Trojans and Firewalls
Protection from trojans can go a little further. The modern day Internet Trojan's
primary purpose is to install a backdoor so that others can gain access to your PC across the
Internet, WITHOUT your knowledge. What they can do, once there, is determined by what trojan they
installed. The latest trojans allow the attacker almost unlimited control over your PC, including
deleting files, editing the registry, executing programs, ftp files in/out, monitoring your actions,
stealing password files and other sensitive information, and many other functions. Port scanners have
been written that make it easy for even a novice (called script kiddies) to find if you have a trojan
installed. They scan large numbers of IP address', extremely fast, looking for installed trojans.
Firewalls like Zone Alarm and
BlackICE, Port Monitors like
NukeNabber,
Attacker, and
PortWatch, and Proxies
are effective tools to help you detect and block access to your PC. Most antivirus
software companies also make firewall products. Microsoft's XP comes
with a
built in firewall. If you install a monitoring tool, and you get warned of a scan by
the program, don't get to excited. As I mentioned before, it is easy
for a novice to scan thousands of IP address quickly. It happens all the time. A recent court ruling
by the US District Court in Georgia, CIVIL ACTION FILE NO.
1:00-CV-434-TWT found that simply Port Scanning itself is not illegal, there was no damage or
impairment, and any cost associated with investigation and prevention are not recoverable. Basically
it's like someone walking through a parking lot checking car doors to see if they are locked. That act
itself is not illegal. If they actually enter an unlocked car, at best it's trespassing. If they cause
damage or theft, now that is illegal. With a computer it is much harder to prove damage and theft and
trespassing is a misdemeaner. DO NOT call our tech support to report that you have been scanned,
there is very little we can do. Like SPAM
E-Mail, any attempt to block the
person that scanned you, may also block ligitimate traffic from that ISP. You can find the ISP they
belong to and send them a copy of your logs asking that they look into it. If they get enough
compaints, and they can track it to the same individual, they will probably cancel their account.
|