Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 12, 2008, 12:57:45 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
199661
Posts
22922
Topics
55005
Members
Latest Member:
AlleyM
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Computer Firewalls
Really at a lost as to what to do
« previous
next »
Pages:
[
1
]
2
Author
Topic: Really at a lost as to what to do (Read 3618 times)
Rickie
Newbie
Offline
Posts: 5
Really at a lost as to what to do
«
on:
January 05, 2007, 11:50:09 PM »
So I would appreciate as much help as possible here, and keep it simple please.
basically, I am being "attacked" over the internet, someone causes my internet to slow down to the point where it does not load webpages, however SOME applications (e.g. MSN messenger) do not disconnect all the time, sometimes they do, sometimes not.
Im in the UK and use NTL (Cable) and have a 2 Mb connection, I am on a network using a wireless router.
If you need any other information please ask, How can I stop this person?
Thanks, Rich.
Logged
pandlouk
I love Comodo
Comodo's Hero
Offline
Posts: 2240
Panagiotis
Re: Really at a lost as to what to do
«
Reply #1 on:
January 06, 2007, 01:23:29 AM »
welcome to the forums
From your description seems that other(s) are using your internet connection.
Check this simple guide
http://forums.comodo.com/index.php/topic,361.0.html
for protecting your wifi network
Logged
Rickie
Newbie
Offline
Posts: 5
Re: Really at a lost as to what to do
«
Reply #2 on:
January 06, 2007, 09:39:11 AM »
Thanks for the help, however I dont think its that, Basically this person lives in sweden and has a severe grudge against me and can mess up my internet connection, I know its him because he likes to gloat.
Logged
Rotty
Global Moderator
Comodo's Hero
Offline
Posts: 793
http://www.venganza.org/ - Noodly Appendage
Re: Really at a lost as to what to do
«
Reply #3 on:
January 06, 2007, 09:41:22 PM »
What firewalls do you have between you and the internet? Have you looked at the logs to see if their is ALLOT of traffic from one IP or a few IP's?
«
Last Edit: January 06, 2007, 09:45:31 PM by Rotty
»
Logged
The opinions expressed in my posts are my own.
They do NOT necessarily represent or reflect the views of my employer.
Rickie
Newbie
Offline
Posts: 5
Re: Really at a lost as to what to do
«
Reply #4 on:
January 08, 2007, 02:46:39 AM »
Thats kinda the problem, I dont think I have one, I have comodo on THIS pc, but thats not much help I dont think as my Network is effected.
so, What network firewalls can I get?
Thanks for your time,
rich.
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 5477
... and I say to myself, "What a wonderful world"
Re: Really at a lost as to what to do
«
Reply #5 on:
January 08, 2007, 03:37:42 AM »
Quote from: Rickie on January 06, 2007, 09:39:11 AM
Thanks for the help, however I dont think its that, Basically this person lives in sweden and has a severe grudge against me and can mess up my internet connection, I know its him because he likes to gloat.
Can you please post your logs here so we can work out exactly what is happening and how to stop. To save your logs, open CPF and click on ACTIVITY - LOGS. Do a rightclick somewhere inside the logs window and select "Export HTML". This will save the log as a HTML file. ZIP this HTML file up and post it back here as an attachment.
Cheers,
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Triplejolt
Global Moderator
Comodo's Hero
Offline
Posts: 343
If you are going through hell, keep going!
Re: Really at a lost as to what to do
«
Reply #6 on:
January 08, 2007, 04:29:50 AM »
Most likely this "Swede" is hammering your router/modem and not your computer directly. And if "he" is infact flooding your network, report the person to your ISP. Tell them you want to report an abuse and let them deal with it. Even though a local firewall will help prevent most attacks, flooding your network can still be achieved. Your ISP, if a serious company, will log and trace the abusers IP (even report the IP used to his own ISP). Your ISP can and will block the abusers IP until the "attack" stops. And if you're a bit lucky, the abuser will have to explain his activities to his own ISP.
Please remember to e-mail your friend telling:
"what comes around, goes around"
Just out of curiosity, how did he get a hold of you IP(s)?
Logged
Cheers
Triplejolt
"Human salvation lies in the hands of the creatively maladjusted."
panic
Global Moderator
Comodo's Hero
Offline
Posts: 5477
... and I say to myself, "What a wonderful world"
Re: Really at a lost as to what to do
«
Reply #7 on:
January 08, 2007, 04:47:24 AM »
Another thing you cold try would be to outline your problems to your ISP and ask if they can allocate another IP address to you. I have seen this done by several Australian ISPs in cases similar to this.
If the ISP won't do anything, your next recourse wouls be to an industry or Government body. In Australia, We could use the IIAA (Internet Industry Association of Australia) of the Communications Ombudsman. You should have similar bodies in the UK.
Cheers,
Ewen :-)
«
Last Edit: January 08, 2007, 05:50:35 AM by panic
»
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Rickie
Newbie
Offline
Posts: 5
Re: Really at a lost as to what to do
«
Reply #8 on:
January 08, 2007, 05:29:56 AM »
Quote from: Triplejolt on January 08, 2007, 04:29:50 AM
Just out of curiosity, how did he get a hold of you IP(s)?
mIRC I think.
Im pretty sure triplejolt is right on what has happened, and today I have called NTL and they were, in a word, useless.
my firewall log is attached as well if that helps.
so there is nothing I can do myself to find his ip and block that connection?
