- Related Stories
-
Homeland Security IT chief blamed for cyberwoes
June 20, 2007 -
Coming attractions for history's first cyberwar
June 15, 2007 -
Cyberattack in Estonia--what it really means
May 29, 2007 -
Cyberattacks at federal agencies draw House scrutiny
April 19, 2007 -
Are commie cybersnoops watching us?
May 26, 2006 - Related Blogs
-
Will the next U.S. president lead on cybersecurity?
October 30, 2007 -
Will cyberintrusions crash U.S. electrical grid?
October 17, 2007 -
U.S. cybersecurity czar: Help us help you
October 1, 2007 -
Cyberattacks at DHS prompt new finger-pointing
September 24, 2007 -
Bush, Estonian president talk cyberattacks
June 25, 2007 -
Congress to grill Homeland Security on cyberweaknesses
June 19, 2007
About 120 countries are trying to use the Net as a weapon to target financial markets, government computers, and utilities, McAfee says.
The story "World faces 'cyber cold war' threat, report says" published November 29, 2007 at 6:08 AM is no longer available on CNET News.
Content from Reuters expires after 30 days.






People like Wolf Blitzer are not allowed to make video comments in my house.
People like Wolf Blitzer are not allowed to make video comments in my house.
Take for example Lenovo. Most Lenovo's come with the driver update package turned on. It would take one update by Lenovo to install a trojan on every laptop, and desktop. Including a key logger and or cache scrapper. And because we have already have kernel access for most drivers, the AV programs would probably never see it.
Almost no one monitors outgoing traffic, it would be awhile before we caught on.
Now how about the 3com deal. Would you trust your IDS/IPS products to a chinese company? Think people!
Take for example Lenovo. Most Lenovo's come with the driver update package turned on. It would take one update by Lenovo to install a trojan on every laptop, and desktop. Including a key logger and or cache scrapper. And because we have already have kernel access for most drivers, the AV programs would probably never see it.
Almost no one monitors outgoing traffic, it would be awhile before we caught on.
Now how about the 3com deal. Would you trust your IDS/IPS products to a chinese company? Think people!
Here's an example:
I co-locate several mail/web servers here in the United States. I
don't do any business in the Soviet Union so why should I allow
anyone in Soviet Union to see my servers?
I use Linux so in iptables I drop all traffic originating from the
network blocks - 80.0.0.0 - 90.0.0.0.0 - most of Russia.
Am I being anti-social? Not really.
Remember, I don't do business in that region so why should I
leave my server's open to attack from those countries?
I block lots of 'rouge' countries that have no business probing
my servers. Most countries get entire blocks of IP addresses like
that so it's easy to drop entire countries while allowing
legitimate traffic to pass through.
"Intelligence agencies already routinely test other states'
networks looking for weaknesses"... not the ones they can't see.
Government networks most of all shouldn't be available outside
their territorial boundaries. What's that? An embassy inside a
country you want to block? Then just allow traffic from that
address or network.
Could Google do this? Probably not. But for the rest of us, it is a
viable solution especially governments.
Does it solve the problem completely? Of course not, but closes
a giant open Window that has no good reason to be open.
Attackers could just go from computer to computer to computer
like they currently do and get someone's machine locally to try
and attack me but it makes it harder for them and costs me
nothing.
- Really simple solution...
- by catbutt5 November 29, 2007 10:53 AM PST
- Use the firewall that's probably built into your operating system.
- Like this Reply to this comment
-
-
- I block some russian IP too
- by ralahinn1 November 29, 2007 1:17 PM PST
- Sometimes you have to, a major part of spam bot traffic comes out of russia.
- Like this
-
(8 Comments)Here's an example:
I co-locate several mail/web servers here in the United States. I
don't do any business in the Soviet Union so why should I allow
anyone in Soviet Union to see my servers?
I use Linux so in iptables I drop all traffic originating from the
network blocks - 80.0.0.0 - 90.0.0.0.0 - most of Russia.
Am I being anti-social? Not really.
Remember, I don't do business in that region so why should I
leave my server's open to attack from those countries?
I block lots of 'rouge' countries that have no business probing
my servers. Most countries get entire blocks of IP addresses like
that so it's easy to drop entire countries while allowing
legitimate traffic to pass through.
"Intelligence agencies already routinely test other states'
networks looking for weaknesses"... not the ones they can't see.
Government networks most of all shouldn't be available outside
their territorial boundaries. What's that? An embassy inside a
country you want to block? Then just allow traffic from that
address or network.
Could Google do this? Probably not. But for the rest of us, it is a
viable solution especially governments.
Does it solve the problem completely? Of course not, but closes
a giant open Window that has no good reason to be open.
Attackers could just go from computer to computer to computer
like they currently do and get someone's machine locally to try
and attack me but it makes it harder for them and costs me
nothing.