Networking Forums

Networking Forums > Computer Networking > Linux Networking > Re: blocking gator and it's kin at the firewall

Reply
Thread Tools Display Modes

Re: blocking gator and it's kin at the firewall

 
 
JM
Guest
Posts: n/a

 
      08-05-2003, 05:41 AM
Rusty wrote:

> Hi,
>
> My wife was surfing today and got our win2kpro (and I just installed
> it yesterday!) infected w/ gain/gator dateminder etc simply because
> she didn't press the don't install button in the 5 seconds it allowed
> her while it was hidden behind a dozen pop-up ads.
>
> Im running RH 8.0 with an iptables firewall natting to the inside.
>
> Im wondering if there's product that will run on the linux box and do
> regular automatic lookups from a "spamassassin" type list, build a new
> chain based on existing rules and add those addresses blocking all
> connection attempts from those addresses, established or not.
>
> Thanks
> Rusty

Why not just remove Gator? It's not that hard to find the files it uses.
Just remove them.
 
Reply With Quote
 
 
 
 
/dev/rob0
Guest
Posts: n/a

 
      08-05-2003, 02:32 PM
In article <IzGXa.47566$(E-Mail Removed) >, JM wrote:
> Why not just remove Gator? It's not that hard to find the files it uses.
> Just remove them.


Why not just prevent it from ever coming back? It's not that hard to do,
and once it's done it's done forever.

I implemented my DNS-based gator eradication at a customer site running
appx. 75 Windows machines. When I trapped the gator we quickly (through
apache error logs) identified over 20 infected machines. How often do
you think we should go around removing Gators? Is that a good way for us
to spend our client's money? Sure, a lot of busywork for our Windows
man, but I don't like to do business that way. It's better for us in the
long run if we provide real value for the customer's money.

Gator's gone. Other vicious creatures will rear their ugly heads, and
when they do we'll permanently eradicate them as well.
--
/dev/rob0 - preferred_email=i$((28*28+28))@softhome.net
or put "not-spam" or "/dev/rob0" in Subject header to reply
 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
firewall blocking ports Flood Linux Networking 3 01-04-2007 08:21 PM
Firewall blocking IP renewal? Jeff Wireless Networks 1 07-17-2006 03:44 PM
how do I tell exactly what firewall is blocking intallation Broadband Hardware 1 04-18-2004 07:14 PM
Re: blocking gator and it's kin at the firewall Rich Piotrowski Linux Networking 0 07-29-2003 03:21 PM
Re: blocking gator and it's kin at the firewall /dev/rob0 Linux Networking 0 07-29-2003 01:05 PM



1 2 3 4 5 6 7 8 9 10 11