Welcome to City-Data.com Forum!
U.S. CitiesCity-Data Forum Index
Go Back   City-Data Forum > General Forums > Science and Technology > Internet
 [Register]
Please register to participate in our discussions with 2 million other members - it's free and quick! Some forums can only be seen by registered members. After you create your account, you'll be able to customize options and access all our 15,000 new posts/day with fewer ads.
View detailed profile (Advanced) or search
site with Google Custom Search

Search Forums  (Advanced)
Reply Start New Thread
 
Old 10-27-2010, 05:56 PM
 
10,926 posts, read 21,997,495 times
Reputation: 10569

Advertisements

Quote:
Originally Posted by Asheville Native View Post
I started the thread, it is about being scanned while placing an order on newegg, thus a ZA discussion is off topic
I tell you what, find me a thread on here that stayed 100% on topic and I'll remove my post, otherwise it's staying. I didn't start the ZA discussion, I just commented on it. If your skivies get in a bunch because your thread deviates from what you consider on topic, then all I can say is I wish my life was so serene that I had time to be concerened with such things!
Reply With Quote Quick reply to this message

 
Old 10-27-2010, 07:37 PM
 
Location: SCW, AZ
8,320 posts, read 13,450,418 times
Reputation: 7987
I am amazed at how kwikly the topics in the computer section can get off topic and/or get heated!

Bunch of computer geeks getting into a cyber brawl over (some random computer related topic), now that is always fun for the forum guests!

Perhaps we need a new thread/poll about which current software firewall is the best?


Asheville, you sure you were not visiting http://www.knewegg.com?
Reply With Quote Quick reply to this message
 
Old 10-28-2010, 05:11 AM
 
10,926 posts, read 21,997,495 times
Reputation: 10569
Quote:
Originally Posted by TurcoLoco View Post
I am amazed at how kwikly the topics in the computer section can get off topic and/or get heated!

Bunch of computer geeks getting into a cyber brawl over (some random computer related topic), now that is always fun for the forum guests!

Perhaps we need a new thread/poll about which current software firewall is the best?


Asheville, you sure you were not visiting knewegg.com
We just like to have have fun and give each other grief
Reply With Quote Quick reply to this message
 
Old 10-28-2010, 06:14 PM
 
24,488 posts, read 41,141,698 times
Reputation: 12920
I do have a question about how a port scan even makes it to a software firewall? It should be blocked by the hardware firewall first.
Reply With Quote Quick reply to this message
 
Old 10-28-2010, 07:57 PM
 
16,294 posts, read 28,531,593 times
Reputation: 8384
Quote:
Originally Posted by NJBest View Post
I do have a question about how a port scan even makes it to a software firewall? It should be blocked by the hardware firewall first.
Correct, IF this just came out of the blue, but this didn't as I had a newegg webpage displayed as I was in the process of placing an order. I was actually in the checkout process when the warning appeared. Javascript embedded in the page would contact the server to run the Nmap scan, thus negating the protection SPI, (just basic NAT function provides), and one reason I only allow scripts to run on sites I should be able to trust, otherwise NoScript blocks any script execution.

Once you go to a site, and are not blocking execution of Javascript or ActiveX scripts, they are in, and they gotcha ya by the short hairs, thus the reason I use FF with NoScript, and never use IE.
Reply With Quote Quick reply to this message
 
Old 10-28-2010, 08:28 PM
 
24,488 posts, read 41,141,698 times
Reputation: 12920
Quote:
Originally Posted by Asheville Native View Post
Correct, IF this just came out of the blue, but this didn't as I had a newegg webpage displayed as I was in the process of placing an order. I was actually in the checkout process when the warning appeared. Javascript embedded in the page would contact the server to run the Nmap scan, thus negating the protection SPI, (just basic NAT function provides), and one reason I only allow scripts to run on sites I should be able to trust, otherwise NoScript blocks any script execution.

Once you go to a site, and are not blocking execution of Javascript or ActiveX scripts, they are in, and they gotcha ya by the short hairs, thus the reason I use FF with NoScript, and never use IE.
You see the irony in that, right? It would have had to attack through an already invoked TDP connection to make it to your computer... one that was already utilized by your browser in this case.
Reply With Quote Quick reply to this message
 
Old 10-28-2010, 09:35 PM
 
26,143 posts, read 19,841,434 times
Reputation: 17241
Quote:
Originally Posted by Asheville Native
Sorry newegg, no sale.
Excellent

Having a firewall with SMART FILTERING really helps huh?
Reply With Quote Quick reply to this message
 
Old 10-29-2010, 11:08 AM
 
16,294 posts, read 28,531,593 times
Reputation: 8384
Quote:
Originally Posted by NJBest View Post
You see the irony in that, right? It would have had to attack through an already invoked TDP connection to make it to your computer... one that was already utilized by your browser in this case.
Yea, that's what I said, I have a very good understanding of the process having worked in networking since the early 90's, and holding a number of certifications.
I also understand the power of Javascript that may be embedded in any site I visit, thus I rely on a firewall, modified hosts file, and utilization of OpenDNS to provided additional layers of protection. But I trusted newegg, as I have used them in the past, and they apparently took advantage of that trust.
Reply With Quote Quick reply to this message
 
Old 10-29-2010, 11:29 AM
 
Location: Tyler, TX
23,862 posts, read 24,111,507 times
Reputation: 15135
Quote:
Originally Posted by Asheville Native View Post
I trusted newegg, as I have used them in the past, and they apparently took advantage of that trust.
I'm tellin' ya, you're wrong. You're inferring WAY too much from an ambiguous warning from ZA.

You said something about the javascript initiating the process - well, did you LOOK at the js? Do you have ANY proof other than the ZA popup that Newegg was doing something nefarious?
Reply With Quote Quick reply to this message
 
Old 10-29-2010, 06:46 PM
 
16,294 posts, read 28,531,593 times
Reputation: 8384
Quote:
Originally Posted by swagger View Post
I'm tellin' ya, you're wrong. You're inferring WAY too much from an ambiguous warning from ZA.

You said something about the javascript initiating the process - well, did you LOOK at the js? Do you have ANY proof other than the ZA popup that Newegg was doing something nefarious?
No, I did not say javascript initiated the process, but was explaining to someone that believed the NAT firewall should prevent any external attacks such as this, that javascript exploits are very powerful if embedded in the page, and javascript is allowed to run.

At the risk of repeating myself, but I guess necessarily, I ain't running ZA.

IP address is within newegg's range, and no I didn't run netstat to see all the specific connections and ports currently open, because I was in a bit of a hurry at the time.
Reply With Quote Quick reply to this message
Please register to post and access all features of our very popular forum. It is free and quick. Over $68,000 in prizes has already been given out to active posters on our forum. Additional giveaways are planned.

Detailed information about all U.S. cities, counties, and zip codes on our site: City-data.com.


Reply
Please update this thread with any new information or opinions. This open thread is still read by thousands of people, so we encourage all additional points of view.

Quick Reply
Message:


Over $104,000 in prizes was already given out to active posters on our forum and additional giveaways are planned!

Go Back   City-Data Forum > General Forums > Science and Technology > Internet
Similar Threads

All times are GMT -6. The time now is 01:44 AM.

© 2005-2024, Advameg, Inc. · Please obey Forum Rules · Terms of Use and Privacy Policy · Bug Bounty

City-Data.com - Contact Us - Archive 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37 - Top