CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Hacked and need urgent advise
Goto page 1, 2, 3, 4, 5  Next
 
Post new topic   Reply to topic       All -> FavForums -> Firewalls [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Gamer

Sergeant
Sergeant
Premium Member

Joined: Jan 29, 2003
Posts: 125

Premium

PostPosted: Thu Jun 29, 2006 12:53 pm    Post subject: Hacked and need urgent advise
Reply with quote

A couple of days ago my computer's were hacked. I hosted a game server from home and i noticed that someone tried to add a global start entry to my server box (win 2k3), S&D TeaTimer stopped it and displayed a box with the info, which is how i knew something was wrong (i shut it down when i saw this). This tipped me off and put me into damage control overdrive, as i was patching and updating all my antivirus, trojan, adware tools and doing scans my other computer suddenly rebooted and when it restarted i got an error message about "hal.dll" missing. I booted up with my BartPE and i found out the problem; the hacker had deleted half my windows files. I did a system restore, rebooted, copied over the files i did not want to lose to an extra HD i had lying around and did a low level format, repartitioned the drive and reinstalled windows and all applications.

Ok enough for the background, now i need help securing against this ever happening again.

I've since stopped hosting a server and i changed my IP so the attackers can't get me again. I'm using 2 firewalls and 1 IP blocker as well as a NAT router on my computer and i still feel this is not enough. I'm going to turn my old server computer into a linux router with apf firewall and a honeypot for good measure. I'm using Windows Firewall, Look 'n' stop firewall, Peer Guardian 2, NOD32 (and S&D, spywareblaster, ad-aware, file checker, modified hosts file) and my router is an old LinkSys BEFSX41.

I also downloaded a log parser named Link Logger (is this ok to use? do they have good reviews? i didnt find any info online about it). I've been monitoring my incoming and outgoing connections like a hawk and a lot of stuff scares me, i see a lot of worms, exploits and port scans; is this normal?

I was thinking about possibly buying a newer router (my budget is around $400, but i'd like to pay around $250 max).

Is my current router and setup sufficiant? or can anything be stronger and should i change the router.

P.S. I dont want a wireless router because that introduces a whole host of problems i do not want to deal with, plus my computers are within 4 feet of the router.

P.S.S Which method should i connect everything? Cable Modem => Linux Router => LinkSys Router => PC or Cable Modem => LinkSys Router => Linux Router => PC

Any help would be greatly appreciated as this experience has left me brused and neurotic. Opening ports is hell, but i want to be protected, now i know nothing is 100% when your dealing with hackers.

Back to top
View users profile Send private message
Cudni

Special Response Team


Joined: Dec 10, 2002
Posts: 3718
Location: Et In Arcadia ego
MIRT MVP SRT

PostPosted: Thu Jun 29, 2006 1:20 pm    Post subject:
Reply with quote

That seems secure setup. Keep your OS and security software up to date as well.

LinkLogger is a good app that will give you a good overview, you can also try PortPeeker from same author to sniff the traffic content.

Don't worry to much, just keep an eye, about the blocked traffic logged on your router (especially in Nat mode) as it is usual on the net

What are you trying to achieve with the honeypot?

Cudni


_________________
Hecho en Mexico
Back to top
View users profile Send private message Visit posters website
Gamer

Sergeant
Sergeant
Premium Member

Joined: Jan 29, 2003
Posts: 125

Premium

PostPosted: Thu Jun 29, 2006 4:47 pm    Post subject:
Reply with quote

Brute force break ins so i can ban the IP with APF.

Back to top
View users profile Send private message
Gamer

Sergeant
Sergeant
Premium Member

Joined: Jan 29, 2003
Posts: 125

Premium

PostPosted: Fri Jun 30, 2006 2:39 am    Post subject:
Reply with quote

*I mean i have the honeypot so i can monitor brute force break ins and than ban the ip with apf.

Back to top
View users profile Send private message
blkwlnt64

Lieutenant
Lieutenant


Joined: Jan 26, 2005
Posts: 217


PostPosted: Fri Jun 30, 2006 1:45 pm    Post subject:
Reply with quote

Gamer, You should be using only 1 software firewall - disable the Windows firewall. Running more than 1 has a high probability of conflict.

Back to top
View users profile Send private message
Gamer

Sergeant
Sergeant
Premium Member

Joined: Jan 29, 2003
Posts: 125

Premium

PostPosted: Fri Jun 30, 2006 6:11 pm    Post subject:
Reply with quote

I'd rather have high conflict than lose everything again.

