Picture: The Importance of a Good Firewall

This is what happened when I took down my network’s defenses the other day. Fortunately my Windows machines were patched, or I might have been hit with a nasty remote exploit, or eighty. Click the thumbnail for the larger version.

Why A Firewall Is Important

Those are all incoming connections initiated via Netbios. If you don’t take the time to define static IP’s and explicitly allow incoming & outgoing connections, there’s an excellent chance your home network is being taken advantage of.

Additional Posts Worth Reading

 

2 Comments »

collapse Comment by IDGAF
2008-03-13 11:45:52

I noticed all of those connections are on a NIC/LAN interface. A little birdie told me you’re not a fan of wireless, but I thought it my duty to mention that while these exploits exist regardless of your connection type, a plethora of others are brought to light over the radio waves. So many times we see people go buy a pretty blue box with antennas on it, bring it home and plug it up, and watch their computer flash and connect with utter windows delight! While I personally try to keep abreast of wireless vulnerabilities your run-of-the-mill end user doesn’t really have to do a whole lot to secure and monitor a wireless network at home. Easy modifications that can easily be made on the GUI to vanilla router and AP configs can be a great start:

- static IPs (mentioned in this original post) - MAC filtering - Time based access restrictions - High level encryption methods - effective more so when coupled with authentication - preferably NOT located on the network device, but rather pointing to a secure server’s database

And for those of you who would like to go past your router’s GUI, tools like Kismet and backtrack are great for seeing connections from all network sources and all protocols.

If you have one of those linksys WRT54g router, (just like about half the population does) lots of different firmwareis out there to expand its capabilities.

And for god’s sake - beware the claims of 802.11n - it’s not a standard yet, and there’s a reason why.

So, if you think you’re prone to attacks on the wire, check your little blue box with the ears sometime.

Have faith Guy - the wireless revolution is upon us and may just drag you in kicking and screaming. The devices you use to heat up your pizza and one you use surf the internet are both useful AND dangerous.

collapse Comment by Guy Patterson
2008-03-18 08:19:20

You’re right about the kicking and screaming. Wireless has made huge security improvements, but the data is still being transmitted through free and open air waves. If it’s in the air, someone can capture it. If someone can capture it, someone can decrypt it.

Thanks for the good info though. Should check out iron geek for some real wifi cracking demonstrations.

 
 
Name (required)


E-mail (required - never shown publicly)


URI - Web Site Address






Subscribe

Site of The Day

Sponsors

Categories

Recent Comments

  • Arthur: I can’t even be an Ebay affiliate. Tried various ways but still declined. Any help or suggestions?
  • chicago web design: I can’t imagine that these will last very long before Google banishes them all. But for now...
  • D.Ksyte: Anyone involved with cron job scheduling might find this resource useful. Cron Sandbox at HxPI is an...
  • FoNiX: “…decode md5″ is not possible, only bruteforce: generate hash and compare with original.
  • Z@$#: plz plz decript this hash for me any one….its really important…. 2CAD28C7C619F27DDE7B83C4999795BA
  • Joe: Thanks for writing this up. I tried the second method…however after the debian install the screen looks...
  • Scott: Was this issue ever resolved? I just started having a problem a couple weeks ago. I don’t do any kind of...
  • Prashant Patel: I had integrated Sp3 in Xp But finding one problem. In the Task Manager Process windows many services...
  • Ed: This looks like a real ‘leet’ linux command but it misses the point. Why would a hacker keep the name of...
  • Sudesh: My account was disabled but I followed their guideline and in one sec it was back on :) Here is the...

Top Commentators

Miscellaneous

  • Add to Technorati Favorites