PDA

View Full Version : Security, Firewalls, Sam Spade


bob clark
09-17-2005, 06:14 PM
Hi Steve,

When I first subscribed to Comcast they offered a free 6 month subscription to McAfee's firewall program. I used it until it expired. Years ago I had ZoneAlarm installed but that became troublesome after awhile. Never uninstall ZoneAlarm without reading the directions first! So just used XP's rather threadbare and according to some not very effective firewall.

A few weeks ago Comcast started offering the McAfee firewall (and their AV program too) for free again. And this time it's the full version with the traceroute map in it. Not only do you get the traceroute info and source IP from computers perhaps trying to secretly connect but other info (network) such as ping times etc. and an easy to look at and follow map. It's amazing how much stuff originates from China and even the Czech Republic. And of course Russia!

Deciding on who is really trying to get into your computer and is perhaps a real threat and what's just an innocent knock on the door is still hard to figure out. I've had over 100 attempts just today... and the day isn't even half over.

Just thought I'd give you a heads up in case you hadn't noticed that Comcast was again offering McAfee for free. And this time the full version.

Have a good one.

Steven Edwards
09-17-2005, 07:48 PM
Thanks Bob. I saw the notice in my email account but didn't know the Firewall offered that cool of a traceroute. I just installed it and am anxiously awaiting my first hack attempt. :)

LaoziSailor
09-18-2005, 07:35 PM
I would highly recommend visiting Steve Atkins' site SamSpade.org (http://www.samspade.org/).

He explains Personal Firewalls

http://www.samspade.org/d/persfire.html
If your personal firewall pops up an alert, there is never any reason to worry about it. Never, ever, notify an abuse desk about it. It merely wastes their time, and yours.
...and he goes on...

http://www.samspade.org/d/firewalls.html
A 'personal firewall' isn't a firewall. A firewall is a dedicated box with (usually) two or three ethernet ports running no services other than a firewall. My preferred configuration is an x86 box with a couple of tulip cards running FreeBSD or OpenBSD and ipf, though you can do OK with Linux and iptables too. You can run either on a $100 obsolete PC. (*BSD is better, but Linux is easier for a new user to configure).
If you really want to do this for entertainment value, he offers a slick tool to do it with = Sam Spade for Windows (http://www.samspade.org/ssw/) and it is FREE!

Now if you really want to see how exposed you are, you might consider visiting Steve Gibson's and Gibson Research Corporation's Web homepage (http://www.grc.com/). It will provide you with a lot of information and FREEBIES as well.

I occasionally use (I just did to make sure I'm providing acurate info) his:
ShieldsUP! (https://www.grc.com/x/ne.dll?bh0bkyd2)
The Internet's quickest, most popular, reliable and trusted, free Internet security checkup and information service. And now in its Port Authority Edition, it's also the most powerful and complete. Check your system here, and begin learning about using the Internet safely.

I also downloaded:
LeakTest (http://www.grc.com/lt/leaktest.htm)
Ensure that your PC's personal firewall can not be easily fooled by malicious "Trojan" programs or viruses. Thanks to this first version of LeakTest, most personal firewalls are now safe from such simple exploitation.

...anyway in my opinion it is well worth it, and you judge for yourselves whether Steve Gibson (http://www.grc.com/stevegibson.htm) is or not.

Cheers!

Steven Edwards
09-18-2005, 08:17 PM
Laozi, the McAfee firewall intrigued me because of the graphical traceroute feature (available in other software, too) and I wanted to see if it showed me anything new and different.

'm behind a router anyway, so I'm not too worried about getting infected. :) SamSpade shows me as perfectly clean (stealthed) on all ports.

PN
09-18-2005, 09:26 PM
SamSpade shows me as perfectly clean (stealthed) on all ports.
Sam Spade or Steve Gibson?

Steven Edwards
09-18-2005, 09:28 PM
Sam Spade or Steve Gibson? Steve Gibson. Sorry. :)

PN
09-18-2005, 09:31 PM
That was a fast reply. :)

By the way, Steve Gibson can be heard almost every Sunday on TWiT (http://thisweekintech.com/) (This Week in Tech) along with Leo Laporte, Patrick Norton, Kevin Rose, Roger Chang, and John C. Dvorak.