, what constitutes an unusually high <I>volume</I> of packets to a <I>particular</I> remote IP address is very likely to vary from one remote IP to another.<br><SMALL>--<br>Regards,    Joseph V. Morris</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12868341</guid>
<pubDate>Wed, 09 Mar 2005 12:28:52 EDT</pubDate>
</item>

<item>
<title>Re: Difference a year makes, good news, bad news</title>
<link>http://www.dslreports.com/forum/remark,12867921</link>
<description><![CDATA[<A HREF="/useremail/u/269961"><b>astirusty</b></A> : <div class="bquote"><SMALL>said by  jvmorris <A HREF="/useremail/u/360338"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR> What we're talking about here is that very first IP address in the traceroute that's directly under the ISP's control, correct?</DIV>That is what I am thinking.<br><br>This type of filtering has been discussed at DSLR before and just recently in this thread &raquo;<A HREF="/forum/remark,12846659~mode=flat">Re: BBR DDos - going after the bad guys</A><br><br>If the filtering were done, I think it would allow a lot of attacks like the recent DDoS here at DSLR to be quickly minimized.  With the ISPs cooperating -- reporting, tracking and blocking could be partially automated.  But as somebody pointed out, getting ISPs outside the U.S. to legally comply would be nearly impossible.  You have to show them a financial reason to do so.  <I>Either that or we start WWW2, which is designed from ground up with hacker and crackers in mind.  And all those wanting to connect to WWW2 have to comply with specific regulations.  Pipe-dream!</I>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12867921</guid>
<pubDate>Wed, 09 Mar 2005 11:29:57 EDT</pubDate>
</item>

<item>
<title>Re: Difference a year makes, good news, bad news</title>
<link>http://www.dslreports.com/forum/remark,12867827</link>
<description><![CDATA[<A HREF="/useremail/u/269961"><b>astirusty</b></A> : <div class="bquote"><SMALL>said by  Link Logger <A HREF="/useremail/u/356416"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>drilling into this almost 98% came from x.x.*.* and at this level we see the spread of source for 445 scans. </DIV>So if we want to clean up the internet of all these scans - we just need to get your entire sub-domain blocked?!?  :o ;) :)<br><br>On a serious note, this information is very interesting.  I am taking a SWAG here, but the viruses/worms are setup this way so they draw less attention?  <I>Because the hackers know (or believe) the ISPs have not in the past monitored or filtered at these levels??</I>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12867827</guid>
<pubDate>Wed, 09 Mar 2005 11:17:16 EDT</pubDate>
</item>

<item>
<title>Re: Difference a year makes, good news, bad news</title>
<link>http://www.dslreports.com/forum/remark,12867806</link>
<description><![CDATA[<A HREF="/useremail/u/360338"><b>jvmorris</b></A> : Now <B>that</B> is an interesting set of graphics! :)<br><br>But the <I>last</I> one is kinda scary!  (That's the various Class C subnets there, isn't it?)<br><SMALL>--<br>Regards,    Joseph V. Morris</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12867806</guid>
<pubDate>Wed, 09 Mar 2005 11:13:19 EDT</pubDate>
</item>

<item>
<title>Re: Difference a year makes, good news, bad news</title>
<link>http://www.dslreports.com/forum/remark,12867775</link>
<description><![CDATA[<A HREF="/useremail/u/360338"><b>jvmorris</b></A> : <div class="bquote"><SMALL>said by  astirusty <A HREF="/useremail/u/269961"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>I believe it is going to take egress and ingress filtering not only where traffic comes into and out of an ISPs domain (where the ISP connects to the outside world), but also filtering done where the ISP's users connect to the ISP.  Not the user end where the user modem or interface is (these would likely get disabled by hackers).  But user egress and ingress filtering at the point where the ISP's connect the users to their network work (the users merge with the ISP's sub-nets).</DIV>Yes, that was what I was thinking.  There's a name for the routers/collectors/concentrators that provide this function, but it eludes me at the moment (not being at all experienced in that part of Internet architecture).<br><br>From running traceroutes directly from here (and regardless of whether I was using a dial-up or ADSL connection), I would typically pass through three or four 'internal' IP addresses before hitting the public internet.  What we're talking about here is that very first IP address in the traceroute that's directly under the ISP's control, correct?<br><SMALL>--<br>Regards,    Joseph V. Morris</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12867775</guid>
<pubDate>Wed, 09 Mar 2005 11:09:23 EDT</pubDate>
</item>

<item>
<title>Re: Difference a year makes, good news, bad news</title>
<link>http://www.dslreports.com/forum/remark,12867682</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : In Feb/2005 80% of all inbound 445 scans came from my local netblock x.*.*.*, drilling into this almost 98% came from x.x.*.* and at this level we see the spread of source for 445 scans.  Hence you can say the most prevalent worms only vary the last two number of your IP Address when scanning.  So if my local ISP wanted to drop their network bandwidth and load, they could by cleaning up locally infected systems or filtering various ports like 445.<br><br>I will add these three charts to my page which show this.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/12867682?c=787861&ret=L2ZvcnVtL3IxMjg2NjM0Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="8748 bytes" WIDTH=600 HEIGHT=222 SRC="/r0/download/787861.thumb600~b5e9b4f86ce43ca65bd79c894c4a924c/1.gif/thumb.jpg" ALT="Click for full size"></A><br>*.*.*.*</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/12867682?c=787862&ret=L2ZvcnVtL3IxMjg2NjM0Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="8818 bytes" WIDTH=600 HEIGHT=222 SRC="/r0/download/787862.thumb600~274a01ad7ad7ad7d73d5f0b399ae5db2/2.gif/thumb.jpg" ALT="Click for full size"></A><br>x.*.*.*</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/12867682?c=787863&ret=L2ZvcnVtL3IxMjg2NjM0Ni54bWw%3D"><IMG class="apic" BORDER=0 TITLE="12721 bytes" WIDTH=600 HEIGHT=222 SRC="/r0/download/787863.thumb600~068ae40523a24c9ef54edefd375e542d/3.gif/thumb.jpg" ALT="Click for full size"></A><br>x.x.*.*</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12867682</guid>
<pubDate>Wed, 09 Mar 2005 10:58:33 EDT</pubDate>
</item>

<item>
<title>Re: Difference a year makes, good news, bad news</title>
<link>http://www.dslreports.com/forum/remark,12867600</link>
<description><![CDATA[<A HREF="/useremail/u/269961"><b>astirusty</b></A> : I believe it is going to take egress and ingress filtering not only where traffic comes into and out of an ISPs domain (where the ISP connects to the outside world), but also filtering done where the ISP's users connect to the ISP.  Not the user end where the user modem or interface is (these would likely get disabled by hackers).  But user egress and ingress filtering at the point where the ISP's connect the users to their network work (the users merge with the ISP's sub-nets).<br><br>Not being a network expert by any stretch, I am sure there are some real administration issues that would make doing this result in numerous migraines.  But, considering the costs of all the wasted bandwidth, it would appear to be worth a few headaches.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12867600</guid>
<pubDate>Wed, 09 Mar 2005 10:49:39 EDT</pubDate>
</item>

<item>
<title>Re: Difference a year makes, good news, bad news</title>
<link>http://www.dslreports.com/forum/remark,12867347</link>
<description><![CDATA[<A HREF="/useremail/u/360338"><b>jvmorris</b></A> : I think there <I>is</I> a certain amount of ingress filtering, at least, being done by at least some ISPs.  I did a quick check on the unsolicited inbound probes against my current IP address early this morning, <I>fully 60% of them came from <B>within</B> my own Class B subnet</I>, virtually all of which is (supposedly) residential/home DSL customers.  So my ISP must be doing some sort of ingress filtering, at least.  (I think Blake's experiences with Shaw(?) show an even higher percentage of users within his own subnet.<br><br>If it's now mostly within the subnet (as in my case), then <I>more</I> ingress and outgress filtering is unlikely to do much, <SMALL>I think</SMALL>.  Of course, if my ISP simply shut down port 445 probes on its <I>internal</I> routers (within the subnet, that is) that would produce a 50% drop in the number of probes I'm seeing presently here.  I don't think there's any practical reason why Port 445 traffic needs to be running around even <I>within</I> an ISP's subnet and that would undoubtedly have a certain impact on the load of the ISP's internal routers.  (I've no idea how easy/difficult this is to do with that kind of router, which is far different from what we have in SOHO NAT routers, however.)<br><SMALL>--<br>Regards,    Joseph V. Morris</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12867347</guid>
<pubDate>Wed, 09 Mar 2005 10:19:22 EDT</pubDate>
</item>

