Medium Level Settings

Attacks Tab

Overview of Zone Security Options

Overview of Medium Level Security

The Attacks tab shows all the Internet attacks that are blocked by iolo Personal Firewall. The firewall analyzes arriving packets and communication attempts; when the signature of an attack is recognized, it is blocked.

 

Many of the attacks you are protected against are Denial of Service (DoS) attacks that can crash your computer or network. iolo Personal Firewall notes any blocked attacks in the Firewall Odometer.

 

To follow is a list of each known attack and a description.

 

Attack Name

Block

Attack Description

Ping of Death                

Yes

A type of DoS attack that sends an ICMP PING packet with a large amount of data. It causes a buffer overload on the receiving operating system and crashes the system.

Land

Yes

A type of DoS attack that sends a packet with a header that has the same source and destination data, causing the system to go into an infinite loop. It causes computers running various operating systems to crash.

TCP Port Scan

Yes

A TCP port scan sends a message to ports. The response received indicates whether the port is used and can then be probed further for network vulnerabilities.

If iolo Personal Firewall's detection algorithm finds a TCP scan, further communication from that source is blocked.

UDP Port Scan

Yes

A UDP port scan consists of sending sends empty UDP datagrams. The response received indicates whether the port is used and can then be probed further for network vulnerabilities.

If iolo Personal Firewall's detection algorithm finds a UDP scan, further communication from that source is blocked.

SYN Flood

Yes

A type of DoS attack that sends a large volume of SYN packets. It causes a buffer overload, affecting the performance of a Web server.

UDP Flood

Yes

A type of DoS attack that sends malformed packets to UDP ports, causing the receiving system reply with ICMP "Destination Unreachable" packets. It causes a buffer overload on the receiving operating system and crashes the system.

ICMP Flood

Yes

A type of DoS attack that sends a host more ICMP PING packets than the system can handle. It causes a buffer overload on the receiving operating system and crashes the system.

Helkern

Yes

Also known as SQLSlammer, a worm that causes a DoS attack. It causes a buffer overload on servers running Microsoft SQL Server 2000 and spreads rapidly across unprotected networks.

SmbDie

Yes

A type of DoS attack that sends a malformed packet over the SMB (Server Message Block) protocol used for file and print sharing. It causes computers running Windows NT, 2000, or XP operating systems to crash.

Lovesan

Yes

Also known as MSBlast or Blaster, a worm that causes a DoS attack. The worm sends a malformed packet that causes a buffer overload in the Windows RPC (Remote Procedure Call) locator service. It causes computers running Windows XP or 2000 to crash. For systems running IIS 5.0, the worm can also give an attacker remote access to a computer.

 

Note: If you want to remove the block for an attack (not recommended), instead of Medium level settings, use Custom level settings and select the Attacks tab.