Due to a recent rash of hackings in wow i am taking a new intrest in my computer security, and have a few questions
Which are the good ones? Might it be wiser to replace it with 2 specialist programs?
Any thoughts, ideas, input would be appreciated.
I am currently using Zone Labs Zone Alarm Security Suite, but i was wondering if any1 knows what level of protection this actualy gives.
Same as you, I'm using ZoneAlarm (http://www.zonelabs.com/store/content/catalog/products/sku_list_za.jsp?dc=12bms&ctry=US&lang=en&lid=nav_za) as my firewall, but I'm not using the whole Security Suite, I'm only using the free alternative that contains only of the firewall part - which imo opinion is mostly enough. I used Norton some years ago, but that suck up waaay too much resources (and you have to pay for it), so I dumped that one pretty fast.
About those recent threats of hackings of WoW accounts: that is based on the scenario that somebody has been able to install some kind of key logger software on your computer (either throug a malicious link, some script on a site or whatever).
For such a program to be harmful to you, the program itself must be able to connect to the internet to send out the information it has gathered, or the hackers must be able to contact the program on your computer to retrieve the data from it. For that to be possible, you must allow it to either access the internet or act as a server (listen to the internet for connections).
So as long as you have ZoneAlarm up and running (or some kind of other firewall, as long as it's not some student's (like myself :P) school project), and don't allow any random request for internet access that pops up, you should be pretty much safe :)
Even though it doesn't have much with this to do, I could mention that I use Avast (http://www.avast.com/eng/download-avast-home.html) as my anti-virus software. It's free (you have to register your name and e-mail to get an activation key), easy to use, and I haven't had any problems with it as long as I've used it.
Thanks bob, i am prob looking at a format right now due to some windows problems, so on a fresh install ill prob set it up a bit stonger. And any other opions are still appericiated :smile:
I've never been keen on integrated products, perhaps unfoundedly. I can't abide Norton so I've made sure swerve it. I'm using the Enterprise version of McAfee 8 (via work) as AV but Avast and AVG are good free products.
Am I silly for not running a hardware firewall and relying on my router? I know some people advocate it. I can get ZoneAlarm Pro from work, I've used their free product and wouldn't say it's bad at all. As long as you can configure it in the right places to allow things to continue working.
I run regular sweeps with Spybot S+D (some back it with Adaware), it and my AV are ensured to be updated.
The whole home security thing is multilayered: Firewall(s), AV, ASpam, OS patches (I use MS WSUS to manage my home machines), passwords and network security (especially if wireless). It's a trade-off between security and ease of operation. I'm quite happy that a little more time spent securing rewards by not having to recover a mess later, even if a password is a little more convoluted than "password".
you should also check out ewido as an adware scanner. it's one of the better ones and I think now owned by Grisoft (AVG) so hopefully complimentary. It's useful to keep things like hijackthis, rootkit revealer, and some trojan-detector on hand just in case you suspect something's up. I think it was rootkit revealer that showed I had a 2 year old install of starforce v1.2 as well as an install of a recent GTL-induced starforce v3 or whatever, both running...
I also would like to know what people advocate wrt firewalls. I rely mainly on my router and the windows firewall (shock horror) simply for ease of use. I tried Zone Alarm a few times but tend to find it overly needy requiring constant attention to stop it breaking my legit programs, and also to stop unwanted stuff. I thought the Kerio firewall was easier to use than the Zone Alarm one, but even then I've yet to find anything as simple to use as the inbuilt widows firewall.
I run a hardware firewall on the ADSL connection and then ZoneAlarm Pro as a software firewall and AVG as my anti-virus. I run a variety of spyware and anti-trojan packages which I use to scan my machine on a regular basis. Nothing really nasty found yet and long may that continue - because having my WoW account hacked scares the bejayzus out of me.
TL.
I use ZoneAlarm security suite. I had enough of Norton's insanities (I'm a beta tester for Symantec, and really - I have had enough).
ZA SS is a curious beast - comprises not one integrated tool (though it does its best to look that way) but in fact a whole bunch of tools from various sources which they really should do a better job to make look more like a ZA product. Maybe in a later version... Either way, for the most part it works well, and the ZA firewall is moronic but effective.
If you have a few machines to license, bulk licensing starts at only 3 machines - search for the links in the consumer (NOT business) area. It's cheaper to license 3 than 2, as I recall.
I think my router has a basic firewall of sorts and i use windows xp firewall aswell. I use to use zonealarm free but it started to block webpages after a while so i just gave up. Is this still a problem? Would you say my current protection is enough? I use avg free and lots of anti trojan scanners aswell but did think of getting a hardware firewall too. Any suggestions TL?
i use mcafee firewall and a norton 2005 antivirus
no problemos
No firewall on my actual box iteself, but I certainly run a virus scanner (AVG Free, as several people have already recommended). After all, email viruses get through your firewall unless you block all mail. Firewall wise all the PCs in my house run to t'internet via a FreeBSD box running PF, which is handy as both a firewall, NAT and a QoS system so someone else's big downloads don't affect my WoW :biggrin:. I simply block *everything* inbound that isn't either a response to an outbound packet sent by one of the house machines or part of a TCP stream set up by a machine within the house. Of course if I ever wanted to run a game server or Ventrilo server or something i'd have to set up some port forwards, but that is fairly easy once you've got the hang of PF.
