somebody can tell me what is DRVNCDB ?
thank you
Drvncdb
same connection 3 pc one my husband,one my pc,the other one my tenant up stairs
Please I want know How this happend to me, In my husband pc there was some of my history that I was visited days before in my pc,no everything, and he never touched the computer that morning, the night before he left the comuter on,and the next morning I found one window open and the history from that morning,and 100% my husband did not touch his computer that day,after few minute,everything disappeard window and history!!nothing was there anymore,and my husband did not belive me
Please tell how this is possible?
I think the tenant un stairs he doing somenting to us? he is really good with computers.
thank you
Tracking of IP adresses
Hey ey
I was wondering wether it would be possible for me to track down from where someone is connecting to the internet using an IP adress as it’s done in the "Anonymous Surfing Test"…
Thing is that someone (I suspect a few "friends") is pretending to be me over the internet and the only clue which i’ve got is his or her IP adress.
Nairu
Spam
Jim,
Know of any websites that can tell you if an IP address is spam. I looked online but they all listed my own IP as spam so I figured they didnt work.
Roger
IPSEC Services Problem
Regarding IPSec Policy,
http://www.auditmypc.com/ipsec-policy.asp
Local Security Settings > IP Security Policies on Local Computer
STATUS MESSAGE:
"Assigned, but the ‘IPSEC Services’ service is not in a running state."
Tried to start the service by entering Administrative Tools > Services
IPSec Services > Properties > ‘Start’
ERROR MESSAGE:
"Could not start the IPSEC Services service on Local Computer.
Error 1747: The authentication service is unknown."
OPERATING SYSTEM:
Microsoft Windows XP Professional SP3…
Intellectual Property Protection
Seclore Technology develops innovative solutions in the area of information usage control. Seclore is an Information Rights management company which recognizes the importance of intellectual property protection and has achieved industry leadership in the area of information usage control, information rights management, document security, enterprise DRM. Seclore provides world class document rights management solutions that allow controlling the usage of confidential information, regardless of where the information is physically present or how it is distributed. Seclore offers information security solutions for data contained in Files, Folders or provided to a vendor for outsourced processes.
I just thought I would let you know this.
Proxomitron software zipped tight
I’ve downloaded the proxy zip file which contains proxomitron software, but what is the password?
Summer Olympics
Jim,
A man was walking through the Olympic village carrying a long pole. A reporter asked him, "Are you a pole vaulter?" The man replied, "No. I am German, and how did you know my name is Walter?"
Roger
how to open port 80?
I’ve been trying different things and performing port scans on my system trying to see if my computer is secure, but it saying port 80 is closed on my ip
How do i open it?
i want to do DoS attack on my own home broadbande router(orange)
Hi guys…
thanks for last reply but i want to do a sample DoS attack on my own home router.i have attached 5 computer with it.
Is it possible i can do the DoS attack by using different ping command.
i am in big trouble please help me i will be very thankfull to you.
Regards
Jabran
DoS Attack Simulator help plzzzzzzzzzzzzzzzzzz
Hi guys,i am doing my project in DoS attacks and now i want to create the simulation Lab on DoS attack i need to show them.Can you plese tell me which simulator i can use for this and from where i can get the labs to do this project.i’ll be very thankfull to you.
MusicETC Firewall
Hello, I am a member of MusicETC (music sharing) and have been unable to connect due to a firewall somewhere. I have actually turned OFF my Windows Firewall and have also uninstalled my AVG Virus protector, but to no avail. I have tried adding Gnutelle as an exception to the firewall, even adding their port as an exception and nothing works. I have seen tons of other posts on various sites with this exact problem, but as of yet have read no solution. Do I have a firewall somewhere else that needs to be changed? I have Mozilla Firefox and no other anti-virus program that I know of. Any ideas?
Custom Protocol Hardening
Hi
I am working on a task for protocol hardening in linux. This involves testing the some existing standard network protocols and also testing new custom protocol for security vulnerabilities. I would like to know where I can find some defined test scenarios or standard test procedure to carry out the protocol hardening task.
I also want to know the different protocol hardening tools that can be used. Like fuzzing tools. I have found a few tool like Spike, Autodafe. But they don’t seem to work well. Spike is very old and it has lots of dependency errors. Autodafe is good but I would like to knnow more tools.
The main thing I require is the standard procedure to find protocol vulnerabilities in custom protocol.
sharky
computer security!
hi folks!
i’ve been surfing around for a while now; and really the best site i’ve seen, in matters of IP-adresses, Internet-security a.s.o. is by far this one.
really, i wonder why and how long jim is going to do this just for the fun of it, not to say for OUR benefit.
he is even kind enough to answer questions from users who obviously tend to hide whatever they can (just wondering why)! 
i’ve been searching in this forum and found nothing (so far) which really is basic to me. lots of users prefer to surf anonymously, than really protect themselves. they care about firewalls, IP-protection, a.s.o. but has anyone ever heard about prophylaxis?
i’m talking about programms which are supposed to protect you. and so i want to tell you about my experience with these programms called "antivirus":
since i’m working with PCs since about 22 years now, i tend to say that i had lots of opportunities to test some, but don’t worry, i’m not going to bore you with too much details and so i will just try to amuse you with the last 5 years.
i started (as most of us) with McAffee. one day one of my PCs showed a strange behaviour and i was curious enough to install Norton Antivirus. this new fellow all over sudden discovered 12 trojan horses which McAffee didn’t even see. so the choice was made. off we go with norton.
