![]() |
Conficker virus rant (boring) |
Post Reply ![]() |
Page 123> |
Author | |
chickenfizz ![]() Young Croc ![]() ![]() Joined: 17 March 2008 Location: United Kingdom Status: Offline Points: 982 |
![]() ![]() ![]() ![]() ![]() Posted: 20 January 2009 at 9:56am |
OK, I've been reading about this terrible worm that's been affecting millions of PCs etc...
I'm having a rant, don't take what I say here as fact, it's mostly speculation and wonderings. There doesn't seem to be a lot of information about how the worm actually attacks, I understand it's through a security hole in the windows 'server' service. All the advice on the web says, "users should always install all the latest patches from microsoft and make sure your security software is up to date". Personally I suspect this is crap (although I don't know for sure). I've seen many PCs with automatic updates enabled and running the latest security magic and they all run like a bag of hammers and half the time you've got things popping up from the taskbar demanding attention, restarts, updates more resources etc etc. And often these PCs still have viruses anyway! After recently fixing a PC for someone I updated them to the latest version of AVG, this litterally halfed the performance of the machine. For years I've run windows XP with no anti-virus, with no automatic updates (although I do install service packs) and with windows friggin security center disabled. I am behind a hardware firewall and use a hosts file to block ads etc and have sensible surfing habits! I haven't had a virus in the last 4 or 5 years. Now I don't see why my firewall alone isn't enough to stop this virus from infecting me, as I understand it the worm is on the wan side and my computer would effectively have to ask to be infected before anything could get through to my network unless I was specifically forwarding ports to allow external access to the windows networking (foolish). Am I right? Is the real answer to the problem, "everyone use a firewall"? I don't see the point in preventing viruses etc by running software which uses half your memory, constantly scans files, flashes messages in your face, uses network bandwidth and cripples performace, is that not just like having a virus? |
|
![]() |
|
The Garglebard ![]() Registered User ![]() Joined: 29 August 2008 Location: Lancashire Status: Offline Points: 362 |
![]() ![]() ![]() ![]() ![]() |
YesÂ
![]() |
|
![]() |
|
toastyghost ![]() The 10,000 Points Club ![]() ![]() Joined: 09 January 2007 Location: Manchester Status: Offline Points: 10883 |
![]() ![]() ![]() ![]() ![]() |
The latest AVG is awful, but it can be made reasonable if you disable the link scanner part of it before installing.
|
|
![]() |
|
AlfieDring ![]() Young Croc ![]() ![]() Joined: 04 September 2006 Location: Bath, UK Status: Offline Points: 842 |
![]() ![]() ![]() ![]() ![]() |
Same, but make that a software firewall 10 years (apart from one annoying little pesky thing, but that came off a USB key anyway...) Alf |
|
![]() |
|
djgorey ![]() Young Croc ![]() ![]() Joined: 29 December 2007 Location: S. Wales Status: Offline Points: 1306 |
![]() ![]() ![]() ![]() ![]() |
A lot of these e-mails warning you of "big dangerous virus" or "big dangerous scam" are pure spam.
And has for viruses...I've got a Mac
|
|
![]() |
|
nickyburnell ![]() Old Croc ![]() Joined: 06 February 2005 Status: Offline Points: 4410 |
![]() ![]() ![]() ![]() ![]() |
Depends on the firewall. NAT translation as I understand it wouldn't stop this. A hardware firewall configured correctly or something like ZA would I believe stop it. However, most people cannot deal with Windows updates never mind a firewall. People see PC's as TV's, something that sits in the corner when in fact they are like their cars, learn to maintain or pay.
So yes I believe a proper firewall will keep the latest bug out (or in
![]() As a foot note, please don't encourage people with no knowlege to run without AV. It's OK for you because you understand, hundreds of Joe Public with no AV doesn't bear thinking about.
Rgards
Nick
This thread should be in the Computer section.
|
|
It's everything, not everythink!
|
|
![]() |
|
tb_mike ![]() Old Croc ![]() Joined: 01 October 2004 Location: New Zealand Status: Offline Points: 2744 |
![]() ![]() ![]() ![]() ![]() |
FOOD MONOCULTURE = DANGEROUS.
