PDA

View Full Version : You too can pass yourself off as an instant firewall expert!


MAX REVERSE
8th Apr 2000, 02:28
Well, something like that.

Seeing as firewalls are the latest hot topic on the forum, those of you who don't already know might like to subscribe to the newsgroup comp.security.firewalls

It covers lots of the stuff you're asking (such as "Should I be worried by all of these access attempts I'm getting?") and you can always post a question yourself if you don't see what you're after.

It's also a good place to get an idea of what's hot (ZoneAlarm) and what's not (Lockdown).

Personally I think that everyone is getting a little hot under the collar about access attempts. I suggest you download a decent firewall, switch off access attempt notification and just get on with enjoying surfing. Besides, it isn't blocked access attempts which are reported that should worry you, it's successful accesses that are NOT!

What you might be interested in is that the latest beta of ZoneAlarm has an access attempt logging feature that is lacking in the current version. It lets you keep tabs on what is going on without the alert window popping up every few minutes!

The Zombie
13th Apr 2000, 01:38
I could not have put it better.
Well said.

Blacksheep
13th Apr 2000, 09:17
Oh, I don't know about getting hot under the collar :)

My PC was hacked and 600 megabytes of one of my partition drives was turned into a hidden and password protected file belonging to someone else. After I discovered its existance and deleted it by reformatting the partition, the hacker turned nasty and tried messing with my system files. My daughter's boyfriend helped me out a lot and I've ended up with ZoneAlarm. This seems to be effective protection against invasion.

We all think that there is nothing of interest to others in our PCs, but what hackers are interested in is making use of other people's computers for their own benefit. According to my teenage "hacker" advisor, the main means of entry is through ICQ and the main objectives are copying expensive software, concealing activity by using another person's computer for file access, and the creation of storage space for files that they don't want to keep in their own machine.. I leave it to your imagination as to what such files may consist of!! http://www.pprune.org/ubb/NonCGI/redface.gif While I was cleaning out trojans I found one that belonged to Network Solutions and another pointing to a US government computer in Texas http://www.pprune.org/ubb/NonCGI/eek.gif

So, its not just paranoia, the b*st*rds really are out to get us...

**********************************
Through difficulties to the cinema


[This message has been edited by Blacksheep (edited 13 April 2000).]

MAX REVERSE
13th Apr 2000, 13:49
Actually Blacksheep, I was going to mention your experience in my posting to encourage people to download the firewall, but then dropped it because I was rambling on too much.

My point was really to those who are asking questions like "One of my ports has been probed!!!!!! Should I report it to my ISP?" (The answer, by the way, is NO: isolated probes are to be expected - 'internet background radiation' as Steve Gibson puts it.) To balance this with your experience, I suggest the following:

Try the latest beta of ZA - it has a nice logging feature so that you can periodically review access attempts, rather than having them pop up at every probe. Should you want to report anyone to an ISP, you'll really need to send a copy of your log to them to make them take any notice.

Don't get paranoid - have some faith in the firewall. As long as you've configured it sensibly (ie. you don't grant automatic internet access and server capability to every program that asks for it) then you shouldn't need to be checking the log every five minutes (I usually review it at the end of my session).

Read the newsgroup! OK, a lot of it is strong meat, but there are also plenty of concerned people asking the same sorts of questions as get posted in this forum, and there are a lot of friendly people who give good advice. Also take a look at the ZA faq (see the ZoneAlarm thread for the url) which will give you a lot of information.

I know I go on about ZA a lot - I'm not on retainer, honest! It's just a good, FREE program which should help give you a little peace of mind in cyberspace.