a very big disadvantage is that this fellow slows down the machines a lot; so i tested BitDefender. you can imagine how surprised i was, seeing, that my new pal discovered 3 viruses and 5 trojan horses, which norton lived very well with.
a good friend of mine finally gave me an adress for an antivirus, which i tested right-away. it was easy since this new programm offered a full fonctional evaluation-version for 30 days. i was disgusted to realize that my Bitdefender has also been fooled by (believe it or not) 12 viruses and 5 trojan horses.
i observed that this new program was very discrete, didn’t bother my CPU and sometimes, up to 5 times a day he updated himself automatically (i was still in evaluation period).
i’ve been working with this program now since 4 years and never ever had any problems. of course i meanwhile have a licenced version. The programm i’m talking about is NOD32 from ESET. if anyone is interested here’s the adress: nod32 . com
by the way: meanwhile i’ve turned off any firewalls and stuff like that, since my new (best) pal takes care of everything.
so folks, instead of talking and caring about therapies and hiding stuff, first of all take care of prophylaxis and prevention. i should not forget to mention that kapersky also has a very good reputation.
best regards
Constant Unsolicited Connection Attempts.
From my McAfee Personal Firewall log, I can see unsolicited connection attempts. They are coming at 5-10 minute intervals, and each consists of about 10 transmissions over a period of 1-2 seconds. They show several points of origin (obviously fake) but using the firewall’s trace option, I can see that no matter their origin or initial routing, the last link is always from a point in south-central Wisconsin to me.
Questions:
1. Should I be concerned? The firewall is blocking the transmissions, but I feel like I’m under constant attack.
2. I have a dialup line. My ISP says since I get a different IP each time I connect, it would be virtually impossible for this to happen unless I had some spyware alerting someone when I was "on the air". However, I have McAfee spyware protection, Spybot and Windows Malicious Software removal. None can find a problem. Do I need to look further for spyware?
Thanks for any help.
WinSvr2k3 as NAT Router & VPN Gateway, iy my config secure?
Hi,
I run a windows server 2003 as NAT router for a PPPoE Internet connection, and as a VPN gateway to access my home LAN over the Internet from PC’s on my university.
My LAN setup is quite extraordinary, I have a Hardware Router+4port Switch+WLAN accesspoint+DSL Modem in one device (zyxel p600) that is the property of my ISP and can not be configured by me.
The device is configured as a Bridge it provides DHCP and DNS, and appears by default as the standard gateway, however it does not provide any routing capabilities, any PC that want to access the Internet have to establish a PPPoE connection (Up to 5 simultaneous connections are allowed, every one with a different Dynamically assigned Extern IP address).
Since I use 4 of the 5 Connections for VM’s that require different extern IP’s, I have only one connection left for regular Internet usage, so I have setup a routing server (on witch also the VM’s are running).
The PC that acts as a router have only one physical NIC and is connected to the p600 over LAN and uses a PPPoE connection to access the Internet, a secondary PC (the one I’m usually working on) is also connected directly, the rest 4 other connects over the WLAN.
I head some troubles setting this up,
1st. was that that the "Routing & RAS" wizard does not allow a NAT&VPN config with only one NIC, though NAT with PPPoE only or VPN only works ok,
To get it to work I head to setup NAT&VPN giving it a virtual NIC as the one for the web during the setup process, than after it I head to manually replace in the config with a PPPoE dial in connection as seen in the NAT only config.
2nd. was that the P600 is by default set up as the standard gateway, and I head to set the server IP manualy as the standard gateway on the PC’s.
3rd. VPN clients couldn’t resolve the names of PC’s inside the LAN (excepted the server itself) to bypass this I head to setup an DNS and enter the server IP manually in the properties of the VPN connection on the remote PC, as well as setting up the host names to point to curtain LAN IP’s.
Due to the 1st and 2nd problem (the 3rd appeared when all was almost done and was easy to solve) I started a thread on a network related German board I know, but instead of help in setting up my desired config i get advices to buy extra hardware or a old PC to run as HW Firewall (IPCop), or comments that the config would be tremendously insecure and even some that it could never work with only one NIC in the server and so on.
Since obviously some if this comments about the feasibility ware plain wrong (my setup works just fine after applying 2 small tricks), I presume the comments about the security deficits are most likely also incorrect, since I can activate in the "Routing & RAS" settings a Firewall for the PPPoE connection and a on line port scan does not revealed any open ports excepted the exceptions I added manually to the FW or set up as forwarded to a PC inside the LAN (VNC for my workstation for example or PPPtP on the server). But since the board have quite a good reputation, at least in Austria, I wanted to consult my setup for its security some ware else, and this board looked just right.
So what is your expert opinion on my setup is it secure? Are there any problems that may bring trouble?
Kind regards
Owen Burnett
Firewall reports Attck on UDP port 1434
Hi,
I am new to this forum
and I have a new firewall: Kaspersky Internet security 7.0.1.325
It reports every hour an attack the only diff is that the ip address changes
Intrusion.Win.MSSQL.worm.Helkern 202.99.11.99 UDP 1434
So by googleling "UDP port 1434" I found your forum and registered.
From what I have been able to understand this port is normally used for SQL server. And Some hackers try to penatrate the vulnarabilities of SQL-Server.
