[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: IDS: Computer Security - Long message
FAQ: See http://www.ticm.com/kb/faq/idsfaq.html
IDS: See http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html
HELP: Having problems.. Then email questions to ids-owner@uow.edu.au
NOTE: You MUST remove this line from reply messages as it will be filtered.
SPAM: DO NOT send unsolicted mail to this list.
USUB: email "unsubscribe ids" to majordomo@uow.edu.au
---------------------------------------------------------------------------
> Hi,
>
> ConSeal Firewall 1.35 for Windows 9x, imho, its the best option for a firewall. You can use it with NukeNabber (www.dynamsol.com/puppet) and @Guard (www.atguard.com), for best protection (not just IP filtering). In NT ConSeal works fine too.
>
> The 30 days trial version (1.04 and not 1.35) you can get on www.signal9.com can disapoint you, because if can be crashed/killed by some script kiddie using known exploits. Test it, and then buy it, because 1.04 as many known ways to crash (and no, there is no crack for 1.35 version, as far as i know, if i'm wrong please let me know).
>
> The "pop-up message advising" is when the firewall is on "learning mode" ... it's one of the things you must disable if you dont want to be flooded out the net ... turn on "warn safe" too, for the logs just log each 2 secs (or for example a smurf can easy crash you in a slow connection).
>
> About trojan ports like 12345 and 31337, its better monitor and protect them in NukeNabber too, like some more other ports.
>
> I'm a Signal9 helper (but i'm not from Signal9) in Undernet at #firewall, where you can get help (see also http://www.betatesters.com/firewall/) and where sometimes James Grant or Sam Curry from Signal9 Support use to be.
>
> It's my pleasure if i can help about logs or firewall configuration. At Betatesters page about ConSeal you can get a ruleset for easy configure the firewall. You just have to change some rules with the primary and secundary DNS of your(s) ISP.
>
> Fell free to mail me about this to this mail (fmartins@pt.imshealth.com) or to my home mail (bacano@esoterica.pt).
>
> Just a little example ... i allready send logs for analisys at Signal 9, with 13Mb long for just 1 single attack ... and i didnt crash, just got a little slow ;-)
> In other hand ... a bad configuration just take 2/3 "log lines" to put you down ...
> Good luck
>
> Kind Regards,
> Fernando Martins
>
>