  Devanchya Smile Premium join:2003-12-09 Ajax, ON
·Bell Sympatico
| reply to Devanchya Re: deep drilling access_logs
I have a bunch of logging already in. the 'easy read' part of it was never built.
So I did figure out what happened:
3-4 of my users were infected by FunWebProducts. They were creating 2-3 connections a second each to the server. Now the site is busy enough that I didn't see it right away. I happened to catch them just as th PC were obviously turned on in the morning.
I have created a rule against this product and will be doing research on how to help prevent this type of fun.
Luckly the FWP was not able to get into the secure part of the website, though I know anything visible on the screen is visible to any viruses. -- »www.codecipher.com - Marking the way to tomorrow's solutions -- Did you know that Perl is not Dead? »perlisalive.org/ |