Back to top
View users profile Send private message
Bad_Frogger

Captain
Captain


Joined: May 12, 2006
Posts: 507
Location: Canada

PostPosted: Fri Jun 30, 2006 8:18 pm    Post subject:
Reply with quote

Hi,

Gamer wrote:
I'd rather have high conflict than lose everything again.

blkwlnt64 wrote:
Gamer, You should be using only 1 software firewall - disable the Windows firewall. Running more than 1 has a high probability of conflict.


Bad out.


_________________
MS's "New Coke"
Back to top
View users profile Send private message
blkwlnt64

Lieutenant
Lieutenant


Joined: Jan 26, 2005
Posts: 217


PostPosted: Sat Jul 01, 2006 11:33 pm    Post subject:
Reply with quote

Sooner or later GOD always punishes those who thumb their nose to reason.

Back to top
View users profile Send private message
Gamer

Sergeant
Sergeant
Premium Member

Joined: Jan 29, 2003
Posts: 125

Premium

PostPosted: Sun Jul 02, 2006 9:28 pm    Post subject:
Reply with quote

Bad_Frogger wrote:
Hi,

Gamer wrote:
I'd rather have high conflict than lose everything again.

blkwlnt64 wrote:
Gamer, You should be using only 1 software firewall - disable the Windows firewall. Running more than 1 has a high probability of conflict.


Bad out.



??? What do you mean by "Bad out"?

Back to top
View users profile Send private message
Tib

Lieutenant
Lieutenant


Joined: Jun 25, 2006
Posts: 159
Location: UK

PostPosted: Sun Jul 02, 2006 9:36 pm    Post subject:
Reply with quote

What he means is by runnign more than one firewall at once you risk making your system unstable and potentialy crashing it. Trust me windows firewall offers no extra security from a good firewall and will jsut cause you problems.

Tib

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Sun Jul 02, 2006 9:44 pm    Post subject:
Reply with quote

[quote="Gamer"]

Bad_Frogger wrote:

??? What do you mean by "Bad out"?

Nothing, it is just his signature. It is added to all his posts. Bad_Frogger, his user name, get it!

BTW, using more than one software firewall - I agree, not a good idea. Not only can you get conflicts, but it can cause the firewall software to fail to operate as a firewall and leave you more exposed than you would be with a single one.

If you don't think your hardware router/firewall is doing the job, then you should consider an entry level commercial grade one, like the SonicWALL TZ-150 for example.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
Gamer

Sergeant
Sergeant
Premium Member

Joined: Jan 29, 2003
Posts: 125

Premium

PostPosted: Tue Jul 04, 2006 12:44 pm    Post subject:
Reply with quote

How much more effective at blocking attacks is the SonicWALL TZ-150 ?

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Tue Jul 04, 2006 2:23 pm    Post subject:
Reply with quote

Gamer wrote:
How much more effective at blocking attacks is the SonicWALL TZ-150 ?
Than what? Since you haven't said what your current hardware is, I can't tell. But, it is a SOHO commercial unit, and it will stop things that a home unit will not.

You can also get a subscription from SonicWALL to add anti-virus, anti-malware, content, anti-intrusion and email packet scanning directly within the TZ-150 (i.e., it runs on the TZ-150 router/firewall, not the systems behind it) in addition to its' base protection.

Personally, I have been using SonicWALL products for years, and also recommending them to my clients, friends and family for protection. I started with a SOHO1, traded up to a SOHO2 and now have a TZ-170, the TZ-150's big brother. During that period I have never had a single infection of any kind, despite it stopping routine zombie port scans at a rate of 1 per minute and serious attacks at a rate of 1 per hour for quite some time. Properly set up, with good browsing habits, and the normal range of protective software on your Windows system as well, nothing will get through unless you do something wrong.

SonicWALL is rated up there with Cisco in terms of quality of their hardware router/firewalls, but runs somewhat less because their target markets are smaller businesses rather than the gigant ones.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
Gamer

Sergeant
Sergeant
Premium Member

Joined: Jan 29, 2003
Posts: 125

Premium

PostPosted: Tue Jul 04, 2006 2:40 pm    Post subject:
Reply with quote

My current hardware is an LinkSys BEFSX41.

P.S. Thanks for the great advice!

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Tue Jul 04, 2006 2:41 pm    Post subject:
Reply with quote

Sorry, you have an old Linksys, I missed that in your original post. IIRC, the original versions of that model did not have either port stealthing (it did have port blocking but it was not completely effective) or SPI, so the TZ-150 will be more effective just in its' base configuration even without the additional subscription add ons. With the add ons (they cost about $150/year for the package - called "Gateway Protection") it will be much more protective than the old Linksys.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Firewalls All times are GMT
Goto page 1, 2, 3, 4, 5  Next
Page 1 of 5

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer