Re: ZoneAlarm Security Alert - My own ISP?



On Wed, 26 Dec 2007, in the Usenet newsgroup comp.security.firewalls, in article
<13n4t87bs9qrjfb@xxxxxxxxxxxxxxxxxx>, Marshall Price wrote:

I often get alerts like this:

-------
ZoneAlarm Security Alert
Protected
The firewall has blocked Internet access to your computer

Brave Firewall!!! Good Firewall!!! Well Done!!!

(NetBIOS Session) from dialup-4.232.33.145.Dial1.LosAngeles1.Level3.net
(4.232.33.145) (TCP Port 3436) [TCP Flags: S].

Some luser's windoze box looking to see if you want to share.

Since the city name embedded therein is often my own (Miami), and I'm a
dial-up user, I suspect these might be coming from Earthlink, my own ISP.

No, they're coming from a "Point Of Presence" provider - it could be
any number of actual ISPs. This is why when you are dialing in, you
are required to identify yourself not only by "username", but by
"username@xxxxxxxx" so they know which list of usernames to look at.

How can I determine whether they are from Earthlink

As usual, the Level 3 rwhois server isn't allowing remote access, but
in theory you might send mail to abuse@xxxxxxxxxxx You'll probably only
get an auto-response from their ignore-bot.

and whether to let them through?

Do you want to share your system with this unknown person/zombie?

What about other NetBIOS Session alerts?

See that your computer is not configured to share anything/everything
with any/everyone. Microsoft copied the idea of the UNIX command
"netstat" which shows what ports are open on your computer. I got rid
of windoze before they invented the network (or what-ever they're
claiming now), but other posters have suggested

C:\ netstat /an in a DOS window
C:\ netstat /ano for winXP

The original command on a *nix box would show

[compton ~]$ netstat -anptu
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN
[compton ~]$

Here, the box has exactly one port "open" and in fact it's actually
restricted to allow connections from only ~4300 addresses in the entire
world.

If I click on "Don't show this dialog again," will I stop seeing all
security alerts? Should I?

Sorry - I don't use windoze. Personally, I don't bother wasting CPU
cycles having the firewall tell me it blocked access to a closed port.
They didn't get in, and there is little you can do to get them to stop
trying (there really isn't an Internet Police Force, and most "abuse@"
complaints are ignored), so what else are you going to do? See that
your box isn't offering services to anyone you don't specifically want
to have access, and don't worry about it.

Old guy
.



Relevant Pages

  • Re: ZoneAlarm Security Alert - My own ISP?
    ... The firewall has blocked Internet access to your computer ... "netstat" which shows what ports are open on your computer. ...
    (comp.security.firewalls)
  • Re: avast
    ... > Just did a clean installation of xp pro sp1 and download 'avast anti ... Did you firewall before connecting to the internet? ... Internet and patch with the critical updates? ... Why you should use a computer firewall.. ...
    (microsoft.public.windowsxp.general)
  • Re: XP NOT RESPONDING
    ... Did you have a firewall going before connecting to the internet? ... Microsoft has these suggestions for Protecting your computer from the ... Why you should use a computer firewall.. ... are pay - some you can only download if you are registered - but it is best ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: Guide to secure installtion of IIS 5
    ... don't forget a well-configured firewall. ... Do not put the computer onto the network or the Internet until after the ... Follow the instructions for hardening Windows and IIS at ... Install all service packs and security fixes from Microsoft and otherwise ...
    (microsoft.public.inetserver.iis.security)
  • RE: firewall
    ... You need to do a lot of reading about ipfw ... IPFW is the only firewall available to FBSD, ... rules do not function correctly on a DSL or cable internet ... @320 pass in quick on rl0 proto tcp from 63.70.155.0/24 to any port ...
    (freebsd-questions)