Quote from coolweb:
1. Just hide behind a Router, nothing can get to you
2. Those scans php exploit scans aren't going to effect you,
I guess its a good piece of mind to have an actual hardware blocking.
A router can do that for you though.
There are no php exploits on that screen.
What you see on that screen is stuff like Spyware trying to get into the computer etc..
I am behind a cisco ASA firewall and this sits behind that. What you see on that list is stuff on websites trying to mess with the computer.
Such as this
"Filter Name 6794: HTTP: Google Analytics Information Disclosure
Category Application Protection - Security Policy
Severity Low
Description This filter detects an attempt to publish information to Google Analytics.
Google Analytics is a free service that allows web site owners to track statistics about the users of their site. It collects data such as whether the user is new or returning, timestamp of visit, referrer, and other sensitive data without the user's consent or knowledge.
References:
OR this
Filter Name 9286: HTTP: Malicious FakeAlert Webpage Request
Category Application Protection - Exploits
Severity Critical
Description This filter detects the download of a malicious FakeAlert web page.
FakeAlert web pages, also known as scareware, are designed to entice users into downloading and installing malware onto their computer. The page is designed to display a false "My Computer" hard drive scan to the user and report that several infections have been detected. The page then instructs the user that installing a piece of software will rid their system of said infections.
Reference:
Scareware Wikipedia Article
Filter Name 4430: HTTP: HSBC Login Phish Site
Category Application Protection - Identify Theft
Severity Minor
Description This filter detects a connection to a spoofed phishing web site designed to trick a user into revealing sensitive financial account information, such as a username and password, over an insecure HTTP link.
The firing of this filter indicates that the source IP address is the host of the malicious web site, and the user at the destination IP address has likely been tricked into clicking an e-mail link to the malicious web site.
References:
Filter Name 3142: HTTP: Phish Site with Forged Verisign Seal
Category Application Protection - Identify Theft
Severity Minor
Description This filter detects a connection to a spoofed phishing web site designed to trick a user into revealing sensitive financial account information, such as a username and password, over an insecure HTTP link.
The firing of this filter indicates that the source IP address is the host of the malicious web site, and the user at the destination IP address has likely been tricked into clicking an e-mail link to the malicious web site.
References: