RE: Hackers

by Rob Prentice <RJP(at)clickdms.com>

 Date:  Thu, 13 Jul 2000 09:05:51 +0100
 To:  "'Shaun L. Sides'" <arch(at)charter.net>,
HWG techniques <hwg-techniques(at)hwg.org>
  todo: View Thread, Original
The problem i had with Zone Alarm is that on NT it doesnt like the DUN.
and it messed it up. also, its too aggressive. BlackIce, sits in the
background and alerts you to TCP/IP, trojan scans, people looking for
open ports (such as 21 and 80 etc...) but doesnt bother you with them,
also people trying to corrupt your DNS. why they would want to do that
on a workstation i dont know. anyway... Black Ice defender is good. ive
tested it as best as i can. not the most vigerious testing, but it was a
test anyway.

a firewall is only 35% of computer security on the net. another 40% is a
virus scanner and remover. firewalls technicly dont have to scan for
trojan files. so, of you have sub7 sitting there but you havnt run it,
then the firewall wont see it. (probably). so a virus scanner is needed
to find it. then the last 25% is the user. dont run files without
checkign them. make sure your not inviting people in through MSexchange
server (netBIOS tends to get carried away and let people over the net
see your computer (like network printers, drives computer ID's etc...)

-----Original Message-----
From: Shaun L. Sides [mailto:arch(at)charter.net]
Sent: 12 July 2000 21:59
To: HWG techniques
Subject: RE: Hackers


-----BEGIN PGP SIGNED MESSAGE-----

On 12 Jul 2000, at 16:00, Rob Prentice wrote:

> if you get someone and they manage to get you to install a trojan
> or something (back orrifice and sub7 are examples of a trojan),
> then a firewall (it dpends what one) may not do anything about it.
> sub7 can be called anything you want almost. command.com,
> command.exe, oooiii.exe. some firewalls only look for file names.
> not the code behind them. 

This is precisely why I prefer ZA over BID.  ZA intercepts all 
incoming and outgoing traffic and alerts you.  If you have external 
security set to high (the default), then you have to give your 
permission for every prog that wants access outside your machine. 
 That means all the trojans.  I dunno bout you, but if oooiii.exe is 
asking for permission to access the internet, I'm not inclined to 
grant it. ;-)

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.2 -- QDPGP 2.61a
Comment: http://community.wow.net/grt/qdpgp.html

iQCVAwUBOWzcASEw9uEAOtM/AQF6XwP+KKfZHMUEwdME736ppPzE0uuelvxCa4x0
roPs8HLTOePYSIF8boGMuoZRBL0ss+azerjqD9xAlFXtSYCev8lDekDTavuDfDjj
zH/seHIZoCptj0BZCdbXKBdWxWAPgvIPQZWPc6w6FAHxhO7zkOZ3tNBFZ3JmNaSy
n87um4EA6dk=
=pEaE
-----END PGP SIGNATURE-----

HWG hwg-techniques mailing list archives, maintained by Webmasters @ IWA

This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.