What I want to know is by using my firewall to block UDP port 1434 in and out is this a good or bad idea?
By the way I did not install Microsoft SQL Server 2005 yet. I plan to.
By blocking the port I at least have stopped the alerts from my firewall.
But do know how important that port is.
Can someone explain.
thanks in advance
bye, Guy
How do I block an IP address from accessing my web site?
How do I block an IP address to prevent a specific individual from accessing my web site?
Jm
Proxomitron + the Anonymous test
Hello,
I have tried everything with Proxomitron, check all boxes and such, to try and keep the anonymous tester from finding out where I live etc, but it never ever works! The best setting until now is the default.cfg, which was able to hide my UserAgent. That’s it.
The point is that I’d like pretty much everything to be hidden (except for my IP-adress, because I’m not too fond of proxies). I have installed Grypen’s filter, and cleared the cache before retrying it, but to no avail. That’s why I ask here: what must I do?
Thanks in advance,
Qopzeep
Ps: here are my specs
Browser: Mozilla Firefox 2.0.0.12
Proxo Version: Naoko 4,5
From Wireless to Cable, out of the Pan into the Fire!…
I just felt that the wireless arraignment i had with my neighbor was too public, open, and vulnerable, so i got in on a Comcast special and now i find out that cable modems allow all ports except port 25 to be open, i guess port 25 is a ‘honeypot’ or something, whereas DSL modems make one configure all or most open ports… Now what kind of firewall/security issues do i face? WinXP sp2 etc.
I left wireless simply because i felt so exposed to wireless pirating, even with WEP or WPA or MAC filtering…
IPSec & P2P…
I run alot of P2P, Azureus, eMule, aMule, ShareAza, etc., and i was wondeing what modifications i would want o make to the IPSec i downloaded and assigned. Please advise noob.
Hardware firewall, software, or both?
Hi people!
I don’t know much about internet security, so I have some questions…
I have Cisco LynkSys wrt54gl router with internal hardware firewall – does this kind of firewall make my system secure from hackers attacks and does it secure my privacy or should I add some software to protect myself better?
It looks like it stealths all the ports, but is it enoth to feel protected?
It doesn’t control program activities, does it meen I am not protected from hackers intrusions?
What would you guys use to protect yourself if you would have Cisco LynkSys wrt54gl router firewall?
Sophisticated Attacks on Community Financial Institutions Increasing!
In today’s high tech world, maintaining the privacy and protection of customers and employees’ information grows more and more difficult particularly for many financial institutions. These days’ scammers are getting bolder and more brazen in their abilities to get personal information from banking customers as they aggressively target the smaller locally owned community financial institutions.
In fact, a recent customer reported a complex, malicious, and targeted attack took place on their institution’s customers and employees. A well-recognized phishing activity trends website reported that financial institutions saw a continuing rise in phishing activities with 92.5% of attacks targeted on financial institutions.
On average, a phishing site stays online for 3.8 days. The relevance to the number of days online is that the longer it remains online, the more possibilities for the scammer to gather personal information. It is imperative that we are prepared for this type of incident and the response that is needed.
Phishing and Pharming Attacks
There was a time when only the larger financial institutions such as Wells Fargo bank were targeted for phishing and pharming scams, but that’s no longer the case. The increase in phishing attacks on community financial institutions stems from the fact that smaller financial institutions are simply more profitable and are usually less protected from fraudulent activities.
As mentioned above, one of our local community financial institutions was hit with a complex and sophisticated vishing/pharming/phishing telephone scam that focused on customers as well as on the bank’s employees. Fortunately, we have been preparing our client for years for these types of attacks, and therefore they were on the alert, so the attack caused minimum disruption.
Sharp customers and employees recognized that the e-mail messages were a scam because of poor grammar and content in addition to the salutation being addressed to “member” or some other non-descript person. A genuine message from a financial institution always addresses the customer by their full name. Furthermore, the scams did not provide a means for contacting the institution if there were any questions, but instead told the customers and employees in the e-mail message not to reply. No legitimate institution would ever tell you not to reply.
But even with preparation and after years of working in the Internet security arena, we were surprised at the combination of attack vectors used.
Combination of Attack Vectors
The scammers’ used a variety of strategies starting with a mass email and pharming scam as an attempt to steal personal information using a Do-IT-Yourself Phishing kit. The initial attack was then followed up with telephone calls to certain area codes with spoofed numbers and using a technique called Vishing. Besides, using pharming, phishing, and vishing tactics aimed at stealing valuable information such as credit cards, social security numbers, IDs and passwords, the attackers didn’t stop there.
The scammers also included Spear Phishing, an email spoofing fraud that targets financial institution employees in an attempt to gain unauthorized access to confidential data. Because of the banks watchful eye, they caught it in time, but these types of attacks are getting bolder and more commonplace and require a great deal more vigilance in keeping personal information away from scammers.
Why Customers Are Fooled
Approximately 19% of recipients respond to Spear-Phishing, which today is one of the most menacing threats to Internet users. Unfortunately, users do not clearly understand the importance of checking for authenticity, which should include specific indications that the site they are being sent to is secure.
As a busy society, we are so focused on getting the job done quickly and efficiently, we often don’t check for important clues, which is why many users receiving messages or paying bills online don’t watch out for the clues that indicate whether an e-mail message or site is fraudulent.
