republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Startup security for "always-on" connection.
Search Topic:
Uniqs:
447
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Avira AntiRootkit Tool »
« Beware these "fake" antispyware programs  
AuthorAll Replies

schwendrick

join:2005-01-12

Startup security for "always-on" connection.

Hello, I need some good feedback.

I have a PC which gets turned off at the end of the day connected to an "always-on" DSL connection. I do have a NAT router... the prior one was compromised and I have no reson to really trust this one. In the past I've been TARGETED for online intrusion attempts.

I'm concerned about vulnerability for the several seconds during the boot process prior to security software being loaded. I don't know at what point the computer is accessable to the outside world vs. at what point I'm protected.

Security software loading at startup is Online Armor and Avast!

Assuming a compromised router, is the startup software loading soon enough to protect me from startup boogies? Is there more I can be doing to protect myself during these critical few seconds?

Knowledgable feedback appreciated. Thanks.

Win XP SP2

daveinpoway
Premium
join:2006-07-03
Poway, CA
Out of curiosity, what make and model router were you previously using, and what makes you think that it was compromised?

schwendrick

join:2005-01-12

reply to schwendrick
Actually I wanted to remove attention from the router as I presumed that's the first thing that would be focused on.

At what point during the boot cycle does the PC become vulnerable through the network port, and is it late enough that my security software is enough in place to prevent malware from being installed/executed?

Thanks

Mele20
Premium
join:2001-06-05
Hilo, HI

You can use BootlogXP to show you when your security software loads during the boot process. I have DiamondCS ProcessGuard and it loads extremely early in the boot process before my Antivirus loads even. It is a classic HIPS that runs in kernel mode and would not allow anything that somehow got downloaded before the AV was loaded to execute. It would block it and as soon as Windows finished loading stick a popup in the middle of my screen, where it would be impossible to miss,and demand that I tell it what to do about the new process/program that wants to start.

»www.greatis.com/utilities/bootlogxp/
--
"The same ferocity that our founders devoted to protect the freedom and independence of the press is now appropriate for our defense of the freedom of the internet. The stakes are the same: the survival of our Republic". Al Gore, The Assault on Reason

schwendrick

join:2005-01-12
Thanks Mele20. Good tips.

mikenolan7
Premium
join:2005-06-07
Torrance, CA
reply to schwendrick
Another option would be to use a shutdown script to disable your network connection, then after start-up, enable it manually when you are ready to go online.


La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage

reply to schwendrick
said by schwendrick See Profile :

Actually I wanted to remove attention from the router as I presumed that's the first thing that would be focused on....

The idea is to help others, such as those who may also be using this particular router you speak of.

It would be nice to know what router you believe was compromised, how it was compromised, and what lead you to believe you were "targeted" for online intrusion attempts.
--
10,582 DEADLY TERROR ATTACKS SINCE 9/11~~TEAM DISCOVERY
Can't feel you anymore, don't need you anymore, don't believe you anymore, I don't need you anymore

genewitch

join:2007-09-12
Klamath Falls, OR
·Charter Pipeline
·Suddenlink
·Cebridge Connections


1 edit
reply to schwendrick
said by schwendrick See Profile :

Actually I wanted to remove attention from the router as I presumed that's the first thing that would be focused on.

At what point during the boot cycle does the PC become vulnerable through the network port, and is it late enough that my security software is enough in place to prevent malware from being installed/executed?

Thanks
Network should come up last, but there's no guarantee. If you are paranoid about it, before you shut down the machine turn off the network card (nethood ->properties ->device ->disable)

Unless something fishy is going on that should stay set until your machine is completely booted, at which point you can go in and enable it at your leisure.

PS this is how my network is run, there's no internet to any computer until i explicitly boot a virtual machine for that purpose. My computer can't even lease an IP until i do that.
Forums » Up and Running » Security » SecurityAvira AntiRootkit Tool »
« Beware these "fake" antispyware programs  


Thursday, 10-Dec 12:56:39 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [131] AT&T Launching New 24 Mbps U-Verse Tier
· [82] 3G Network Test Says AT&T Is Tops
· [75] AT&T Hints At Usage-Based iPhone Data Pricing
· [72] Mediacom Unveils 105 Mbps Pricing
· [67] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [66] Sprint Poised For A Turnaround?
· [51] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [45] Microwaving Your Innards Is Not 'Extreme'
Most people now reading
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· New Mediacom Email [Mediacom]
· [WIN7] Well, I was dumb, but do I have recourse? [Microsoft Help]
· Windows 7 boot manager editing questions [Microsoft Help]
· 60GB would only last us two days! [TekSavvy]
· Snow on Roof [Home Repair & Improvement]
· So what's your impressions of Lich King so far.... [World of Warcraft]
· ICC10 [World of Warcraft]
· [Bug] Extra Emblems of Frost [World of Warcraft]
· Will Gearscore die now? [World of Warcraft]