-
Thanks again Forester. I will have to try the rc.local. I got the update-rc.d info from the rcs.d read me. What I also discovered is that programs that I completely removed using apt-get and autoremove, did not delete the symbolic links in the rcS.d. A couple of which were previous firewalls I tried and later removed. I thought the extra links might have something to do with the problem. I guess I was fortunate to be able to clean them out using update-rc.d. Anyway, at least now I have another route to pursue.
-
Additionally, using "netstat" I found many connections doing I/O's. and flooding me with SYN's (I think they are bad). "arno-iptables-firewall status" will also give you feedback on what the "script" is doing to protect you. After installing the firewall I saw download bursts up to 170 KBPS, never seen before. Any unwarranted connection now gets dropped. I guess I have a bad router. But routers generally ship open. I prefer to develop my security in the firewall, leaving my ISP's router as they shipped it in case I need to call them. I have tried tinkering with the router settings in the past and was almost unable to recover the original settings. (newbie x 2)
Last edited by BoDiddley; 04-20-2011 at 01:29 PM.
-

Originally Posted by
BoDiddley
Additionally, using "netstat" I found many connections doing I/O's. and flooding me with SYN's (I think they are bad). "arno-iptables-firewall status" will also give you feedback on what the "script" is doing to protect you. After installing the firewall I saw download bursts up to 170 KBPS, never seen before. Any unwarranted connection now gets dropped. I guess I have a bad router. But routers generally ship open. I prefer to develop my security in the firewall, leaving my ISP's router as they shipped it in case I need to call them. I have tried tinkering with the router settings in the past and was almost unable to recover the original settings. (newbie x 2)
It is difficult to generalise about ISP since folks on this forum are all over the world. I guess many have a solution that uses "Internet Connection Sharing" under Windows. That may rely on firewall software running on the machine that shares out the internet connection. I'm not familiar with the technical details. When I switched to broadband my new ISP offered me the choice: use their ADSL box or my own so I bought my own. It's the DHCP server for my home LAN and came with the correct default firewall configured. It meant I've never needed to look into firewalls and proxies and all that stuff in detail.
You need a firewall between you and the Internet but it is only part of the story. There is so much misinformation out there.
SYNs are not bad. There are an essential part of establishing a TCP/IP connection. There is a particular kind of denial of service attack that floods a vulnerable system with SYNs. The vulnerable system allocates some resources and replies OK in order to complete the connection. The attacker does not complete the connection but keeps sending more SYNs. This can tie up enough resources to bring a server down.
Inbound connections never get made unless you've 'opened the port' by starting some daemon service. The bad guys are like vampires - they can't just break-in while you're not home, someone has to invite them in. So what daemons are you running ? mysql ? ssh ? ftp ? telnet ? We had someone on the forum the other day wanting to open port 631 (ipp) so he could print from the Internet.
Which options did you use with netstat ? With no parameters it will list lots of connections that are internal to your machine. You need only be concerned about tcp, udp and raw socket connections.
Oh, if you are editing posts under Iceweasel and you have NoScript running, you need to allow both knoppix.net and googleapis.com
but it make editing bearable.
-

Originally Posted by
BoDiddley
What I also discovered is that programs that I completely removed using apt-get and autoremove, did not delete the symbolic links in the rcS.d.
Oh. Did you use apt-get remove or apt-get purge ? The first does not remove configuration files and, may be, that means these symbolic links.
-
I used remove, and autoremove. I did not know about purge - thanks. ... Iceweasel - have allowed both but my editor is still a nightmare. Have to try a different spell checker as previously mentioned. I just used netstat without switches... I am familiar with protocols. I always ran my own firewall in Windows. I am running no daemons, however, what I have noticed is the ability for some to utilize an existing http to trace, determine IP and flood - so it would seem. They seem to lurk on sites and disrupt legitimate requests you initiate.
Last edited by BoDiddley; 04-23-2011 at 08:53 PM.
-
There is one big name company that is always listed on my http connections, they have 4 primary servers - and can hop to others if you block theirs. They can disrupt me but with an active firewall, the moment they try any I/O they get dropped. They used to trace my http back, and then begin searching for open ports using about 10 to 20 different connections from the same server, and tie up all my resources. This might not make scientific sense, but it does happen.The syn floods have stopped as well. Some time nusiance seems the objective - for me. But I am certain ther are cataloguing and planting bots for all those happy-go-lucky users without a care.
-

Originally Posted by
BoDiddley
There is one big name company
Not Wikileaks then. 

Originally Posted by
BoDiddley
that is always listed on my http connections,
That doesn't sound normal. I guess you are streaming television.

Originally Posted by
BoDiddley
But I am certain they are cataloguing and planting bots for all those happy-go-lucky users without a care.
Big Brother then. 
Actually I think the way it works is some patsy runs a program for a buck and hour that does the probing and cataloguing of vulnerable sites. The program reports back to the tech guy who plants bots at a later date. The tech guy sells lists of infected IP addresses to the really bad guys.

Originally Posted by
BoDiddley
They used to trace my http back, and then begin searching for open ports using about 10 to 20 different connections from the same server, and tie up all my resources. The syn floods have stopped as well.
The attack sounds classic. Through your http connection they can tell you are using a Mozilla based browser - it's in the protocol. Perhaps they can also tell you're running Linux. Perhaps they assume Linux users are complacent and therefore likely to be vulnerable.

Originally Posted by
BoDiddley
This might not make scientific sense, but it does happen.
Some time nuisance seems the objective - for me.
That won't be the objective. The objective might not be criminal but you really want to keep out of it. I could image a 'security' firm being tempted to do research this way, Likewise I can see Ebay being concerned about folks with a Paypal account and a vulnerable PC. I could also imagine government agencies preparing for the cyberwar they believe is coming.
Anyway, I'm just glad you are protected now. Myself, I'd never go near that site again. But that's just me.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules

GIGABYTE B365 HD3 LGA1151 Intel 9th Gen motherboard
$59.99

Corsair RMe RM850e 850W 80 Plus Gold Fully Modular Low Noise Certified Refurb
$58.99

Gigabyte GA-B85M-D3H Motherboard
$54.99

ASUS PRIME Z490-V Motherboard Intel Z490 10th gen DDR4 LGA 1200 ATX w/ IO Shield
$84.99

GIGABYTE A520M DS3H AC AMD AM4 Motherboard mATX
$59.99

Asus Prime B660M-A AC D4 Motherboard Intel LGA 1700 14th 13th 12th Gen DDR4
$79.99

Intel H81 Motherboard M.2 NVMe LGA 1150 mATX w/ IO Shield (Random Slot Color)
$29.90

(Factory Refurbished) ASUS TUF GAMING B650-PLUS WIFI DDR5 AMD ATX motherboard
$97.99

ASUS PRIME Z890-P WIFI Z890 LGA 1851 ATX motherboard, Intel® Core™ Ultra Series
$235.99

Gigabyte Z370M D3H LGA1151 DDR4 Micro ATX Motherboard PCIe 3.0 Desktop Mainboard
$77.99