Computing.Net > Forums > Security and Virus > am i wasting my time

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

am i wasting my time

Reply to Message Icon

Original Message
Name: echobunny
Date: October 25, 2003 at 13:02:57 Pacific
Subject: am i wasting my time
OS: XP pro
CPU/Ram: PIII 700 / 386mb sdram
Comment:

i kepe getting these backdoor/subseven trojan intruson attemp warnings in my nortot firewall

i block each IP as they come in. am i wasting my time doing this? will they always try to get to me on anther IP? or will there come a point where i will have blocked all their IP addresses


Report Offensive Message For Removal


Response Number 1
Name: capt
Date: October 25, 2003 at 13:08:46 Pacific
Reply: (edit)

Why not just set NIS so it can do its job, and not notify you. Very seldom can you can anything about the intrusion notification.


Report Offensive Follow Up For Removal

Response Number 2
Name: anonproxy
Date: October 25, 2003 at 21:05:09 Pacific
Reply: (edit)

"or will there come a point where i will have blocked all their IP addresses[?]"

Don't worry about that.

Don't block by IP unless you have too. Instead make a rule. It should say something like this:

Block all incoming traffic on ports 1-65,535 via UDP and ICMP. And another for blocking all incoming traffic on all TCP ports except(!) ports 80 (HTTP), 443 (HTTPS), 25 (SMTP), and whatever else you tend to use.



Report Offensive Follow Up For Removal

Response Number 3
Name: JackG
Date: October 26, 2003 at 01:26:38 Pacific
Reply: (edit)

Or do it the quite way, with a router with built-in inbound firewall. That way they never get to your system and slow it down looking at all the port requests.


Report Offensive Follow Up For Removal

Response Number 4
Name: EC
Date: October 26, 2003 at 16:41:00 Pacific
Reply: (edit)

Just remember, that no port can be opened from the outside of the Operating System, but only from the inside, and by a program that is authorized to use it, that is if you're security firewall is set correctly.
And , NO ports should open at all.
Run a port scan at www.grc.com
To receive http traffic, port 80 does not need to be open, as the the open part applies to outgoing, not incoming.


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software