Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Incidents: Re: suspicious firewall rules in WinXP firewall

Re: suspicious firewall rules in WinXP firewall

From: <Valdis.Kletnieks_at_vt.edu>
Date: Tue, 04 Jul 2006 10:39:04 -0400

On Mon, 03 Jul 2006 15:16:23 PDT, Bob Madore said:
> The first problem of course is the firewall or internet security suite
> --- remove that and all should be OK again.

You mean "all should *look* OK again".

> A spyware and virus have the ability to perform this same problem.

And if the corruption of the firewall is due to spyware or a virus,
fixing the firewall doesn't remove the actual malware, and as a result,
things are most certainly *NOT* OK. You have gotten rid of the patient's
fever, but the bacteria is still present.

Nuke it from orbit and reinstall. It's the only way to be sure.

  • application/pgp-signature attachment: stored
Received on Jul 04 2006
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]