This is topic A Couple Of Quick Questions About Logging Off The Computer in forum Film-Yak at Film-Tech Forum ARCHIVE.
To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=8;t=002527
Posted by Paul G. Thompson (Member # 655) on 09-23-2003, 06:27 PM:
First question: If I push "Start" scroll to "Shutdown" and click on it and then select "Log Off yada", are hackers still capable of finding their way into the computer if it is connected to DSL?
Second question: If I click on "Tools" in the MSIE tool bar, select "Internet Options" and select "Use Blank" and click on "Apply" and click "OK", can hackers still find their way into the computer if no other programs that access the internet are running, such as AIM 95, MSIM, etc?
Thanks in advance.
Posted by Daryl C. W. O'Shea (Member # 1303) on 09-23-2003, 07:54 PM:
1 - Yes... this doesn't disconnect the network interface.
2 - Yes... your homepage has nothing to do with your internet connection.
Of course, you've got a properly configured firewall running on your machine, so your susceptibility is substantially reduced.
Posted by Bobby Henderson (Member # 840) on 09-23-2003, 09:01 PM:
It should be noted not all DSL service has to be "always on." Software like EnterNET 300 can turn it "on" or "off". And then there are other more simple things such as shutting off the power to your cable/DSL modem. Hackers may have a lot of tricks up their sleeve, but they have NO software to make that power button switch on.
Posted by Daryl C. W. O'Shea (Member # 1303) on 09-23-2003, 09:06 PM:
Ah yes, I totally overlooked the possibility that you're not using a Cable/DSL router. If you are using software provided by your DSL provider to connect to their service, it is most likely that you are disconnected from the internet when you log off the machine.
Now if you are using a Cable/DSL router or even just a connection that doesn't require you to login to the service (like many cable services) then you are not protected if you simply log out of the machine.
Posted by Brad Miller (Member # 2) on 09-23-2003, 10:02 PM:
So Daryl, which wire(s) would have to be cut on a standard cat 5 nic cable to prevent the connection? I'm thinking it may be worth Paul's while to cut open a cat 5 cable and put a box with a switch inline.
Posted by Darryl Spicer (Member # 711) on 09-23-2003, 10:10 PM:
I noticed on my computer after the machine goes to sleep mode the network card deactivates does this prevent hackers from gaining acces?
Posted by Daryl C. W. O'Shea (Member # 1303) on 09-23-2003, 10:22 PM:
Disconnecting pin 1 or pin 3 (white/green or white/orange) would prevent the interface from working. Depending on your luck, putting a switch in the cable or making a box with a switch and a pair of jacks, the interface might not work regardless of the switch's position. Clean connections and the shortest un-twisted wire lengths possible are key.
Darryl, if the network interface card deactivates when the computer goes into sleep mode then sure, nobody can access your machine... that is if Wake-On-LAN isn't enabled. However, it doesn't really make much sense to be concerned with that. Wouldn't you rather make sure your computer is secure both when you're not using it and when you are using it?
Posted by Darryl Spicer (Member # 711) on 09-23-2003, 10:34 PM:
the machine is secure when I am using and not using it I was just curious if the network card being in sleep mode was accesable if someone was able to hack through.
Posted by Paul G. Thompson (Member # 655) on 09-23-2003, 11:03 PM:
The situation I was adressing is with the funky peer-to-peer network at work which is on DSL.
I decided to try an experiment at home. I just logged off on my networked Windows 98 machine. I need the password to get back on. OK, no problem.
But when it is logged off, I came to this machine to see if I can access the drives of the computer I supposedly logged off the network.
Yes....logging off didn't make a hoot of difference.
Now what is the sense of having all that password crap in the computer? Seems to me it is practically worthless. Sure, it keeps people out of that specific machine but the damned backdoor is still open wide enough for anyone as well as a herd of Rhinoceri to get through.
But yet I cannot acccess anything in this machine from the Windows 98 machine without a password I thought never existed.
This machine is running W2K. When I set it up a couple of years ago, I don't recall setting any passwords to keep the rest of my network BS computers out of this machine.
I don't know how to disable a password that does not exist so I can get into this machine from one of my other piles of junk.
As mentioned, the best way is to turn a switch that says O-F-F or install one helluva firewall.