An Incident Response Plan
As these scams are on the rise in financial institutions, if a financial institution is prepared, and in today’s world, they have to be, the consequences will be minimal. In the event of phishing and pharming scams, staff members in a financial institution should know how to deal with this type of situation effectively.
To ensure the customer’s safety and privacy, an incident response plan should be in place and is required by examiners to be in place. Included in the plan should be an organized approach as to how the problem is going to be handled as well as having a clearly laid out plan to address the situation.
The following should be considered in regard to an Incident Response Plan:
* Start by assessing the situation so that you know exactly what your bank is dealing with; if an incident has occurred, it’s usually up to the CEO and CIO to handle the overall incident response along with members of a CSIRT.
* Fight the attacker
o Educating the end user
o Redirecting pharming clicks to an education page (most attacks are pulling images from your site)
o Attempt to shut down the phishing site yourself
o If needed have a competent vendor to respond to the situation for counter attack; this helps identify who will take down the website as well as which agencies to contact.
o Exploit the phising website
o Communicate with customers
+ Post Bulletins on Website to ensure customers are aware of the situation
+ Have employees assure customers that security controls are in place for the institution.
o Contact authorities such as Secret Service, FBI; in addition, contact Financial Service Vendors for support on abnormal activity on customer accounts.
o Feed bogus information to the pharmed sites.
o Review abnormal activities on Customer Accounts and bogus accounts
o Implement 3rd party monitoring companies
This is not intended to be a complete incident response plan, but trigger the thought process on items to be covered.
Preventative Actions
At one time or another your institution will be affected by a fraud scam, therefore being prepared with a good response plan for employees as well as providing customer education, in addition to having the resources (either in-house or outsourced) to handle the problem efficiently and effectively are the most effective preventive actions.
Prevention of course is primary insofar as keeping phishing and pharming scams at bay, and therefore as a preventive measure, customers who use online banking in any financial institution should be warned to use caution when opening any type of email with links that appear to come from their financial institution. Even if the message looks legitimate, prudence is always best. Educate customers to be proactive rather than reactive.
Alert customers not to click any links that come in emails, especially if they appear somewhat suspicious. In addition, if the customer has any doubt about the e-mail message, alert the customer to call their financial institution directly to determine whether it could potentially be a phishing or pharming scam.
Provide customers with Security Awareness Training by developing a web page about information disclosure in addition to providing a closely monitored email address for this activity should be set up by your institution where customers can send suspicious activities.
About the Author
Mr. Gale Yocom is a recognized technology expert and President of the Dallas-based security specialist company Covetrix. For the past ten years his company has provided full service networking and security solutions to government entitities, financial institutions, and commercial businesses across the U.S. Performing security audits, penetration testing and implementation of security controls, he brings a wealth of knowledge and information to Internet security.
Mr. Yocom is known for effectively uncovering weaknesses in institution’s security practices and has impressively strengthened the security posture of many financial institutions. Mr. Yocom can be reached by contacting him at gale(at)covetrix.com or by visiting him on the web at covetrix.com
devldr32.exe
Hi,
I found your site by googling "devldr32.exe", which my copy of ZoneAlarm
Pro flagged as suspicious behavior. The information I got from your site
stated:
1) this program belongs to soundblaster drivers and ‘is required
for your soundcard to function properly" and
2) The program is also considered to be a securiy risk, possibly a virus and "delaying the removal of devldr32.exe may cause serious harm to your system…"
So which is it? Do I delete devldr32.exe or what? Any clarification of this issue will be appreciated.
Thanks!
why lie?
http://www.auditmypc.com/software_audit.asp
Why do you pretend you can see real internal IP at above link when it is just a javascript trick?
Sorry if i posted twice
test won’t work
some of your scans won’t work for me. I enter my ip as requested and press return but go back to same page with firewall test
best spyware
Hi Team,
What is the best spyware and antivirus software for a PC at Home.
Kindly guide me
Regards
satyaprasad
Wireshark
Hi Jim,
I hate to ask this question but, somewhere in the forum you gave detailed instructions on running wireshark..saving the file and then examining the packets. I’ve searched ( I think ) every thread but can’t find it. My laptop seems to be running slower than usual and I’m getting a little concerned of what’s going back and forth.
Thanks
gregg
what is the use of port scan when there is already have firewall.
what is the use of port scan when there is already have firewall.
also how does it aid system administrators.
How safe..??
How safe are we?
I work for a company & wish to view my bank details etc over the company internet but how safe is this? Can they monitor what websites i visit? Can they see passwords etc? How does a company narrow down who is looking at what?
Thanks
Dan
Proxy servers?
I’m in the beginning stages of considering a proxy server in order to be as net anonymous as possible…the Auditmypc tests opened my eyes to this personal info leak.
Can someone recommend (especially free) proxy servers?
WMI Issue !
Hi Karthik !
Any body having any idea what the WMI protocol uses port number for the SSO in Sonicwall SSO agent software and computer !
I think its TCP 135 ! what about others opinion !
Do update ! Its important !
Grrr!
I keep trying to do the Anonymous Surfer test and get the error message:
Instruction at 0x7c901010 referrenced memory at 0x0000001c. Memory could not be "read". Click ok to teminate the program.
When I click ok it closes my browser completely. I have been having loads of issues with my pc for a while now and have a feeling something fishy is going on since my mouse likes to travel to places where I haven’t put it.
