Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

Please answer all parts (2-3 lines answer only) for Upvote. 1. a) What is Grey L

ID: 3903427 • Letter: P

Question

Please answer all parts (2-3 lines answer only) for Upvote.

1. a) What is Grey Listing?

b) Why is important to periodically monitor and provide a baseline of the top 5000 domain names being accessed by your organization?  

c) Assume that alter the grep command to search the var/log/messages file for the IP address of 5.79.11.202. For example;

What type of network forensic evidence can we discover about IP address 5.79.11.202 from the preceding grep example?

d)

Linux will store DNS network forensic evidence in /var/log/messages file. Since Linux stores a lot of evidence, the grep commands is used to filter the message log and will search for www.reddit.com

The following is a sample of one DNS forward lookup.

Describe and explain the network forensic evidence for each field of this entry using the following table

# grep 5 . 79. 11. 202 /var/log/messages 1457131141.17235911192.168.75.4511192.168.75.111INI Idcs.cb.philips.com. I JA115.79.11.2021119101 11

Explanation / Answer

1. a) What is Grey Listing?

Answer:

A graylist (also spelled greylist) is a list of e-mail addresses or domain names a spam filtercan use to identify suspected spam. If a message arrives from an address or domain on the list, it will be quarantined and then delivered to the subscriber only if the sender attempts to send the message again within a certain period of time. Once a sender has been recognized as legitimate, its address is removed from the list and future messages from that address can pass through the filter unhindered

The chief advantage of graylisting is the fact that it eliminates most spam while giving desired e-mail traffic a chance to get through. It requires no special configuration efforts on the part of the end user and places no additional burden on the resources of the end user's computer. However, unless a sender transmits its first message to a graylist user twice from the same e-mail address within the prescribed time, the filter will reject the message. Graylisting can also cause annoying delays in the receipt of initial messages.

The term graylist arises from the fact that its mode of operation is between that of a blacklistand a whitelist. A blacklist is a list of e-mail addresses or domain names known to be sources of spam. After filtering, traffic from an address or domain on the list disappears forever. A whitelist works in the opposite way; it is a list of e-mail addresses or domain names from which an e-mail filter allows messages to be received

Hire Me For All Your Tutoring Needs
Integrity-first tutoring: clear explanations, guidance, and feedback.
Drop an Email at
drjack9650@gmail.com
Chat Now And Get Quote