Skip to navigation

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.

// Home / Blogs

Posted on December 20th, 2008 by Steve Cassidy

On a BotNet near you…

I’d welcome other perspectives here, but it seems to me that the overall infectious environment has jumped up like crazy in the last couple of weeks. This is more or less in line with the closure of McColo Corp – as the traffic from them receded, so the trojans have taken up the slack. Looking at the variety of firewall logs I can get my hands on, it seems that there’s a massive collateral DoS effect that develops, as a relatively benign infector opens the door a crack – and the IP address that hosts it is beaten to death by traffic that’s not allowed to reach the infected host, by the firewall.

I suspect these are not necessarily new viruses, either, and that the DoS effect is unintentional. These script kiddies just want their copy of “Quantum of Solace” and don’t actually intend you any active harm: but, in a couple of cases now just over the last 10 days, I’ve been obliged to start rotating the firewall’s static external IP address to stay ahead of the inbound stuff, to give enough breathing space to work out where and what to disinfect. Most irritating, and a very good way of finding out that you need a smarter firewall or a more attentive ISP. So long as you don’t have work to do, that is!

Tags: , ,

Posted in: Real World Computing

Permalink | Trackback

Follow any responses to this entry through the RSS 2.0 feed.

Leave a Reply

Spam Protection by WP-SpamFree

* required fields

* Will not be published

SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2010