Any advice would be greatly appreciated! I am running Trend-Micro’s PC-cillin and Windows XP firewall with medium security.
cmd.exe
hello guys,
Is it possible for a certain malware to target only cmd.exe and not the entire system? I mean the task manager, folder options, etc. I’m asking you this because my cmd.exe won’t opened! Every time I type in the run box it keeps telling me that "windows cannot find cmd.exe". Any ideas?
regards,
myzani
is my system hacked?
I’ve just done an anonimity test from this website and the results are not good enough. The host name is unrevealed but my personal IP address is revealed (Bad proxy? Bad system configuration? …?)
I’m using win xp sp2, opera 9.25 and zone alarm pro 4.5.594 when doing the test [and up till now
]
After that test, I installed and ran cain & abel to explore my own system and when I try it’s LSA dump on my local system I found two suspicious entries:
L$HYDRAENCKEY…
L$RTMTIMEBOMB…
(complete record is in attached file)
Are they normal entries or not? Is my system hacked?
Help me cleanup Generic5.HHY trojan and Atlas DMT spyware
Hi everyone,
I need help with my LAN. I have a Microsoft SBS box and HP laptops running Windows XP. I’ve set a wireless LAN with a wireless broadband internet connection. The connection uses a static IP, which after testing with your awesome Internet Security Test, showed that it connects through a proxy. Most of my machines have picked up malware from the network. It has been very difficult to remove.
I uninstalled Norton because it is not able to pick up anything (although it did find Trojan.startPage.1505 and RIZON-A worm a week ago). It did seem, though, that whatever malware that’s there, uses some of norton’s processes and services for its attacks.
When I try to clean the one laptop it becomes even more sluggish and the trojan launches an internet DOS, such that I cannot stay online for long before it shuts me down. I’m afraid that it has spread itself across the network.
I have since installed AVG and it picked up the Generic5.HHY from the one laptop. Doing an Activescan with Panda I found the Atlas DMT spyware on the server. I have run Spybot and Combofix to try and remove the malware, but I’m not winning.
Can somebody, please, help?
Heita Da!
help me please
i thought i was computer savvy but i have been hacked i don’t know how far back it goes, i had avg, comodo firewalll, avg anti spyware and spybot, i thought i was well protected i had a dlink router and before a 2wire. i first noticed i got hacked when i had no dsl download speed. i work on peoples computers from time to time i thought i was pretty knowledgeable. i did use dictionary passwords, and my routers unfortunatly were set at default i thought if i can barely get a signal there was no chance of anyone else getting in. i wasn’t worried about people stealing my credit mine is so bad i don’t even want it. I checked and all my pcs were hacked, and filled with rootkits and remote admin software. i dont know if me transfering files with usb drive will infect pcs or could they have been done just hooking up to internet. i assume that these rootkits had been on for some time even years on some. I AM STUPID I KNOW!!!
Unblocking my IP
Hello,
I’m a newbie. My question is this: I think my Ip address has been blocked from visiting a public website [ www.royal-orleans.com ], and I wondered if there was a way to unblock it? Every time I type in the address I am redirected to this site: This is the screen I am getting when I type in the url: http://img50.imageshack.us/img50/3554/fedoranu8.jpg
I am also getting this: Just tried it again and this is what I got: http://img403.imageshack.us/img403/5623/forbiddenmk7.jpg
I CAN access the website via other computers so that is why I think it is blocking my IP on the computer I’m using now.
Cheers
Blockbuster
logging.exe question
Hello,
I’ve recently started getting popups from certain sites such as adutfriendfinder, popuptraffic, and ad2.adecn.com.
And I keep getting this ‘object’ (not sure if it’s a window – cannot enlarge it) called NULL. I’ve also noticed several instances of LOGGING.EXE when I check in Task Manager. I have a suspicion that NULL is connected to LOGGING.EXE.
Any advice on how to stop this appreciated.
Turbo
Windows XP Srvice Pack 2
Comparing IE7′s and Google’s popup blockers
I had been using Google’s popup blocker but wasn’t totally happy with it. Too many ads were coming through. So ran your diagnostics and Google failed two of the basic tests, the Modeless Dialog and the forth of the four user launched ad blocking tests.
So shut it off and turned on Internet Explorer (7) popup blocker, set it to medium setting and it based all basic tests and all advanced tests.
Just for fun, I reset Internet Explorer to the high settings and it did not do as well as it did at the medium setting. It appears to be too over-aggressive and won’t allow your user launched windows to appear.
Based on your tests, it looks like IE7′s medium setting is the best. Might try some other tests to see if these results hold up.
Tor – The Onion Router – Will this provide Anonymity?
Jim, if you haven’t already seen this on the free download sites, you might want to take a look:
http://www.torproject.org/overview.html.en
Would this help us be more anonymous without the overhead of Proxo?
-Steve
Routers, Static IP address, and Port Forwarding
Thought I might share this with others struggling with these issues.
I do music and video downloads through Azureus, and was always perplexed at how slow it was. Apparently I was having NAT problems. I just did not have a healthy connection, apparently due to my router. Azureus recommended setting up a static IP address and then do port forwarding. They have at least 30 pages on how to optimize everything, and admit that NAT problems can be difficult with all the router and software firewall combinations out there. I had spent countless hours over a 2 week period trying to sort out their instructions and got nowhere.
