PPRuNe Forums - View Single Post - Attempted Firewall Breaches - What Action?
Old 19th October 2003 | 16:15
  #3 (permalink)  
Evo
20 Anniversary
 
Joined: Sep 2002
Posts: 1,650
Likes: 0
From: Chichester, UK
Then there are the hackers, actively trying to hack into your computer. If the hacker is any good, then he would have hacked another computer and from there launched his attack against yourself. So going back to the place the attack was launched from will only lead you to a poor unsuspecting person, that did not even know his computer had been hacked.
An active hack attempt on a private user is extremely rare. Getting access to remote computers is useful for a number of reasons (for example as a proxy to hide behind, spam mailer, host to put something on or to enroll in a denial of service attack) but there are so many vulnerable computers (i.e. broadband but no firewall, unpatched Windows) online that can be trivially accessed that nobody would bother with you if you have the basic defences in place - unless they are after you and you alone, and for a private user this is very unlikely (unless you've made an enemy down the pub ).

As Richard says, the firewall is just picking up sweeps over a wide range of IP addresses, one of which corresponds to your computer. These will either be active port scans (initiated by a l337 h@x0r script-kiddie with a copy of nmap), or most commonly a virus/worm scanning unknown to the owner of the computer. At first they're interesting, but there are so many that it's better to turn off the pop-up box and just ignore them. A precursor to a real attack is rather different, and any halfway-competent hacker can stealth it so that your firewall will probably miss it anyway.
Evo is offline