RE: Hackers

by Rob Prentice <RJP(at)clickdms.com>

 Date:  Thu, 13 Jul 2000 09:33:51 +0100
 To:  "'martyh(at)cinci.rr.com'" <martyh(at)cinci.rr.com>,
"Shaun L. Sides" <arch(at)charter.net>,
HWG techniques <hwg-techniques(at)hwg.org>
  todo: View Thread, Original
a good protection against BO and S7 etc... is to get the programe ( not
hard to do... there are tutorial sites for trojans (sorry... not
torjans... network administration tools ) and install the server side
and learn what it can do. setup a contained two computer network and
install the server on one, and the client on the other and play with it.
then youll know for sure what they can do and how to detect them for
your self with first hand experience.

-----Original Message-----
From: Martin T. Hugo [mailto:martyh(at)cinci.rr.com]
Sent: 13 July 2000 03:39
To: Shaun L. Sides; HWG techniques
Subject: RE: Hackers


Hi all,

I know this has dragge don a bit but, I agree with Shaun.  I use ZA and
I
haven't had any problems with it, or it's functionality.  It gives me a
sense of security (if anyone can give me an example of a ZA
failure-assuming
correct configuration of course- I would be very interested in it).

Incidentally, there is a neato proggy called bocheck.exe which will
check
behind your firewall for Back Orifice type trojans.

Marty

-----Original Message-----
From: owner-hwg-techniques(at)hwg.org
[mailto:owner-hwg-techniques(at)hwg.org]On Behalf Of Shaun L. Sides
Sent: Wednesday, July 12, 2000 4:59 PM
To: HWG techniques
Subject: RE: Hackers


-----BEGIN PGP SIGNED MESSAGE-----

On 12 Jul 2000, at 16:00, Rob Prentice wrote:

> if you get someone and they manage to get you to install a trojan
> or something (back orrifice and sub7 are examples of a trojan),
> then a firewall (it dpends what one) may not do anything about it.
> sub7 can be called anything you want almost. command.com,
> command.exe, oooiii.exe. some firewalls only look for file names.
> not the code behind them.

This is precisely why I prefer ZA over BID.  ZA intercepts all
incoming and outgoing traffic and alerts you.  If you have external
security set to high (the default), then you have to give your
permission for every prog that wants access outside your machine.
 That means all the trojans.  I dunno bout you, but if oooiii.exe is
asking for permission to access the internet, I'm not inclined to
grant it. ;-)

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.2 -- QDPGP 2.61a
Comment: http://community.wow.net/grt/qdpgp.html

iQCVAwUBOWzcASEw9uEAOtM/AQF6XwP+KKfZHMUEwdME736ppPzE0uuelvxCa4x0
roPs8HLTOePYSIF8boGMuoZRBL0ss+azerjqD9xAlFXtSYCev8lDekDTavuDfDjj
zH/seHIZoCptj0BZCdbXKBdWxWAPgvIPQZWPc6w6FAHxhO7zkOZ3tNBFZ3JmNaSy
n87um4EA6dk=
=pEaE
-----END PGP SIGNATURE-----

HWG hwg-techniques mailing list archives, maintained by Webmasters @ IWA

This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.