Posted by Bobby Henderson (Member # 840) on 09-24-2003, 12:51 AM:
Paul, you're talking about network limitations in the consumer versions of Windows. Much of that stuff is an outright laffer. Just hit the Esc key to get by the "login" thingie when the computer boots. If you have multiple Win9x PCs networked together you can see the other PCs even if they are not "logged in". About the only thing you can do is disable file sharing on a hard disc or other type of disc.
On any WindowsNT machine (or machines running Win2000 or WinXP Professional) you can assign specific access permissions not just for disc drives, but also file folders or specific files themselves --something UNIX has been able to do for 2 decades.
Home networking is a slightly different animal than networking into broadband/DSL/cable Internet access. Software firewalls are okay, but if you have an "always on" connection (like most people using cable modems) you should get some kind of hardware firewall device.
The cheapest solution is using a cable/DSL router, which acts as a firewall to outside access. I have a little 4 port Linksys unit to network my old SCSI PC to my newer (yet now aging) Dell PC. The documentation doesn't make it easy to configure in sharing DSL access, particularly when you have a dynamic changing IP address. But once it is working you can get online without using software like Enternet300.
Of course other things apply, such as using constantly updated anti-viral software and spy-ware removal tools. However, in the end if I am not doing anything on the Internet I don't need to be connected to it. I shut off the power to my DSL modem. There is no way a hacker can break into your machine while that modem is powered down.
To be honest, I see damage from lightning strikes as a greater threat. I have the habit of removing the phone line from the DSL modem, especially if I leave on a trip for a day or two.
Posted by Dino Panagiotopoulos (Member # 1579) on 09-24-2003, 04:25 PM:
What I usually do before I log off at night, is go to my desktop PC (my laptop runs wirelessly) and disable the LAN connection in the network connections menu. Because My network cable runs through a wireless router first, the connection is always on and the only way to disable it is to turn off the LAN connection. It should be under the group of "LAN or High Speed Internet". This is the quickest easiest way to "disconnect" your machines from the DSL router.
Posted by Paul G. Thompson (Member # 655) on 09-24-2003, 04:56 PM:
Well, I splurged and spenmt 96 bucks (tax included) to get the Norton 2003 Internet Security Professional for my machine I am on now at work. Although this a whimpy 300mhz machine I was sort of pleased that Norton didn't bog this thihng down to a crawl like McAfee does.
Installed all the updates - seems to be running OK. So far, so good.
I also tried the "Escape" key to get around the password on this machine that has W2K. Feel much better now....It won't let me in without my password.
Daryl, is this machine still on the internet if I select "Log Off Yada Yada." As mentioned, that is a useless attempt on Win98. I think you said "Yes", but I don't know if you were also refering to W2K.
Anyway, thanks to all. You all have been a great help.
Posted by Daryl C. W. O'Shea (Member # 1303) on 09-24-2003, 05:50 PM:
Yes, the W2K machine is still connected when you are logged off. Your software firewall, however, should still be active.
Posted by Paul G. Thompson (Member # 655) on 09-24-2003, 05:56 PM:
Thank you, Daryl.
Posted by Joe Redifer (Member # 3) on 09-24-2003, 06:15 PM:
Why not just unplug the ethernet cable when you are not using it? Very few hackers can get in if there is no physical connection to your computer.
Or power the machine completely off. Only a couple hundred hackers could access your machine if it is completely powered down, and that's pretty good odds.
Posted by Daryl C. W. O'Shea (Member # 1303) on 09-24-2003, 06:19 PM:
No problem Paul.
I think more than a hundred people have access to a brick, Joe. Of course if they've busted through your window, it probably doesn't matter if you're logged in or not.
Posted by Bobby Henderson (Member # 840) on 09-24-2003, 08:05 PM:
If someone physically breaks into your home, just make sure they cannot find any un-used checks or other stuff with credit card and/or check account numbers on them. Those types of things are the most desired item of burglars now. They may totally ignore stuff like jewelry and stereo equipment since many pawn shops and similar operations have to file paperwork with police departments when paying people for stuff.