Quote from: tugs;153426I use ZoneAlarm security suite. I had enough of Norton's insanities (I'm a beta tester for Symantec, and really - I have had enough).
I took this one too, if it works for him its good enough for me also, and i could get a free key, which always helps :biggrin: Any idea on where the different bits come from?
I use AVG including firewall, just bought it for 2 years, only about £28
Last night I've checked this thread again and it was pretty usefull (my internetconnection got lost the last few days or going really really slow, might be because of a virus/trojan). Tonight I'll make a new thread about AntiVirus and such which will include all suggestions and such given.
I also found a nice for Bastet if he still has the problems (sorry guys, the text is in Dutch but I'll translate it when I have the time):
http://www.hijackthis.nl/computerschoonmaken.html
Having used various distros of Linux/BSD over the years for firewalling and routing duties, recently I've been trying security/AV/router sentry systems.
The PC
All you need is an old PC and a couple of NICs - my current box has 128MB of memory and a 4GB HD. I'm sure most people's upgrades have left them with enough bits lying around to build one. With 3 NICs, you have the option to set up a DMZ - a network segment available on the Internet (web, mail ftp, etc.) but isolated from the rest of your home network - probably overkill for the average non-geek though...
The Distros
IPCop - http://www.ipcop.org
"IPCop Linux is a complete Linux Distribution whose sole purpose is to protect the networks it is installed on. By implementing existing technology, outstanding new technology and secure programming practices IPCop is the Linux Distribution for those wanting to keep their computers/networks safe."
Endian Firewall Community Edition - http://www.endian.it/en/community
"Endian Firewall Community is a "turn-key" linux security distribution that turns every system into a full featured security appliance. The software has been designed with "usability in mind" and is very easy to install, use and manage, without losing its flexibility. The features include a stateful packet inspection firewall, application-level proxies for various protocols (HTTP, FTP, POP3, SMTP) with antivirus support, virus and spamfiltering for email traffic (POP and SMTP), content filtering of Web traffic and a "hassle free" VPN solution (based on OpenVPN). The main advantage of Endian Firewall is that it is a pure "Open Source" solution."
Smoothwall - http://www.smoothwall.org
"SmoothWall Express is an open source firewall distribution based on the GNU/Linux operating system. Linux is the ideal choice for security systems; it is well proven, secure, highly configurable and freely available as open source code. SmoothWall includes a hardened subset of the GNU/Linux operating system, so there is no separate OS to install. Designed for ease of use, SmoothWall is configured via a web-based GUI, and requires absolutely no knowledge of Linux to install or use."
RedWall - http://www.redwall-firewall.com
- Configuration is currenty stored on a floppy/USB Memory Stick/Harddrive or sent by email
- Most reporting functionality is done via mysql (except for the squid reports)
- based on gentoo
- bridging support
- Mail Virus scanning, spamfiltering and gateway functionality
- /etc is writable (tmpfs) feeded by the configuration medium
- /var is writable (ramdisk or harddisk) (you are not going to run squid on a ramdisk... aren't you ?)
- The cd will (at least it should) detect all your network cards during the initial boot"
m0n0wall - http://m0n0.ch/wall/
"m0n0wall is a project aimed at creating a complete, embedded firewall software package that, when used together with an embedded PC, provides all the important features of commercial firewall boxes (including ease of use) at a fraction of the price (free software).
m0n0wall is based on a
bare-bones version of FreeBSD, along with a web server,
PHP and a few other utilities. The entire system configuration is stored in one single XML text file to keep things transparent.
m0n0wall is probably
the first UNIX system that has its boot-time configuration done with PHP, rather than the usual shell scripts, and that has
the entire system configuration stored in XML format."
In Use
I've only used IPCop and Endian, which are both (loosely) branched from the original Smoothwall, but they are both easy to install and configure. Just make sure you have your network planned and written down before you start the setup. Both have the facility to make a backup of your working configuration, so if you decide to try something else, you can restore a working version back the way it was.
The facilities in each distro vary somewhat some will provide web content filtering, some will provide SPF and so on - visit the web sites for a detailed list.
Conclusion
With the exception of m0n0wall, all the distros offer AV and spam filtering, NAT, firewalling, DHCP and proxying services which essentially remove the need for running the same stuff on your windows box - if set up and maintained regularly. Of course, anything that takes the load off your games machine has got to be a bonus - so dig out that "obsolete" PC, set up a proper sentry system and wave goodbye to Norton bloatware and the like.:thumbsupsmileyanim:
Brilliant post DM - I will be trying some of those to see how I get on. Thanks :thumbsup:
TL.