something smells fishy

I originally posted this in the off-topic section
http://forum.avast.com/index.php?board=9;action=display;threadid=5015
thinking it was probably just a glitch. However, it happened more than once and I think something sinister might be afoot.

“it happened again last nast. this time sygate popped up and said i was being attacked. someone was scanning my ports. I am thinking now that I must have some sort of trojan, or that I have made someone interested in my computer. Either way they seem to have access to my computer as Protowall(a program that logs all incoming and outgoing transmissions and blocks certain ip ranges, companies and people) stated that my computer was granting packets at an alarming rate. In fact it had consumed all available bandwith. Sygate provided me with the ip of the attacker I traced the ip back on whois and it said Verizion internet services in virginia.
Weird, I turned off the pc today while I am at work.”

any one have any ideas?

Sounds off, but you might consider investing in a Hardware Firewall. I’m not talking garbage LinkSys router, i’m talking something more serious, like a SMC2804WBR Barricade. They block about 1400 different attacks, and have an aggressive firewall setup.

The good part, you can get them for around $40 in most parts of the country. Software firewalls are unimpressive to say the least, I simply refuse to use one, they are too easy to bypass, and offer little in the form of real protection in my experiance.

yes, but I like the software firewall control. Being able to restrict outgoing transmissions, as well as, incoming. What I want is a hardware firewall with a software gui.

Kezz

that is not expensive! Sygate is free ;D

Uhh dude, my SMC Barricade has a GUI… But of course, it does NOTHING for outbound, but you don’t need a firewall to monitor outbound ports, thats a bit too heavy if you ask me. A simple port monitor/blocker application would solve that trick nicely, such as SSM.

SSM+Hardware Firewall would be lightyears stronger than Sygate or BoneAlarm.

can you give me a link to the ssm?

Its free, and his website is UNGODLY slow… But the program is small, and very effective. (takes a bit to load his page which seems to be hosted on a 14.4 modem)

http://maxcomputing.narod.ru/ssme.html?lang=en

Regards

What is this SSM that you talk about? Got a link?

Douglas

Does your hardware firewall block outgoing traffic, many don’t? If not you need a software firewall as well , there is no extra overhead inbound as your hardware firewall blocks it pre-software firewall.

So when a program that has regular access to the internet is infected, effectively hijacked it can pass out any of your confidential data. My software firewall checks that the program is the same one that was given permission.

So when I update any of my programs, the next time I use it Outpost confirms, the program has changed and do I wan’t to allow it access. I don’t class that as excessive, but that’s just my opinion (and I am on dial-up so there is no hardware router/firewall option) and its your computer.

David

Outbound protection is overrated for one thing, and you certainly do not need a software firewall if you want outbound protection. Theres plenty out there, with a whole lot less payload, that perform outbound/application filtering without the weight and compatibility issues of a Software firewall.

Products like SSM I believe take up a meager 100-200k of ram and have no compatibility issues, whereas most software firewalls i’ve seen, average between 10-50 MB of ram, and large amounts of CPU time. Inbound im well protection (hardware), outbound/applications I can control with a tiny little application.

As I said, it’s your computer, some of us have no choice (those on dial-up so there is no hardware router/firewall option).

Have you ever given Zone Alarm a try. I use it and tested my ports on line and came out that I was in stealth mode on all of them. Zone Alarm is free too!