Then I came across a site called Port Forwarding offering free help for setting up your router and Firewall. In about 30 minutes I had my static IP address and port forwarding working. Now I am uploading and downloading five to ten times faster than before. Check it out if you are having problems in this area:
http://portforward.com
You give them your router model and operating system, and the program or game you are trying to get set up, and they come back with very specific instructions . They have it worked out for 100′s of router manufacturer’s and specific model numbers, and for all the usual operating systems and programs. (And if you have a router not on their list, you can submit a request and they will work with you to get it set up, then they add it to their list of supported routers.)
Just wish I had found this site earlier. It would have saved me a ton of time.
-Steve
2 Free Antimalware Programs Recommended By Microsoft
Antivirus: superantivirus.notlong.com, antispyware: http://superantispyware.com/
Others
Avast and AVG
Email viruses
Some Email viruses are destroying my PC when i opened it…so please could anybody clarify my doubt how to prevent my Pc from those Email viruses?????
Bank and Cell Statements hacked
Greetings all,
I have reason to believe someone is gaining access to my phone and bank statements online. I have scanned my computer for viruses and spyware and found nothing, I also did a clean reinstall of the system software just in case. I’ve been reading a lot about "cookies" and found that a person can bypass any passwords by having the right ones. I did have an open wireless network in my home in the past and think that the cookies could have been stolen at that time. Can having the right cookies really help a person gain access to a site as secure as a bank’s?
If not a proxy server – then what, please?
I read about setting up a proxy server for myself, but I don’t know how to go about it.
I just want my ID to be a little less open to scrutiny on the web than it is now. I read here that it’s not actually necessary to have a proxt server to get greater privacy.
Free Vulnerability Scan – Trial
I’m interested in receiving any information about free vulnerability scans. If you have any information at all, please send it to my email address at: paul@relevantsitecontent.com
I’m impressed with the free scans offered at AuditMyPC.com, but am interested in programs that I can use on my personal PC to test my server. A program that sits and runs on my computer would be ideal!
Thank you,
Paul Glen
Zone Alarm Force Field!
I just installed a new Zone Alarm force field application and am having problem after problem with it. Once installed, it seems to mix with my other applications and things get all mucked up. I tried to uninstall their application, but it just made things worse for me.
Is there a good free firewall that really works, without any catch? If so, please let me know! Will Proxo do the same thing.
Good luck to you!
~Lauren
Security questions and concerns. Help! I am confused.
Hello everyone:
Let me start by saying I am not much of a computer nerd. But recently my computer got all bogged down, running slowly and often freezing up. I was using a non-genuine Windows XP Professional (with SP2) that I had upgraded to from the genuine XP Home edition that originally came with my computer when I purchased it two years ago. (Mark that down under really dumb things to do.) Anyway I suspected my problems were related to this, as well as to the fact that I had multiple popup blockers running, both hardware and software firewalls, and multiple spyware programs running. (another one to mark under dumb things). I took the bold move to wipe it all out and start fresh with the original and XP Home edition. (Microsoft won’t let you downgrade from XP Pro to XP Home).
This got me started into trying to get a handle on all this security stuff (popup blockers, firewalls, anti-virus, anti-spyware). I have brought it down to just a hardware firewall (my Belkin router), one stand alone virus program (Alvira AntiVir free version), and one stand alone spyware program (Windows Defender, also a freebie). My browser is Internet Explorer 7 (IE7) which seems very rich in security software with lots of flexibility (perhaps too much for people like me.) Anyway with IE7, I use the "medium" settings for both security and privacy. I was using IE7′s popup blocker, but have recently (as in just today) switched over to the free Google Toolbar popup blocker after disabling IE7′s popup blocker.
Anyway all these changes led me to the AuditMyPC site where I started testing all this. My questions are this:
1. Is anything gained by adding a software firewall to my hardware firewall (the router has network address translation? Or would I just be creating some redundancy and potential conflicts that could slowdown or jam up the system?
2. If I started using Proxomitron routinely what should I do with all the security stuff I already have in place? Specifically Windows defender and IE7 security and privacy settings. I have tried it out and I sure like that it hides my internal IP info. But when I have it enabled it seems to slow the system down and prevent me from visiting some sites. I configured it at Level 3 for the web filters. Is this too agressive?
3. Also I am able to launch video’s on all the news sites except Foxnews. It happens with or without using Proxomitron. Does anybody have any experience with this? I suspect it has something to do with the popup blockers since I have plenty of the latest media software loaded. And no jokes about being a conservative, I balance it with routine visits to the New York Times news site. The contrast in reporting spin is truely amazing!
Hope I am not abusing the forum with so many questions. Thanks for your consideration of these questions. Captain Cookie over and out.
Port info?
Hey, this is my first thread on this forum, i have done a lot of my own research but am still at a loss for some information. for example, i do my best to keep track of who is accessing my home network and what is going on with it but for the life of me i cant figure out some of the established connections. if i see an established connection to an IP adress on a port im unfamiliar with, i try to look it up but am usually unsuccessful. like port 2999 all the info i can get is its some remoteware…im not sure how to tell which connections are good and which ones, if there are any that are harmful or shouldnt be there. is there a list or a website that anyone knows of where i can easily look up information on ports and ip adresses that i have established connections to? any help on this matter would be greatly appreciated.
Questions about some incoming connections
Hi,
I was looking at the logs for my router, the incoming connections especially. I found 3 that were wierd, I couldn’t find any port info about them.
