GAH!!! ZoneAlarm blocked 1130 access attempts...

MaxDSP

Lifer
May 15, 2001
10,056
0
71
935 of those were high rated. This is within the last 3-4 weeks. Are these all hacking attempts done by script kiddies or something?
Im on a DSL connection.
 

NikPreviousAcct

No Lifer
Aug 15, 2000
52,763
1
0
1) it doesn't matter what kind of connection you're on
2) it doesn't matter if it's a script kiddie or someone who knows what they're doing

if a hacker wants to get through, they'll get through - just take an extra 5 minutes.

Just make sure it's running fairly stable. If you're unsure, get a better firewall.

nik
 

Harvey

Administrator<br>Elite Member
Oct 9, 1999
35,058
70
91
ZA is nowhere near the AOL of software. At least it works.

Personally, I like the previous freeware version 2.6.362 better than the new one so I stayed with it. The reports are easier to access and use. When I was using the new one, I turned off those silly text panels, and I think they got too cutesy with the way they scrolled open and closed.
 

Ime

Diamond Member
May 3, 2001
3,661
0
76
I don't run ZA, but I do have a Hardware-based firewall from 2Wire that does a decent job.

My biggest threat is I started running Kazaa-lite and opened a port for it to run on as a server.
 

NikPreviousAcct

No Lifer
Aug 15, 2000
52,763
1
0
Originally posted by: MaxDSP
Originally posted by: notfred
Originally posted by: MaxDSP
access attempts...

Attempts to access what? OH, wait, you don't know, for all you know it's logging webpages you visit.

you tell me what it could be.

You fscking look it up for your damn self.
rolleye.gif


nik
 

MaxDSP

Lifer
May 15, 2001
10,056
0
71
Originally posted by: ffmcobalt
Originally posted by: MaxDSP
Originally posted by: notfred
Originally posted by: MaxDSP
access attempts...

Attempts to access what? OH, wait, you don't know, for all you know it's logging webpages you visit.

you tell me what it could be.

You fscking look it up for your damn self.
rolleye.gif


nik



I was asking what it could be in my original post jagoff.
 

NikPreviousAcct

No Lifer
Aug 15, 2000
52,763
1
0
Originally posted by: MaxDSP
Originally posted by: ffmcobalt
Originally posted by: MaxDSP
Originally posted by: notfred
Originally posted by: MaxDSP
access attempts...

Attempts to access what? OH, wait, you don't know, for all you know it's logging webpages you visit.

you tell me what it could be.

You fscking look it up for your damn self.
rolleye.gif


nik



I was asking what it could be in my original post jagoff.

Oh, so I should have told you sooner? Mm.

What do your ZoneAlarm logs actually tell you? Or are you just a script kiddie with no idea what you're doing?
rolleye.gif


nik
 

NikPreviousAcct

No Lifer
Aug 15, 2000
52,763
1
0

MaxDSP

Lifer
May 15, 2001
10,056
0
71
Originally posted by: ffmcobalt
Originally posted by: MaxDSP
Originally posted by: ffmcobalt
Originally posted by: MaxDSP
Originally posted by: notfred
Originally posted by: MaxDSP
access attempts...

Attempts to access what? OH, wait, you don't know, for all you know it's logging webpages you visit.

you tell me what it could be.

You fscking look it up for your damn self.
rolleye.gif


nik


maybe you should go whine some more about this in Forum Issues


I was asking what it could be in my original post jagoff.

Oh, so I should have told you sooner? Mm.

What do your ZoneAlarm logs actually tell you? Or are you just a script kiddie with no idea what you're doing?
rolleye.gif


nik

maybe you should go whine some more about this in Forum Issues
 

NikPreviousAcct

No Lifer
Aug 15, 2000
52,763
1
0
Originally posted by: MaxDSP
Originally posted by: ffmcobalt
Originally posted by: MaxDSP
Originally posted by: ffmcobalt
Originally posted by: MaxDSP
Originally posted by: notfred
Originally posted by: MaxDSP
access attempts...

Attempts to access what? OH, wait, you don't know, for all you know it's logging webpages you visit.

you tell me what it could be.

You fscking look it up for your damn self.
rolleye.gif


nik


maybe you should go whine some more about this in Forum Issues


I was asking what it could be in my original post jagoff.

Oh, so I should have told you sooner? Mm.

What do your ZoneAlarm logs actually tell you? Or are you just a script kiddie with no idea what you're doing?
rolleye.gif


nik

maybe you should go whine some more about this in Forum Issues

Maybe you should have posted this in the CORRECT FORUM, smart guy.

nik
 

FoBoT

No Lifer
Apr 30, 2001
63,084
15
81
fobot.com
here is a week's worth on time warner cable in kansas city

320 alerts found using input module SnortFileInput
Earliest alert at 09:58:23 on 9/29/2002
Latest alert at 04:36:37 on 10/3/2002
the number after the type is the # of alerts for that type in the time period above, 5 days
so the total # of alerts is about 300+
Signature # Alerts
WEB-CGI csh access 1
WEB-FRONTPAGE /_vti_bin/ access 1
SCAN SOCKS Proxy attempt 1
WEB-CGI calendar access 1
WEB-MISC whisker HEAD with large datagram 1
WEB-CGI rsh access 1
SCAN Proxy (8080) attempt 2
WEB-IIS ISAPI .idq access 2
WEB-CGI zsh access 2
DOS MSDTC attempt 2
WEB-IIS view source via translate header 2
WEB-IIS .cnf access 2
WEB-IIS CodeRed v2 root.exe access 2
WEB-CGI ksh access 3
WEB-CGI redirect access 9
DNS SPOOF query response with ttl: 1 min. and no authority 13
WEB-IIS cmd.exe access 18
WEB-CGI scriptalias access 29
WEB-IIS encoding access 29
WEB-IIS scripts access 31
WEB-MISC http directory traversal 46
WEB-ATTACKS id command attempt 122
 

FoBoT

No Lifer
Apr 30, 2001
63,084
15
81
fobot.com
Originally posted by: Harvey
Steve Gibson's

Steve Gibson is an idiot

and a publicity whore that only cares about selling crap and making money

he is NOT A SECURITY EXPERT!!!
 

aux

Senior member
Mar 16, 2002
533
0
0
Originally posted by: ffmcobalt
1) it doesn't matter what kind of connection you're on

It matters. Broadband users are targeted more frequently for obvious reasons.

Originally posted by: ffmcobalt
Zone Alarm = AOL of the firewall world
:)
in addition to that many programs with 'firewall' in their name are not exactly firewalls

btw, on another forum someone was complaining that his "firewall" had alerted him about outgoing traffic from his computer to a webserver

Originally posted by: ffmcobalt
If you're unsure, get a better firewall.

better -- get a real firewall (by real I do not necessarily mean hardware firewall) and have it properly set as in most cases the default settings are useless, either too many false allerts or not detecting real problems

Originally posted by: FoBoT
Steve Gibson is an idiot

and a publicity whore that only cares about selling crap and making money

he is NOT A SECURITY EXPERT!!!

:)
go to The Register, search for Steve Gibson and enjoy the readings
 

Jzero

Lifer
Oct 10, 1999
18,834
1
0
The problem with looking at that data is that it doesn't serve much purpose. If ZA blocked it, then it was blocked, so it doesn't matter all that much if you know about it. If ZA didn't block it, then you won't hear about it, so you're already screwed.
 

WinkOsmosis

Banned
Sep 18, 2002
13,990
1
0
You guys bash ZoneAlarm but fail to suggest a "real" firewall. Until someone suggests something better, I'll keep ZA.