-

Originally Posted by
BoDiddley
Additionally, using "netstat" I found many connections doing I/O's. and flooding me with SYN's (I think they are bad). "arno-iptables-firewall status" will also give you feedback on what the "script" is doing to protect you. After installing the firewall I saw download bursts up to 170 KBPS, never seen before. Any unwarranted connection now gets dropped. I guess I have a bad router. But routers generally ship open. I prefer to develop my security in the firewall, leaving my ISP's router as they shipped it in case I need to call them. I have tried tinkering with the router settings in the past and was almost unable to recover the original settings. (newbie x 2)
It is difficult to generalise about ISP since folks on this forum are all over the world. I guess many have a solution that uses "Internet Connection Sharing" under Windows. That may rely on firewall software running on the machine that shares out the internet connection. I'm not familiar with the technical details. When I switched to broadband my new ISP offered me the choice: use their ADSL box or my own so I bought my own. It's the DHCP server for my home LAN and came with the correct default firewall configured. It meant I've never needed to look into firewalls and proxies and all that stuff in detail.
You need a firewall between you and the Internet but it is only part of the story. There is so much misinformation out there.
SYNs are not bad. There are an essential part of establishing a TCP/IP connection. There is a particular kind of denial of service attack that floods a vulnerable system with SYNs. The vulnerable system allocates some resources and replies OK in order to complete the connection. The attacker does not complete the connection but keeps sending more SYNs. This can tie up enough resources to bring a server down.
Inbound connections never get made unless you've 'opened the port' by starting some daemon service. The bad guys are like vampires - they can't just break-in while you're not home, someone has to invite them in. So what daemons are you running ? mysql ? ssh ? ftp ? telnet ? We had someone on the forum the other day wanting to open port 631 (ipp) so he could print from the Internet.
Which options did you use with netstat ? With no parameters it will list lots of connections that are internal to your machine. You need only be concerned about tcp, udp and raw socket connections.
Oh, if you are editing posts under Iceweasel and you have NoScript running, you need to allow both knoppix.net and googleapis.com
but it make editing bearable.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules

(New) AMD Ryzen 7 5700X 8 Core 16 Thread AM4 Unlocked 3.4 GHz CPU OEM Tray
$174.99

AMD Ryzen 7 5700X 8-Core 16-Thread AM4 Desktop Processor - Tested & Working
$155.00

MSI GF63 Thin 11SC-693 15.6" 256GB SSD, Intel Core i5 11th Gen., 8GB Windows 11
$550.00

Dell OptiPlex 5090 SFF PC w/ i7-10700 2.9GHz CPU 2TB HDD 8GB DDR4 RAM Win 10 Pro
$209.95

Intel Core i7-6700 SR2L2 3.40GHz 8 MB 4-Core LGA1151 Socket CPU Processor
$27.99

AMD Ryzen 7 5700X 8-Core 16-Thread Unlocked Desktop Processor 3.8GHz
$165.00

AMD Ryzen 7 5800X3D 3.40GHz 8 Core 100-000000651 16 Thread AM4 CPU
$290.99

Intel Core i9-9900KF 3.60GHz 8-Core LGA1151 CPU SRFAA - Tested Working
$169.99

Lenovo Thinkpad E15 Gen 2 8GB RAM 256GB SSD Intel Core [email protected] Laptop
$220.36

Dell OptiPlex 5070 SFF i7-9700 (8-Core) 3.0GHz 16GB 256 SSD Windows 11
$250.00