View Single Post
  #17 (permalink)  
Old 12-18-2007, 10:40 AM
wige's Avatar
wige wige is online now
Moderator
WebProWorld Moderator
 
Join Date: Jun 2006
Location: United States
Posts: 2,648
wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9wige RepRank 9
Default Re: hard drive downloaded

Quote:
Originally Posted by weegillis View Post
Any kind of excessive network activity should have been reported, and blocked. There is no way a hard drive can be transmitted over the network without some kind of flags being raised, unless of course all the user has is windows firewall. In this case their ISP should have intervened.
Even with the most stringent of firewall rules, it is possible for an attack like this to succeed. For example, imagine the target computer is on a home network, with antivirus and a firewall. There is a second system on the network with antivirus and a firewall as well. Antivirus is up to date and the firewalls are properly configured. As you browse the web on your computer, you come across a recently hacked web site that profiles the computer and immediately uploads the appropriate virus to install a backdoor and delete the antivirus definitions. Because the virus is contained in normal Internet traffic, the firewall does nothing to stop it, and the virus is new and has not been added to the definitions in the antivirus software. The backdoor establishes an outgoing connection to the attacker's own server, mimicking Internet Explorer or Firefox traffic so the firewall again does nothing to stop it. The attacker receives a message from the web site indicating the IP address that was compromised and logs in to the backdoor connection and manually changes the firewall rules to allow the backdoor to accept incoming connections. At this point, the computer is wide open. In addition, data on every computer on the network is open to compromise if file sharing is enabled.

There is no absolute solution to prevent malicious activity on your network. The best you can do is have a multi-tiered security system - antivirus, antispyware, software firewall, hardware firewall, all with proper precautions installed - to minimize your risk as much as possible.
__________________
The best way to learn anything, is to question everything.
Reply With Quote