On The Insider: Tila Tequila Announces Engagement
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 3 of 20:
Next »
« Previous
Thank You TIMEBOMB. Heres More.
I have several clients who wanted to be cheap. And cheap both ways. They didn't want to buy more ram to run anti-spyware programs in the background. And of course they thought that a router stopped drive by downloads. So they didn't want to buy antispyware software. They thought that a router was a permanent, one time cost, solution.

One client heard this and heard that, and wanted me to install a IP to IP (serial) router setup. (using two routers and setting the first and third IP # on them to different private router addresses and turning on DHCP, making the second router think it was plugged into a cable modem by plugging into its internet port. This is not the same as link-to-link (parallel) dual router setups where you just hook up the routed side links.) Serial setup of two routers protects you from anyone that hits the first router.

I said I will do what you want, but it will not stop anyone from drive by downloading. It was hard to get him to understand that once you request a web page, your computer and router(s) assume(s) you want the page and open ports to talk to the web site. When they transmit back, they can also send a drive by download. You have opened the ports, because you asked for that web site. Bang, they got ya! Routers do not care about blocking requested information from any IP address that is sending correct packets.

WELL, his computer just kept on slowing down. He never would let me run a spyware scan before. But when he called me again, I said I will give you 2 free hours if you will let me scan your computer with anti-spyware software. He said; "my routers are protecting me so I don't think that is the problem." "But since your going to do it for free, I'll let you prove yourself wrong." (Makes you wonder why he even called me if he knows all the answers?)

So I gave him the two free hours. I even used the three free anti-spyware programs, Spybot, Adaware SE, and (trial version) of Spyware Sweeper. His computer had every spyware, malware, and keylogger listed. He only had 256 MB of ram and even under normal conditions; He had 23 MB left over to run programs after a clean boot. (All this auto-running on a normal boot: OS, Stupid Printer interface software, AV-Mcafee, Software firewall-Mcafee, Stupid hotlink contact information for the PC manufacturer, Stupid Office package startup, Stupid Hot toolbars for three search engines, Messenger, and Launching outlook express-stupid.) What a load already. I had to turn off some of the resident programs just to get the anti-spyware programs to run.

Now on top of that, he had 135 MB of malicious software running. Windows was beating the hard drive to death using it as a ram-(swap) drive. And of course he could actually see this shortage every time he wanted to run a program. It took 45 minutes for a simple program like notepad to come up. I let the software remove them. And then I had to go out to the registry to eliminate the keys for the ones that will regenerate themselves when you try to remove them.

He didn?t want to add any anti-spyware at the time. He said; ?well you found a bunch of spyware. So what? It was probably on there before you installed the hardware fire-walled routers.? I said o.k. and left. Two days later he calls me and says; ?It?s doing it again.? I instructed him on how to run the scans again and 78 of the 12,279 spies had returned. I told him; ?They know where you are at. And without a true ASW shield, they will keep doing that to you.?

He finally let me install a spyware shield. He apologized; ?Man I?m sorry. Everybody has been telling me a bunch of Malarkey!. Sorry I was so hard-headed.? I told him that no apology was required. There are a lot of people out there that became experts after buying their first computer or first router. They honestly believe they are protected from everything.

---------------------------------------------------------------------------
Want to see how well your router protects you? Go to this site and check to see if they can read your internal IP address. It will be a red triangle warning on the page:

http://www.auditmypc.com/free-spyware-removal.asp

The site is harmless. If your software firewall responds to it, and you don?t allow it, it still means that it got past your router. (Or your SW firewall would not have warned you it was incoming.) But 9 out of 10 systems tested show the internal IP. The other one triggers the firewall. You may also want to read the information at this site on how to stop sites from reading your clipboard.
---------------------------------------------------------------------------
Posted by: internet11   Posted on: 04/29/06 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

I already have a tool that does this.  Mr. Roboto | 04/28/06
Wrong  TimeBomb | 04/29/06
Thank You TIMEBOMB. Heres More.  internet11 | 04/29/06
Firewalls are no help...  BitTwiddler | 04/30/06
Awsome  jstead1 | 04/28/06
I have a tool like this already!  The Rifleman | 04/28/06
Ummm...  TimeBomb | 04/29/06
It's about time!  darreno1 | 04/29/06
One more protection program?  jpr75_z | 04/30/06
I Tend To Agree! But JPR75_Z. Did We Learn?  internet11 | 04/30/06
would it be possible  xuniL_z | 05/01/06
Primitive FUD.  Anton Philidor | 04/30/06
an anti-virus does not stop exploits  Suzi_z | 05/01/06
Why not just avoid IE?  johnsmith222 | 05/01/06
I think that might just be an even trade  xuniL_z | 05/01/06
Need math lesson  Langalibalene | 05/01/06
ok.  xuniL_z | 05/01/06
Maybe its just me  zmud | 05/01/06
an excellent driveby preventer  jon702@... | 05/01/06
exploits are not the same as drive by downloads  Suzi_z | 05/01/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

SmartPlanet

Click Here