|
IMPORTANT (Just thought I might post this)
As a further (perhaps unnecessary) demonstration of how useful a firewall is, here's the last 10 entries in my (hardware) firewall's log. Bear in mind this was from just over five minutes, and this kind of traffic is arriving all the time. This is all genuine traffic lifted straight from the log.
Thursday February 01, 2007 02:57:51 Unrecognized attempt blocked from <Taiwan IP address> to <My IP address> TCP:135 {135= Microsoft DCOM server. Commonly left open by Microsoft, and exploited by certain IRC bots}
Thursday February 01, 2007 02:58:56 Unrecognized attempt blocked from <UK IP address> to <MY IP address> TCP:2967 {2967= ssc-agent. Commonly left open by a vulnerability in Norton products. used by many exploits}
Thursday February 01, 2007 02:58:59 Unrecognized attempt blocked from <UK IP address> to <My IP address> TCP:2967 {As before, same person came back for another try}
Thursday February 01, 2007 03:00:42 Unrecognized attempt blocked from <Taiwan IP address> to <My IP address} TCP:135 {As before}
Thursday February 01, 2007 03:00:45 Unrecognized attempt blocked from <Taiwan IP address> to <My IP address} TCP:135 {And again}
Thursday February 01, 2007 03:01:31 Unrecognized attempt blocked from <Different UK IP address> to <Me> TCP:5800 {5800= vnc access. Commonly used for buffer overflow attacks}
Thursday February 01, 2007 03:01:35 Unrecognized attempt blocked from <Same IP as before, but different port> to <Me> TCP:1433 {1443= Intergrated engineering software. Used for a zero day exploit}
Thursday February 01, 2007 03:01:58 Unrecognized attempt blocked from <Netherlands IP address> to <Me> UDP:1026 {1026=Calender access protocol. Another one opened by Mcrosoft and often exploited}
Thursday February 01, 2007 03:04:19 Unrecognized attempt blocked from <Brazil IP address> to <Me> TCP:22 {22= SSH remote login protocol. Often opened by SSH clients, and exploited}
Thursday February 01, 2007 03:04:23 Unrecognized attempt blocked from <Taiwan IP address> to <Me> TCP:135 {yep, Taiwan's back for more too}
These aren't just random misdirected internet traffic. They're all to potentially vulnerable ports, which leads me to believe they're all created by people running hacker tools, for the sole purpose of trying to access my computer. My computer is no more obvious or useful then any computer on the internet (it's probably better stealthed than many), so if they're trying to hack me, they're probably trying to hack everyone else in the area, all at the same time. My firewall blocked all these attempts, but without it, nothing else on my computer would have blocked them. No one is safe from attacks nowadays. Best you can do is stop them getting in.
And as for saying "a crappy firewall wont help", this program is a downloader. It needs to go on the internet to download more nasty stuff to put on your computer. Any firewall with application control will allow you to block this attempt in one click, thus making the trojan pretty useless.
|