Read Please, and then act:
http://www.networkworld.com/news/2005/1 ... 05-botnets
Caught one on my proxy this morning.
If you do not wish to install the F-secure's Beta Blacklight,
Get this:
It is free, works wonders, and is not CPU intensive.
I would never do a Intranet VPN client provision without it.
Great for home network use as well.
http://www.zonelabs.com/store/content/c ... edownloads
Rootkits
Moderator: Scott Danziger
- -Metablade-
- Posts: 1195
- Joined: Fri Nov 04, 2005 4:54 pm
Rootkits
There's a bit of Metablade in all of us.
- gmattson
- Site Admin
- Posts: 6073
- Joined: Wed Sep 16, 1998 6:01 am
- Location: Lake Mary, Florida
- Contact:
Thanks...
I've been using Zonealarm (the free version) and Advast with excellent results for about three years.
The problem with any firewall program is that something can sneak through by posing as something you currently use.. How did you catch that worm? What warning did Zonealarm give you?
The problem with any firewall program is that something can sneak through by posing as something you currently use.. How did you catch that worm? What warning did Zonealarm give you?
GEM
"Do or do not. there is no try!"
"Do or do not. there is no try!"
- -Metablade-
- Posts: 1195
- Joined: Fri Nov 04, 2005 4:54 pm
You are spot on.
Often getting "in" is easy depending on if the sysadmin is paying attention
,but some tools to help you are employing Dynamic NAT (Network Address Translation)
http://computer.howstuffworks.com/nat.htm
and a proxy in front.
My issue was that I sometimes use a proxy for a security testing environment, and sometimes new betaware can contain malware.
In this case, Zone alarm did not prevent my download,(which it's not really designed to do) but when then malware attempted to phone home, Zone Alarm caught it.
However, there are many malware rootkits which are very good at hiding.
Most important is to block any IRC ports.
In fact, it's a good idea to disable ALL ports except the ones specifically being used.
Often getting "in" is easy depending on if the sysadmin is paying attention

http://computer.howstuffworks.com/nat.htm
and a proxy in front.
My issue was that I sometimes use a proxy for a security testing environment, and sometimes new betaware can contain malware.
In this case, Zone alarm did not prevent my download,(which it's not really designed to do) but when then malware attempted to phone home, Zone Alarm caught it.
However, there are many malware rootkits which are very good at hiding.
Most important is to block any IRC ports.
In fact, it's a good idea to disable ALL ports except the ones specifically being used.
There's a bit of Metablade in all of us.