Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Trojans

Thread Tools
 
Search this Thread
 
Old 06 September 2002, 08:44 AM
  #1  
Dr Nick
Scooby Regular
Thread Starter
 
Dr Nick's Avatar
 
Join Date: May 2001
Posts: 507
Likes: 0
Received 0 Likes on 0 Posts
Question

Hi Everybody!

I have Norton Internet Security (firewall and virus software)

I got it when I got ADSL. This seemed like a good idea. Previously I had no antivirus stuff at all but common sense and possibly some luck had allowed me to never have a virus problem.

The firewall runs in the background all the time.

About twice a day I get a message saying someone tried to attack me with the sub7 trojan.

Is it possible that the software could be genrating false alarms or are these all genuine attacks?

If I did not have the firewall software would they always be successful attacks?

This is an area I know very little about.

However, I have read that there is little point tracing the IP address back to the provider and complaining becuse the IP address is probably faked and the provider will just ignore you. I'd appreciate your comments on this.

There is nothing important on my computer but I take this kind of thing quite personally. I feel that often the best form of defence is attack. I would like to find out who the culprits are and encourage them to stop.
Old 06 September 2002, 09:00 AM
  #2  
MarkO
Scooby Regular
 
MarkO's Avatar
 
Join Date: Oct 1998
Location: London
Posts: 4,891
Likes: 0
Received 0 Likes on 0 Posts
Thumbs down

Don't take it personally. It's just script kiddies probing random IP addresses for vulnerabilities. It's not meant directly for you, any more than spam is.

Just make sure you've got a half-decent firewall running (Zonealarm does the job nicely) and ignore them.
Old 06 September 2002, 09:05 AM
  #3  
V5
Scooby Regular
 
V5's Avatar
 
Join Date: Jul 2002
Posts: 1,933
Likes: 0
Received 0 Likes on 0 Posts
Post

I have sometimes wondered if this is something I need worry about. I use a work laptop at home with a normal modem connection to freeserve. Should I run some sort of firewall?
Old 06 September 2002, 09:31 AM
  #4  
MarkO
Scooby Regular
 
MarkO's Avatar
 
Join Date: Oct 1998
Location: London
Posts: 4,891
Likes: 0
Received 0 Likes on 0 Posts
Cool

It's less important if you're on a dial-up connection like freeserve, since you'll be automatically disconnected every couple of hours and when you redial you'll get a new, different IP address.

Mind you, I still have the firewall turned on in XP, just in case.

If you're on a fixed/constant connection (e.g., ASDL) then a firewall is essential.
Old 06 September 2002, 09:36 AM
  #5  
Dr Nick
Scooby Regular
Thread Starter
 
Dr Nick's Avatar
 
Join Date: May 2001
Posts: 507
Likes: 0
Received 0 Likes on 0 Posts
Post

Why do ADSL connections get a fixed IP address?

My ADSL behaves just like a dial up. If I leave it alone after 30 mins idle (as set by me) it disconnects.

When I reconnect, will it be the same IP or a different one?

Cheers
Old 06 September 2002, 09:52 AM
  #6  
MarkO
Scooby Regular
 
MarkO's Avatar
 
Join Date: Oct 1998
Location: London
Posts: 4,891
Likes: 0
Received 0 Likes on 0 Posts
Thumbs down

ASDL should be 'always-on'. Otherwise how would you be able to run, say, a webserver from it?

The IP will be constant per-session, and may even be constant inter-session, depending on the contract you paid for. A permanent fixed IP will usually cost more though.

Who is your ADSL with? Considering one of the raisons d'etre for having ADSL is to have an always-on connection which doesn't drop, it sounds like you're getting a raw deal?
Old 06 September 2002, 01:19 PM
  #7  
scooby nutter
Scooby Regular
 
scooby nutter's Avatar
 
Join Date: Dec 2000
Posts: 1,028
Likes: 0
Received 0 Likes on 0 Posts
Post

When i get these buggers trying to probe my computer,as soon as it happens i use a little piece of software which sends something back to them."Ping"their ip addy with data and it slows their connection down


Trending Topics

Old 06 September 2002, 06:33 PM
  #8  
boomer
Scooby Senior
 
boomer's Avatar
 
Join Date: Feb 2000
Location: West Midlands
Posts: 5,763
Likes: 0
Received 0 Likes on 0 Posts
Post

scooby nutter,

trubble is that if you ping 'em back, they know that your IP address is valid and may snoop some more.

You are better off being stealthy and ignoring it - that way they will get bored and go back to playing with themselves! Hopefully they will go blind before they actually cause any harm

mb
Old 06 September 2002, 07:53 PM
  #9  
scooby nutter
Scooby Regular
 
scooby nutter's Avatar
 
Join Date: Dec 2000
Posts: 1,028
Likes: 0
Received 0 Likes on 0 Posts
Post

LOL@boomer

hope the buggers go blind
Old 06 September 2002, 09:14 PM
  #10  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

The object of the exercise when it comes to port scans is to pretend to be a black hole....don't give them any information, just drop the packet.....All of the Firewall's that I've seen that are configured to reject rather than drop are the ones that are continually probed/attacked.

As Bruce Schneier says in Secrets & Lies,

When being chased by a Grizzly Bear the object of the exercise is not to out run the Bear.......you just need to out run the person your with !

If you don't give anything away they'll move on it a more tempting target.



Jeff
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
The Incredible Hulk
Computer & Technology Related
4
16 May 2005 08:56 AM
ex-webby
Computer & Technology Related
0
05 April 2005 10:08 PM
Shropshire-Guy
Computer & Technology Related
16
30 December 2004 01:25 PM
jono300
Computer & Technology Related
5
31 May 2004 09:01 PM
Avi
Computer & Technology Related
6
01 May 2002 03:19 PM



Quick Reply: Trojans



All times are GMT +1. The time now is 03:47 PM.