|
Posted by Billy Joe on 09/30/05 00:07
Triffid wrote:
> db wrote:
>> "Billy Joe" <see.id.line@invalid.org> wrote in message
>> news:16adneSwEYLo-6HeRVn-oA@adelphia.com...
>>
>>> db wrote:
>>>
>>>> "Billy Joe" <see.id.line@invalid.org> wrote in message
>>>> news:FICdnfvoLv0JxaHeRVn-ig@adelphia.com...
>>>>
>>>>> I did notice today, when testing this, that the banned IPs listed
>>>>> in my firewall showed up immediately and in larger number than
>>>>> over the past several days. I also noticed that this appeared to
>>>>> be the same, whether using the ws2_32.dll or HOSTS files. Can't
>>>>> draw a conclusion from so limited a test tho.
>>>>
>>>> I logged 15 THOUSAND connection attempts from 'them' yesterday.
>>>> Insane...
>>>
>>> They must have you targeted, db. I was nowhere near that high!
>>>
>>> I do notice that, once I have been visited by one or several, the
>>> next time I log on with the same ports open they are the first to
>>> show up here. I've set up a slightly wider range of ports in the router,
>>> and bump
>>> the numbers each time I start MX.
>>>
>>> Hell, it's all a game, isn't it?? ;-0)
>>>
>>> BJ
>>
>>
>> It's an interesting game for sure. Stats for today, only 12,742
>> attempts this time, weeeeee (though prolly because I wasn't running
>> primary for 24 hours today).
>>
>> They're not a problem here though so long as the door doesn't get
>> answered. :)
>>
>>
>>
>
> You got me worried now. Is this PeerGurdian we're talikng about here,
> I've never bothered till now. Should I?
I'm speaking only for myself here, Triffid.
I don't use PG, I enter IP addresses into the Kerio firewall because, to
plagiarize db's eloquence, PG is on the wrong side of the door. A passive
(or stealth mode) firewall will not respond to a blocked address, so they
(the blocked party) may "know" you're there but they can't actually "see"
you. For all that they know, you've logged off the net.
Unless things have changed since I dismissed this useless "product," PG sits
inside the firewall - so the blocked party has already established contact
with your PC - PG just breaks the connection. Kind of like using automated
lights at home, then allowing the newspapers and Evian deliveries to pile up
on the porch while you're away!
And, in all honesty, I only enter IP addresses into the firewall for test
purposes. There is no way that I can know which source address is a bad
one. Fending off buckshot with an umbrella, I'd say! If security were
push-button simple, wouldn't the world be a nicer place? ;-0)
BJ
[Back to original message]
|