«
Last Edit: January 08, 2007, 05:33:53 AM by Rickie
»
Logged
Triplejolt
Global Moderator
Comodo's Hero
Offline
Posts: 343
If you are going through hell, keep going!
Re: Really at a lost as to what to do
«
Reply #9 on:
January 08, 2007, 09:29:19 AM »
Well.... there are some steps you can do.
You should go over the logs and start making
Block and Log
rules containing the IP's that appears most frequently. That should protect you from any direct attack from those IP's.
Judging from the log you sent, the
IP 65.208.83.114
appears unusually frequent. You could perhaps start with these two:
Block and Log IP in from IP 65.208.83.114 to IP [your hostname] where iproto is any
Block and Log IP out from IP [your hostname] to IP 65.208.83.114 where iproto is any
Remember to place these two line above the current Block and Log rule to be of any use.
NTL is obligated to help fix the problem, as long as the error is not on your computer. Ask them to trace your cabel/DSL, checking for parity/bit errors and that you are infact getting the speed-specification you are paying for. They should also investigate your complaint vigorously, if they don't want to open themselves up for a lawsuit. All ISP's are as far as I know, obligated by law to investigate and attempt to prevent Internet abuse. I know the US and UK are.
If you want to capture his IP address, you could use Ethereal/Wireshark to investigate packets_on_the_wire. This requires a little bit of knowledge and some skills. An easier way would probably be to use a 3rd party application designed to pick up mIRC IP addresses. I'm sure there are several around if you google a bit
Logged
Cheers
Triplejolt
"Human salvation lies in the hands of the creatively maladjusted."
Rickie
Newbie
Offline
Posts: 5
Re: Really at a lost as to what to do
«
Reply #10 on:
January 08, 2007, 01:17:29 PM »
Well I blocked that IP and downloaded wireshark
I then looked at wireshark and my first thought was bleh?!!
its confusing to say the least, I shall read through it and try to work it out.
Thanks for the help guys, it's greatly appreciated.
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 1737
Re: Really at a lost as to what to do
«
Reply #11 on:
January 09, 2007, 02:49:44 PM »
Quote from: Rickie on January 08, 2007, 01:17:29 PM
Well I blocked that IP and downloaded wireshark
I then looked at wireshark and my first thought was bleh?!!
its confusing to say the least, I shall read through it and try to work it out.
Thanks for the help guys, it's greatly appreciated.
This issue seems to be an example of Distributed Denial of Service attack. The attacker may be trying to flood your network so that casual traffic is not allowed due to the lack of resources. He can not do this by using a simple PC though unless he has a bandwidth > 2mbit and assigns all resources to this attack. But he may be using bots.
Installing a firewall to your PC could protect PC but not the network. The network must be secured. By network, i do not necessarily mean your wireless network but the path from your router to the your ISP.
A solution is contacting your ISP and ask them to block that attacker if he is identifiable. In case of distributed DOS, this is may be very difficult. The only solution for you is to switch to a dynamic IP address instead of a static IP address.
As a footnote, WWW service providers do not have the chance to use dynamic IP addresses. So for them, there is practically no simple solution to circumvent a DOS attack.
Logged
AOwL
Comodo SuperHero
Global Moderator
Comodo's Hero
Offline
Posts: 2349
Comodo Firewall Pro - Be safe, use protection...
Re: Really at a lost as to what to do
«
Reply #12 on:
January 09, 2007, 08:40:06 PM »
So it doesn't help if your router protects you from a DOS attack?
Logged
WinXP SP2 HE - IE7 - FF 2 - TB - CFP 2.4 - NOD32 - BoClean -ST - AMD64x2 - 3Gb Ram - 1.5Tb HD
panic
Global Moderator
Comodo's Hero
Offline
Posts: 5477
... and I say to myself, "What a wonderful world"
Re: Really at a lost as to what to do
«
Reply #13 on:
January 09, 2007, 11:26:36 PM »
Quote from: AOwL™ on January 09, 2007, 08:40:06 PM
So it doesn't help if your router protects you from a DOS attack?
If your router is spending all of its time and energy blocking the incoming, attempted DDOS attack, how much time do you reckon it has left to send data outwards?
Regardless of whether CPF or the routers hardware firewall is blocking the incoming data flood, the data flood is still there. If we are relying on the routers firewall to protect us, all we've done is move the block point one step further away from our PC. Our internet connection is still being flooded.
The only thing I'd recommend is to contact the ISP and ask if they can allocate a different IP and then use an anonymizer to access the sites that your "friend" knows you from.
Cheers,
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
comicfan2000
Guest
Re: Really at a lost as to what to do
«
Reply #14 on:
January 22, 2007, 01:10:06 AM »
Darn Sweeds.
Just like A OWL attacking in the night. Next thing you know they will be moderators on Comodo.
See , us Polish people, we are safer, last time I was on the net, I got tangled in it.
I agree with Ewen though, contact the ISP. A college student did this to an instructor and the ISPs\authorities in the area will no longer allow him to have internet access, not in his name anyway. He also faced jail time but got probation. I believe it was Charter that tracked back to his pc. Either way if this is the case, I hope they get em'.
Paul
«
Last Edit: January 22, 2007, 01:19:42 AM by comicfan2000
»
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.25 seconds with 18 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com