<item>
<title>Re: Difference a year makes, good news, bad news</title>
<link>http://www.dslreports.com/forum/remark,12866925</link>
<description><![CDATA[<A HREF="/useremail/u/269961"><b>astirusty</b></A> : <div class="bquote"><SMALL>said by  jvmorris <A HREF="/useremail/u/360338"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>This is the part I found particularly interesting: <br><br><div class="bquote">. . . about 60% of all logged events of all traffic logged which includes both inbound and outbound traffic, are inbound scans and attacks </DIV>Taken in conjunction with your earlier statement that you found over a 300% increase in the number of scans (over the past year), that would suggest to me that, within another year or so, the ratio of unsolicited scans to authentic traffic is gonna start approaching the proportion of spam to authentic e-mail! <br> </DIV>Maybe when the beancounters at the ISPs start realizing the costs of all the scans (in wasted bandwidth) they will finally decide to act jointly with other ISPs to put an end to it.<br>1) Start egress and ingress filtering and logging.<br>2) Start disconnecting users that have systems that are scanning (based on logs).<br>3) Charge a reinstatement fee for users that were disconnected for systems that were scanning (and SPAMMING).<br>4) Join together to put some serious pressure on OS vendors that have produced easy to hack systems that come by default with minimal security turned on.<br><br><I>Ohhh, never mind I just woke up and I am back to reality now...   They will simply charge everyone higher connection fees.</I>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12866925</guid>
<pubDate>Wed, 09 Mar 2005 09:22:43 EDT</pubDate>
</item>

<item>
<title>Re: Difference a year makes, good news, bad news</title>
<link>http://www.dslreports.com/forum/remark,12866346</link>
<description><![CDATA[<A HREF="/useremail/u/360338"><b>jvmorris</b></A> : This is the part I found particularly interesting: <br><br><div class="bquote">. . . about 60% of all logged events of all traffic logged which includes both inbound and outbound traffic, are inbound scans and attacks </DIV>Taken in conjunction with your earlier statement that you found over a 300% increase in the number of scans (over the past year), that would suggest to me that, within another year or so, the ratio of unsolicited scans to authentic traffic is gonna start approaching the proportion of spam to authentic e-mail! <br><SMALL>--<br>Regards,    Joseph V. Morris</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12866346</guid>
<pubDate>Wed, 09 Mar 2005 07:38:01 EDT</pubDate>
</item>

<item>
<title>Difference a year makes, good news, bad news</title>
<link>http://www.dslreports.com/forum/remark,12866125</link>
<description><![CDATA[<A HREF="/useremail/u/356416"><b>Link Logger</b></A> : I have posted a quick comparison of attacks and scans for February 2004 and February 2005.  The good news, scan/attack sources are down about 20% (ie 20% fewer infected systems this year compared to last).  The bad new is infected systems scan far harder so number of scans and attacks are up about 370% compared to February last year.<br><br>See &raquo;<A HREF="http://www.linklogger.com/year.htm" >www.linklogger.com/year.htm</A> for the charts and such.<br><br>Blake<br><SMALL>--<br>Vendor: Firewall Logging Software &raquo;<A HREF="http://www.SonicLogger.com" >www.SonicLogger.com</A> - SonicWall and 3Com &raquo;<A HREF="http://www.LinkLogger.com" >www.LinkLogger.com</A> - Linksys, Netgear and Zyxel</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12866125</guid>
<pubDate>Wed, 09 Mar 2005 06:20:38 EDT</pubDate>
</item>

</channel>
</rss>
