republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Startup security for "always-on" connection.
Search Topic:
Uniqs:
431
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Avira AntiRootkit Tool »
« Beware these "fake" antispyware programs  
AuthorAll Replies

schwendrick

join:2005-01-12

Startup security for "always-on" connection.

Hello, I need some good feedback.

I have a PC which gets turned off at the end of the day connected to an "always-on" DSL connection. I do have a NAT router... the prior one was compromised and I have no reson to really trust this one. In the past I've been TARGETED for online intrusion attempts.

I'm concerned about vulnerability for the several seconds during the boot process prior to security software being loaded. I don't know at what point the computer is accessable to the outside world vs. at what point I'm protected.

Security software loading at startup is Online Armor and Avast!

Assuming a compromised router, is the startup software loading soon enough to protect me from startup boogies? Is there more I can be doing to protect myself during these critical few seconds?

Knowledgable feedback appreciated. Thanks.

Win XP SP2

daveinpoway
Premium
join:2006-07-03
Poway, CA
Out of curiosity, what make and model router were you previously using, and what makes you think that it was compromised?

schwendrick

join:2005-01-12

reply to schwendrick
Actually I wanted to remove attention from the router as I presumed that's the first thing that would be focused on.

At what point during the boot cycle does the PC become vulnerable through the network port, and is it late enough that my security software is enough in place to prevent malware from being installed/executed?

Thanks

Mele20
Premium
join:2001-06-05
Hilo, HI

You can use BootlogXP to show you when your security software loads during the boot process. I have DiamondCS ProcessGuard and it loads extremely early in the boot process before my Antivirus loads even. It is a classic HIPS that runs in kernel mode and would not allow anything that somehow got downloaded before the AV was loaded to execute. It would block it and as soon as Windows finished loading stick a popup in the middle of my screen, where it would be impossible to miss,and demand that I tell it what to do about the new process/program that wants to start.

»www.greatis.com/utilities/bootlogxp/
--
"The same ferocity that our founders devoted to protect the freedom and independence of the press is now appropriate for our defense of the freedom of the internet. The stakes are the same: the survival of our Republic". Al Gore, The Assault on Reason

schwendrick

join:2005-01-12
Thanks Mele20. Good tips.

mikenolan7
Premium
join:2005-06-07
Torrance, CA
reply to schwendrick
Another option would be to use a shutdown script to disable your network connection, then after start-up, enable it manually when you are ready to go online.


La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage

reply to schwendrick
said by schwendrick See Profile :

Actually I wanted to remove attention from the router as I presumed that's the first thing that would be focused on....

The idea is to help others, such as those who may also be using this particular router you speak of.

It would be nice to know what router you believe was compromised, how it was compromised, and what lead you to believe you were "targeted" for online intrusion attempts.
--
10,582 DEADLY TERROR ATTACKS SINCE 9/11~~TEAM DISCOVERY
Can't feel you anymore, don't need you anymore, don't believe you anymore, I don't need you anymore

genewitch

join:2007-09-12
Klamath Falls, OR
·Charter Pipeline
·Suddenlink
·Cebridge Connections


1 edit
reply to schwendrick
said by schwendrick See Profile :

Actually I wanted to remove attention from the router as I presumed that's the first thing that would be focused on.

At what point during the boot cycle does the PC become vulnerable through the network port, and is it late enough that my security software is enough in place to prevent malware from being installed/executed?

Thanks
Network should come up last, but there's no guarantee. If you are paranoid about it, before you shut down the machine turn off the network card (nethood ->properties ->device ->disable)

Unless something fishy is going on that should stay set until your machine is completely booted, at which point you can go in and enable it at your leisure.

PS this is how my network is run, there's no internet to any computer until i explicitly boot a virtual machine for that purpose. My computer can't even lease an IP until i do that.
Forums » Up and Running » Security » SecurityAvira AntiRootkit Tool »
« Beware these "fake" antispyware programs  


Tuesday, 10-Nov 02:43:04 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [83] VoIP Over 3G Still Not Working For iPhone
· [80] Verizon Keeps Swinging At AT&T
· [33] Bill Would Force ISPs To Block Financial Scams
· [21] Mediacom Hints At 50, 100 Mbps Speeds
· [14] Clearwire To Get Another $1.5 Billion
· [11] Monday Morning Links
· [9] 15 States Have Now Gotten Broadband Mapping Money
· [5] AT&T Launching New 7.2 Mbps 3G Modem
Most people now reading
· Know when to run! [Home Repair & Improvement]
· 60 Minutes piece on cyber security last night [Security]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Framed for child porn 151; by a PC virus [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· MI424WR-GEN2 Rev E Configuration Thread [Verizon Fiber Optics]
· How in the world am I going to get into college? [General Questions]
· Google Has Acquired Gizmo5 [VOIP Tech Chat]
· [SU] Apple Releases Mac OS X 10.6.2 [All Things Macintosh]