One other thing.... there is no way to be totally secure while connected to a network. Firewalls (actually 'filters' if only one multihomed host), using address translation of any ratio, are only a stumbling block for an accomplished hacker. The external address is always valid for stateful connections, since the endpoints are absolute. The internal, or RFC1918 address Reel is talking about, can be easily enumerated by sending out of spec packet specifications. Nat is a good start but it's just that, a start. Being a force for good, I would never do it, but I could easily dupe my way into most any system I desired. I have broken into my own systems for academic purposes thousands of times. A common method on these message boards would be for a hacker to post a seemingly harmless link to a seemingly interesting article, but the rub is that he/she operates the web server, which reveals your external IP address, known to be valid for anyone that received a 200/OK message from the webserver, AND sent an ACK/FIN for a graceful connection close. This establishes the source 100%. After that, the spatial skill of the person takes over. Look up the netblock, enumerate all of the users posts, do all of the public record searches, run lexis nexis searches for all hits on possible identity revalations in the area known native to the users netblock, etc. The methods number in the tens of thousands, and given the skill are successful 99% of the time after a few minutes of effort. I wouldn't even want to show you how easy it is for someone who makes a career or hobby out of network security to find your complete life history and current residence; you'd never connect your computer to a network again. Also, realize that NAT or PAT does work on dialup or whatever, the layer1/2 topology does not affect NAT or PAT which are layer3 (IP in this case).
I've completed a working prototype for a personal , TRUE to definition FIREWALL, plug and go, better than most of the largest company's firewalls. Problem is, I can't get the cost lower than 1000$, so I'm not sure how hungry for security people are to spend that kind of money. The product uses 3 different autonomous systems, 2 DMZ networks, and 16 directional, state inspecting filters, intrusion detection and prevention, spam blocking and inline virus scanning. I may try to sell the concept to get the price down.... but the fact is noone else has built it. I have pics but I'm scared to release them until I have a patent done. Point being, help is on the way, but be as careful as possible and remember, EVERY tidbit can come back to aid in tracking everything there is to know about you. Blessing and a curse is this fantastic partially-meshed network we call the internet. Help is on the way......
|