(I censored the IPs just incase im violating a rule or something)
Source IP Destination Port Number
198.53.xxx.xxx 1074
24.66.xxx.xxx 3130
70.74.xxx.xxx 2533
the first IP is registered to Telus. and the other 2 are from my ISP, Shaw.
I don’t know what any of these ports mean! Theres no clear info about them!
SPA.exe and Norton Internet Security
Norton Internet Security 2007 has a live update feature that crashes when you try to run an update. The error message refers to SPA.exe as responsible for the crash. If you Google SPA.exe there are several posts about it as being spyware. I purchased and ran Stopzilla, which did not identify SPA.exe. How do I get rid of this spyware?
Sniffer Detection?
Greetings Everyone,
Is there such a thing as sniffer detection software? And if so what would be a good choice for a MAC running OS X? I would like to monitor my home computer for sniffing activity. And since my computer is already running in "stealth mode" as well as denying "UDP" traffic would I just be wasting my money?
Thanks!
Import your IPsec policy / Question
Hello
To begin with:
Thank you for your outstanding site, it really provides a wealth of useful information.
I have tried to import your IPsec policy, (http://www.auditmypc.com/ipsec-policy.asp) but my problem is that the local security icon does not exist on my XP :
administrative tools (start, settings, control panel), –>local security policy<–
Do you know how I can add this item to Windows (XP Home SP2)?
Kind regards
Brandon
Static IP Versus Dynamic
Would a Dynamic IP address be safer than a static? The reason being that a Dynamic IP is different everytime thereby making it difficult for hackers to target you? My ISP offers a "security" upgrade for $5 more a month, I’m assuming that this is a Dynamic IP address offering?
How to link webcam THRU private IP address?
My ISP ( a satellite provider ) has his "home" customers under a private IP address and natted to the edge router.
The ISP antenna on my house is connected to my Linksys wireless router ( with rangebooster) that then goes to the computer.
I have a security system with cameras and viewing software ( Q-see) that I want to be able to monitor remotely thru the internet..the security DVR is also connected to the computer.
I have tried, with the help of the Q-See tech support people as well as the Linksys people to do the port forwarding required to be able to view remotely but it will not work. My ISP says that because I am behind the private IP address that it’s not possible to view the cameras on the internet. He suggested that I get them linked to a private website ie that I PUSH OUT the images as opposed to trying to COME IN to view them. Thats all the help he’ll give me.
This is a problem since in order to view the cameras the viewing computer needs to have the viewing software installed on it and I don’t know if you can embed this software on a website.
Is there a way to get around the private IP to view my cameras? Is there a way to get my private IP address and port forward it?
I am just a civilian and not a techie so ANY help is appreciated.
Thanks
other intranet PC can’t ping to my. ?why?
I can ping all the machines in the intranet (type A, 255.255.255.0)
but from the other machines nobody can ping to my IP.
This causes for example problems in the CA Antivirus not being capable of list my pc as the others pc in the intranet.
There are some way to force my machine (Win XP Pro sp2) to not responding to ping’s?
How can change this behaviour to the "normal" one?
Even turning off the MS Firewall.
Thanks in advance.
Guerrero.
OpenDNS
http://www.opendns.com/
Would you recommend this service?
Catch a hacker
Hello all,
My name is Roman and I am from Southern California. I am an Art Director for a local magazine and I’m interested in keeping my servers (at work) and my personal computers safe from intusion. Here is my dillema:
For the past couple of months, maybe longer, I’ve had an individual gaining access to my personal email, chat, and even bank and phone accounts even though I religiously change passwords. I thought it was my wireless network at home but i since disconnected it, it did not work. I use a wireless network at work which I’m told is secure but when I change passwords or create new email identities using home or work computers he can still gain access. I’m at a loss. Here at the things i’ve done so far:
1. Changed passwords frequently
2. Downloaded anti-spyware detection software (computers come up clean)
3. Put passwords on my laptop and PC at home and at work (no one else has access to my personal/work computers except me)
4. Checked for keyloggers on keyboards
He’s cocky, and says he does what he does for a living and even harrasses my email contacts with nasty letters posing as me. It does not seem to matter where i’m at or what system im using (wireless or hardwired), my own or my work, he still succeeds in getting the info he wants. Is there anything else I need to watch for or do? Is there spyware that is completely invisible?
The one thing I have saved from him is the many yahoo identities he’s created to harrass my family. Can these be traced? I sent a complaint letter to yahoo about 3 days ago but I feel there is little they can do.
Any advice would be greatly appreciated.
Roman
Secure USB Flash Drive
Hey Guys, I just found an awesome USB Flash Drive called Ironkey. What’s cool about it is that it has a ton af cool security features. Has anyone used one of these before?
Spyware
I have Norton360 but even though they claim to protect me from spyware, I still find loads picked up by AVG-Antispyware, Spybot and Ad-aware – I run scans in that order. I’m paranoid that I’ve still got something in my PC.
I’ve tried Wireshark but it’s a bit geeky for an oldie like me. I can’t figure out how to even get started. When I do Start-All programs -Wireshark, I get this window with nothing on it. I’ve tried looking at the faqs, community support (forget it, those archives are not for idiots like me) and I just plain don’t understand this facility. Even if I can get it to show some information, I don’t expect I’d know what to do with it.