Now, to get back on topic, I have come across a new Internet snafu I've never seen before. I think one of my friends has a new piece of spyware or malware stuck in his system. Whenever he tries to do a search on Yahoo the search fails with a "page not found" thingie. When he tries to visit Google or any other seach engine it redirects him to some page with the title "are you trying to find Google?" The text of it talks about his machine being refused access to google because of spyware supposedly evident on his system.
Has anyone ever heard of this Google failure glitch before? I searched the Symantec website and others and found nothing about this. Ad-aware 6.0 and NAV 2004 also uncovered nothing.
Posted by Daryl C. W. O'Shea (Member # 1303) on 09-24-2003, 08:21 PM:
Weird.
Maybe somebody hijacked his DNS server.
Does http://216.239.41.99/ work for him? Yeah, I know, it's a long shot.
Posted by Bobby Henderson (Member # 840) on 09-24-2003, 10:00 PM:
Yeah, he got to the site by typing in the IP number. I just wonder what is in there that is making his browser get redirected elsewhere. His computer must be getting redirected to spoofs of the Yahoo and Google sites.
Posted by Daryl C. W. O'Shea (Member # 1303) on 09-24-2003, 10:04 PM:
His hosts file has probably been jacked with.
Open C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts with notepad and see what you find.
Posted by Bobby Henderson (Member # 840) on 09-25-2003, 12:12 AM:
Hehe, the ETC folder was missing, but after doing a search for anything with "host" in the name, we found a "hosts" file (with no suffix) in the C:\WINDOWS directory:
127.127.127.127 elite
64.191.95.139 www.google.com
64.191.95.139 google.com
64.191.95.139 www.altavista.com
[snipped here, but you get the idea --the list went on for quite some time]
After deleting the file, search engine stuff resumed normal function.
Posted by Jason Black (Member # 684) on 09-25-2003, 12:46 AM:
So form what I've read thusfar, my setup, (cable modem with Linksys 4port router) and ZoneAlarm (freeware version) should be adequate in keeping hackers out of my system, no?
I'm not as worried over someone actually breaking into the house...as there are no personal documents kept in my PC, I'd be more worried about 'real property'.
Posted by Bobby Henderson (Member # 840) on 09-25-2003, 12:57 AM:
Jason, you should be fine with your setup. The 4-port router acts as a firewall and then you have ZoneAlarm as another firewall level on the PC. You still need to keep up to date virus protection software on your machine to guard against e-mail and instant messenger attachments.
Most people get their machines infected with viruses and malware by clicking on and opening/launching files without considering what they do. This is why the Sven worm is so widespread. Most users don't think before they click. The problem is so bad that SBC Global has shut down certain communications ports used by these worms just to preserve bandwidth. For some users this has disabled online print sharing and a few other functions.
Posted by Joe Redifer (Member # 3) on 09-25-2003, 01:04 AM:
I have a Linksys 4 port router, but I have it direct FTP and HTTP protocols to my kick ass WINDOWS (yeah!) PC for web and FTP hosting. I have Sygate Personal Firewall installed on the PC. It kicks much ass. It's tremendously configurable. Plus I can see who and when (with IP adresses) access the computer.
I have zero firewall or virus protection on any of my Macs. I leave them on 24/7 with my bank account numbers and social security numbers sitting on the desktop in a file called MyBankAccountNumber&SocialSecurityNumber.txt.
Posted by Mike Williams (Member # 1140) on 09-25-2003, 05:22 AM:
quote:
I have zero firewall or virus protection on any of my Macs.
If they are behind your Linksys, they don't need it.
Posted by Bobby Henderson (Member # 840) on 09-25-2003, 07:20 AM:
Although a Linksys 4-port cable/DSL router works great at stopping nearly all break-in attempts, it is not 100% perfect. Some crackers can find ways of getting past them (and even past much more expensive firewalls). So it is still a good idea to have other security software running. Of course, all the script kiddie wannabe crackers are going to be scratching their heads if they manage to pop through a firewall only to find a Mac on the other side.
On a related note, I noticed Linksys improved their support page to provide configuration instructions on setting up their cable/DSL routers for a wide variety of high speed Internet services. SBC Global tries to sell its customers on those 2-wire branded thingies and won't say how to configure a Linksys unit. The Linksys website finally tells how to do it.
Powered by Infopop Corporation
UBB.classicTM
6.3.1.2