SOFTWARE MONOCULTURE = EQUALLY DANGEROUS btw "windows for warships" is being brought out by the MOD! "Monoculture and the Irish Potato Famine: cases of missing genetic variation" If you want to see how easy it is, just search 'metasploit' on youtube. Note that microsoft are a little wierd about it - suggesting users to use the existing windows firewall(which is rubbish). Yes our firewall is limited,but that makes things easier.Ive found that the average user isnt capable of deciding what traffic to let out. Yes they 'learn' and remember your settings. But what when thisisnotavirus.exe wants to make an outbound connection? According to my understanding,yes a proper firewall that will block the windows service -preventing it spreading via that manner. Ofcourse you may get it from your buddys USB stick, and then your firewall may ask if a wierd exe can setup an outbound to an odd URL. Ive been following this too. I had to look at several sites to collect decent info. It seems to spread also by malformed autorun.inf on usb sticks aswell - check for a crazy .vmx in notepad in it.Or disable autorun. You know its funny, Ive used XP for years with a 3rd party firewall , no AV for 99% of that time. Almost no problems,and the benefit of a very fast PC. I was on dialup until recently,so gave up updating. But im not your average user using outlook to send/receive funny .ppt,.doc,britneyspears.jpg.exe, or attempting to download LOST from warez etc. If you scroll through the long MS article, it tells you the work arounds -disable 'computer browser' and 'server' services. These are to do with SHARES and a person who has one pc wont even need. Prevention is better than the cure,as anyone who has treid removing nasty malware would know. I actually have a small XP partition,ready for quick formatting , install drivers from CD and then its fresh as... I do about 6times a year - heaps of spyware hides in windows\system32 or your documents and settings - where youl never find it.Especially if your rootkitted-youl never even seen the malicious files. I guess you might see them if you used a linux live cd and mounted your windows partition and had a look. I found an informative mcafee blog which explains interesting malwares. Il post the link when I find it again. Edited by tb_mike - 22 January 2009 at 4:54am |
|
![]() |
|
tb_mike ![]() Old Croc ![]() Joined: 01 October 2004 Location: New Zealand Status: Offline Points: 2744 |
![]() ![]() ![]() ![]() ![]() |
I think the vast majority of people who have bought recent PCs infact run one OR MORE anti virus programs. But without a decent firewall, its like leaving the windows open with the alarms on. The scary thing is, the latest tvs are going online, so theyl be hackable. Hopefully they run a locked down BSD or embedded linux system. It looks like too many arent patching - http://www.theregister.co.uk/ Interestingly both our local ministry of health,and the british ministry of health got infected. |
|
![]() |
|
nickyburnell ![]() Old Croc ![]() Joined: 06 February 2005 Status: Offline Points: 4410 |
![]() ![]() ![]() ![]() ![]() |
Just a pointer. I've seen the Conflicker on two memory sticks now. In both occasions the stick showed up in My Computer as a folder, not a drive. When cleaned back to normal.
|
|
It's everything, not everythink!
|
|
![]() |
|
Disco Stu ![]() Old Croc ![]() Joined: 03 March 2005 Location: United Kingdom Status: Offline Points: 2487 |
![]() ![]() ![]() ![]() ![]() |
Macs have viruses too, they just dont have a big enough market share yet for people to bother, as a huge amount of people own windows machines, and microsoft is particularly vulnerable. If they overtake microsoft and become the main computer market, you will see more viruses. Its just a computer, ALL systems can be hacked. Stu
|
|
All you need to know is:
Sensitivity + Power Handling - Power Compression = Max Output My acts: www.myspace.com/thebowiexperience www.myspace.com/scheisseelektronisches |
|
![]() |
|
djgorey ![]() Young Croc ![]() ![]() Joined: 29 December 2007 Location: S. Wales Status: Offline Points: 1306 |
![]() ![]() ![]() ![]() ![]() |
Yes I totally agree! As soon as Apple get more popular than Microsoft (which is probably never going to happen), the viruses will be there. However, at the moment, I'll keep my smug face on! For the virus writers, it's all about having the biggest impact and they'll never get that from writing a virus for a computer only a small percentage have.
|
|
![]() |
|
darkmatter ![]() Old Croc ![]() Joined: 26 February 2005 Location: LDN Status: Offline Points: 2425 |
![]() ![]() ![]() ![]() ![]() |
I've had hardly any problems over the last few years by running a decent rule based firewall (Kerio 2.1.5).
I agree, instead of running ten pieces of antivirus software you might as well have a virus ![]() |
|
![]() |
Post Reply ![]() |
Page 123> |
Tweet |
Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |