rules.fwr by RaGe
contact info: http://raptor.dal.net/rage/
                       rage@dal.net
                       rage@tera-byte.videotron.ab.ca
                       rage@iastate.edu

disclamer: this .fwr was configured for ConSeal PC Firewall v1.0 over an 10Base-T ethernet 
connection.  I have sent it to well over 40 people and have had about 5 have problems.  
I am in no way associated with Signal9, the makers of ConSeal PC FireWall.  
This rules.fwr is distributed AS IS by me, I can not, and will not be 
responsible for anything that happens to your computer while using this .fwr.  
I have done my best to cover all aspects of internet security, while still letting you 
use almost everything you used before.  However nothing is ever perfect.  
If you have problems, I would be glad to help, just email me at the address(es) above. 
 Better yet you can find me on DALnet IRC network in channel #RaGe_HeLp or just /msg me 
(raptor.dal.net is the server I use).

Ok, on to what this rules.fwr is setup to do:

TCP/IP:

31 threw 40: I have all of these ports set to warn.  
Most attacks start with a port scan (connecting to every                                                                   
port on your pc attempting to see what ones are open.) with these ports not used by any 
applications that I know of, I have set them to warn (port scan watchers), 
so that if someone connects to all or several of them you will know you are being scanned.

113 (identd): this port can be used for serveral attacks (tcp/ip flooding, teardrop)
however most often its used to identd checking by your server or other applications.  
I have left this port to only warn and log.

139 (nukes): blocks as well as logs and warns

all other ports I have left open, if you know of others that should probably not be, feel
free to contact me.

ICMP/IP:

contrary to "popular believe" icmp does use ports.  ports 0 - 11 is what I have found to 
be common ports.  I have setup the icmp/ip section to catch each and ever single port 
that recieves and icmp, and what it does depends on the icmp port connected.  
currently most attacks are: remote port 3 to local port 3, this is an unreached packet 
attack, your firewall will reference it as (ref#23)  thats reference number 23 in your 
rules.fwr.  another common attack is simple icmp echo requests.  This can be malformed 
to make ssping "ping o' death", as well as others, or a simple flood of pings saturating 
your connection making it useless.
This type of icmp will show up as (ref#20), however remember NOT ALL ICMPS are attacks.  
Now here are a couple things this rules.fwr will NOT be blocking.  It WILL NOT block your 
outgoing icmp echo requests, or incoming icmp echo replys, what this means is you CAN 
ping other servers, and you will get a reply.  It will NOT block outgoing traceroutes, 
or incoming reply's.  It will block be default everything else that doesn't fit what I 
have listed here.

All other data types:

Are by default left to allow all connections in and out.  I know this leaves a few things 
like udp flooding open, however I have not seen anyone using udp flooding in a long while 
now, it seems pretty much old hat, and useless if you have the ms patches. 
(found at http://raptor.dal.net/rage/ of course!)

INSTALLING THIS RULES.FWR

Ok, you need to close your firewall (some connections may be lost when you do this).
Then you need to find the directory your firewall is in (c:\program files\signal9\firewall 
is default) move your  rules.fwr (assuming there is one) out of the firewall directory, 
or rename it, this is basically making a backup in case there are problems with your new 
rules.fwr. Drop in the rules.fwr that you now have. (drag and drop or copy/cut and paste 
will all work fine)
start your firewall up and be sure it says: time AM/PM ruleset file: x:your firewall 
dir\rules.fwr this will mean you are using the rules.fwr as your firewall ruleset, 
if it does NOT show you are using rules.fwr you can click "file" "change ruleset file" 
and choose the rules.fwr that you now have.  You can also use this to move back to 
your old ruleset should you have any problems.

OK MY FIREWALL SAYS I'M BEING ATTACKED!!!

If you are on IRC (hopefully using mIRC the best client) you will want to check if the 
person is on by ip (the numbers your firewall shows). In order to do this, left click
 your firewall on the line that shows your being attacked (you think attacked anyway). 
and it will show you a two sets of numbers, and ask a question like this:

206.149.71.77
129.186.181.33
What is this menu for?

the top number is the ip number connected to you, the second is the your ip. 
if you left click that first number it will be stored on your clipboard.  
you can then go back to mirc and type: /who 206.149.71.77  
(thats /who (hold down control and click V) to paste) and enter, this will look for 
anyone on by that ip, if there is not, try /dns 206.149.71.77
this will look up there ip name, it will look like this:

*** Looking up 206.149.71.77
-
*** Resolved 206.149.71.77 to fbk-p2-77.alaska.net

you can then type: /who fbk-p2-77.alaska.net

and look if they are on by there ip name, this will help you track the user attacking 
you, assuming you are being attacked (that is not allways the case, altho most often I 
find it is).

OK I FOUND HIM, HOW DO I BUST HIS ASS?

The BEST way to go about putting an end to this type of user, that attacks at random, 
or attacks people just because he things he's 3l337, or cool, is to get his internet 
access taken away don't ya think?  here is how you can go about that.  Msg him, and 
talk to him about what he has done.  Most of these user will openly admit they have 
attacked you, smart guys huh?  You can then send this log, as well as the log from 
ConSeal PC FireWall of the attack to the users isp.  Let them know what the attack 
means, as well as be polite about asking them to deal with this user.  
Most isps don't wan't this type of user, and will work with you.  Also, be sure and 
tell them the time zone your timestamps are marked in, so they can find the user 
without bothering you to ask for your timestamp info.  Ok, now that you know what 
you are going to write, how do you know WHERE to write?  Ok, hold on I'm getting 
to that.  First a few helpfull hints from the example above we had:
fbk-p2-77.alaska.net, I would try www.alaska.net and see if they give any 
email addresses, this example does, don't feel bad about sending to the "wrong address" 
within the same domain, someone there will get your email to the right person more 
then likely.  If you can't find a web page for the domain, or email on it try this 
web page: http://rs.internic.net/cgi-bin/whois  and type in: alaska.net 
(or whatever your looking for) this is another way to find possible email addresses 
for the users isp. If all that fails you can also try: abuse@  support@ webmaster@. 
our example would be: abuse@alaska.net support@alaska.net webmaster@alaska.net 


If anyone has any questions that I haven't covered or knows something I should add, 
or even if you just change your ruleset to make it better, or have something to add. 
LET ME KNOW, we could all benifit from your ideas.  
I would also like to thank kitfox on DALnet for help with some of the rules 
in this ruleset, as well as all my friends for helping me test them out and develop them.

RaGe


