| >>On Sun, 11 Sep 2005 08:24:26 GMT, Robert Baer | >> wrote: | >>
| >>> I know very little about how attacks are actually done. | >>> However, i have prevented a number of processes, and have a long list | >>>in my HOSTS file. | >>> As a result, the GRC ShieldsUP tests show only two open ports for a | >>>Win2k computer: 135 (RPC) and 1025 (COM/DCOM); and show others for the | >>>present Win98SE computer: stealthed 106, 108, 109, 111; open 139 (NetBios). | >>> Now it seems that GRC has a DCOMbobbulator program that might fix the | >>>port 1025 problem. | >>> But what about the others? | >>> If i close the open ports, then would i be very safe? | >>
| >>Yes. If you don't have multiple PCs on a LAN you can close all ports | >>and dispense with a firewall and router. Here's my article with | >>instructions for Win 2K: | >>
| >>
formatting link
| | >And this is unsafe. You never know when a program will open a port. It | >could do so at any time. | | You never know when a program will disable a sw firewall either. And | antivirus sw. There are many nasties out there that do for a number | of different firewalls and av products. In fact, that's far more | likely than creating a service and opening a port. If you know of any | nasties that actually do this, let me know. | | Art | |
formatting link
Surenuff, the IRC Trojan that floated around sometime back which used some Mirc DLLs would run a remote control program, open up some ports and send IRC messages to announce it's successful invasion, then remote control software was used to control the system (rconnect.exe seems to ring a bell as the remote control program that was used).
formatting link
This all happened when I was playing around a bit one night and turned off my firewall (Kerio) for some testing, and forgot to turn the firewall back on, and maybe it was just 1 or 2 nights and the machine was attacked. I am not certain how the Trojan was introduced to the system, tho it might be due to a weak account/password. I do not use the system for any other tasks other than as a router to share a broadband connection. I do not use Mirc for IRC. There you go, one example of how a software firewall that blocks outgoing connections could have prevented an infection. Granted, the lame user account name and weak password were also perhaps part of the problem, but had I not disabled the firewall, the attack would never have succeeded because the port would never have been opened, and the outgoing IRC contact could not have taken place to the perpetrators.