[ILUG] From the register. XP machine rooted in 200 seconds.

Liam Bedford lbedford at lbedford.org
Thu Dec 2 11:16:24 GMT 2004


On Thu, 2004-12-02 at 11:02 +0000, Paul Jakma wrote:
> On Thu, 2 Dec 2004, Liam Bedford wrote:
> 
> > It was from my memory that the XP2 firewall drops ICMP by default. 
> > Could be wrong.. my memory isn't as good as paul's ;)
> 
> That report wasnt terribly detailed, but is it not possible they 
> recorded fewer attacks because the firewall had blocked the relevant 
> ports than that it was because ICMP was blocked?
> 
the windows firewall I've used most (zone alarm) classes any attempt to
do anything as an attack. It depends on what the "attack" is defined as.

> Cause I dont see tonnes of ICMP probes here, but I do see tonnes of 
> cruddage directed at various udp and tcp ports (which suggests 
> blocking ICMP makes 0 difference..)
> 
Maybe worms don't like you?

L.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: This is a digitally signed message part
Url : http://mail.linux.ie/pipermail/ilug/attachments/20041202/06309851/attachment.pgp


More information about the ILUG mailing list