lovingboth: (Default)
Ian ([personal profile] lovingboth) wrote2005-12-12 11:21 pm

Hello Ian, got a new router?

For some reason, Zone Alarm started shutting themselves down a couple of times a week here recently. Two AV programs (and the rootkit revealer) failed to find any nasties, but it was somewhat worrying.

The trial replacement, Agentium's Outpost, didn't report any unusual outgoing traffic either but soon had me screaming at it: it'd usually let Opera see the web on every account except my 'user' one - my 'admin' account and everyone else's 'user' one, yes, my user one no. Sometimes, just to annoy me, it'd change its mind about that and allow it... for about 30 minutes. It got uninstalled quickly.

So... try Zone Alarm Pro, and password protect the 'close down' commands. Nope, it'd still close itself down.

Combined with the problems inherent in trying to connect L12's PC to the net via mine using a cable just too big to fit through the hole in the wall, and it was time to bite the bullet and get a router. A wireless one, for L12's PC and any laptop I may end up with.

And it looks like the wired bits (my PC to it, it to the modem box) work. Once I made the modem accept that something had changed on this side of it by power cycling it, anyway.

Its logs do confirm again just how often anyone on the net gets port scanned. Do other people just accept this, or do you see which port(s) are being attacked, make a guess as to which exploit the other end fell prey to and send a suitable something back?

Tomorrow... wireless. Fingers crossed.

Any tips? Stop unknown MACs connecting, use the better WPA encryption, get the router to hide the network's name... anything else?
vampwillow: (Default)

[personal profile] vampwillow 2005-12-12 11:28 pm (UTC)(link)
there is a screen attached to my router box ... occasionally I turn it on to watch what DNS calls my machines are making, but it also shows all the (stopped) scans from outside. They don't happen as often as I'd sometimes expect, but that might be because they don't get anywhere so don't repeat the attempt ...

[identity profile] syllopsium.livejournal.com 2005-12-13 12:11 am (UTC)(link)
these days? unless the portscans are concentrated and repeated I just ignore them. life is too short.

[identity profile] drdoug.livejournal.com 2005-12-13 03:54 pm (UTC)(link)
What he said.

I even remember when it was feasible to track back every piece of spam I received and complain about it!
ext_5939: (nerd)

portscans

[identity profile] bondagewoodelf.livejournal.com 2005-12-13 04:04 pm (UTC)(link)
I got all my Windows boxes at home behind the Linux masquerading firewall. I log some blocked port access there for occasional amusement value (if I am bored and want to see Where In The World Are The Hackers these days).