Basically, are there any more scans I can run to rid me of any residual spyware lurking in my PC? There are all sorts of scans being offered on the web but I do not know how to tell which ones are kosher.
I can’t understand why Symantec does not protect me from all this spyware that I am picking up.
ecard.exe
I received an email a couple days ago from a site stating that I had a greeting card from a " Class-Mate." My daughter, who handles some of my day to day business, downloaded the executable and left it in the download folder. Fortunately, she didn’t run the exe left it for me.
I ran a Google search and it seems the ecard.exe is some sort of a worm. The question is; by deleting the executable file am I safe? I ran Symantec AV and came up with zero threats. Life was much simpler with rotary phones and pagers.
Thanks for your help.
Regards
gl
port 8080
Is there another way to get past the block Wild blue has put on port 8080. I enjoy going to a website chatroom that is on port 8080. HELP!!
Immuneport – port 2627
It is unfortunate that IANA do not preserve the original request I made when requesting 2627 port registration.
But since the application of port 2627 was not yet developed I started to define the port set of rules by my self in order to make it open for the whole community.
I will provide more information in the future as well as implementations.
Briefly port 2627 is intended to become an ‘immune port’ or a channel for information about network vulnerabilities, and attacking pieces of information detected over the network.
The port was first registered by me, Moshe Beeri, at 1998.
I am doing my best to promote extensive use of global network immunity system in the open source way.
I state that:
It is all about pieces of information:
As we all agree, information that travel over the network was generated by individuals that use computers, this is where the most harmful pieces of software (viruses, worms, spy ware, spam ware, Trojans, etc.) are coming from.
Most pieces of information are none attacking nor have any kind of vulnerability potential, although it may be inappropriate to some, but the small fraction of information may harm your organization, some security systems may detect them, wile others may block them.
We in immune port believe that a global system that keeps track of the pieces of information generated travel and arrived to a location should prevent the vulnerability of the whole WWW commuter’s network.
We are also believed that most of the security systems will provide online vulnerabilities information while others will do the blocking itself.
There will always be attacks and there will always be some attacker, but most of the population would like to collaborate and join forces against it.
Declare – Trustful information you are publishing.
Detect – You probably will subscribe to some detecting mechanism.
Inform – Others that you found vulnerability.
Prevent – You system has been warned just monitor incoming data.
Visible IP
I’ve ran the port scan tool several times, and as usual, a natted IP comes up with a message stating this info shouldn’t be visible. The Anon.Surf check came back with the same info. So, I guess the question would be; are there settings available to mask the real IP or could this be standard occurrence with AT&T dsl users?
Regards,
gregg
wmiexe
Hi all, recently I have had intrusion into my comp and my firewall password keeps being changed without my knowledge, attempts have been made to stop me clearing the changed password by using the original firewall disk which I hve been able to overcome by hitting the restart button and letting the comp check the disc on restart.
However after clearing all the temp files stored on the comp and shutting down, on the next restart of the comp I got an error msg that wmiexe had failed and was shutdown, there seems to have been no adverse effect to my comp so far by this, wmiexe.exe was found in c:windowssystem at a size of 16,858bytes and has now been deleted…any info or knowledge of how to spot if someone is actually getting into my comp at the time I am using the net would be gratefully appreciated.
NetBIOS ports issue
I have too many open ports, and want to disable 137, 138, 139. On my other drive I used WWDC to close the ports with no problem. However, after installing on this drive, when I close those three ports I cannot connect to the internet.
I run XP Pro SP2, with BellSouth FastAccess DSL, Westell 6100 modem, ethernet. I do NOT connect with any other computers in/out of network, so there is no filesharing. I do not use any auto updates, except for security programs.
Run Avast 4.7 Pro, Comodo Firewall, Spyware Doctor – but nothing has changed. I am sure it probably has something to do with the way I installed XP, because there were no port closing issues before.
How to stop apps like wget from downloading our database
My site is hosted on a Windows 2000 server. The site is almost all aspx pages with 2 databases. How can I stop others from downloading my database? Is there built-in magic at the server? Any suggestions or detailed information about this subject would be greatly appreciated…
Benton
information on port 3470 UDP
hi,
I was looking at the firewall connections details, and I saw iexplore.exe (Internet Explorer 7) running on port 3470 UDP connected on loopback, but Internet Explorer was not running on the Desktop… just in the back !
I post it relatively to this page : http://www.auditmypc.com/port/udp-port-3470.asp
If anybody knows why this binary runs like this …. pleese tell us !!
Thanks,
FatBass
Ip Address
I’ve visited this site twice. Each time I’ve had two different ip addresses located in two different cities located 30-40 miles from where I live. What does this mean?
ipsec
Jim,
I downloaded and activated the ipsec policy you have online and have a question to ask. I would like to know how to edit the policy. When I enable the policy on my sony vaio laptop running vista ultimate I am no longer able to print to my hp printer that is on a wireless print server with an assigned ip address. As soon as I disable the policy I can print to the printer. I figure there’s a setting or settings somewhere in there that will enable me to use the policy and print to my printer. Thanks for any help you can give me.
Wild-One
connecting to china
my computer tries to connect to an address in china. i’ve tried mcafee, , xoftspy and a number of other progs to find the problem, but no success. any suggestions?
Changing Remote Desktop Port
If I change the port used by windows for remote access will my computer be safer and how to do this?
IP Address
What program can I install that will hide my IP address?

Comments