|
Hrm let me see, with your IP and using Dameware NT Utilities I can load a remote control agent on your system. Remote in when your PC is on and you are away, and wipe out your system. Even with a firewall if I have your IP I can send a query to the firewall which will tell me what it is. If it's not Zonealarm or a software "we block everything and the kitchen sink" firewall I can probably access the settings by simply going to the net and finding out what the port is for remote administration of your firewall, go to your IP and that port in my web browser, run some old school, brute force password attacks if the default PW for that particular manufacturer doesn't work (you'd be amazed how many DON'T disable remote Firewall administration and don't change the admin password) allowing me even MORE access to the systems on your network as I can open every port I want on your system.
Couple in the possibility if it is a corporate employee who uses their system to VPN one could run a sniffer on that system in the background once access is gained, a key recorder or anything of the like (which you would never see running if it's XP because you could launch it as a svchost) and gain access to the passwords, settings, and all the info I wanted that you use to VPN. Not to mention being able to spoof any direct transactions you do through the net. Think you're paypal account info, or credit card billing is safe? If you do any kind of transactions on the net a simple key recorder can record every stroke can be recorded of every website you go to, or even screen shots taken and sent out through the now open ports to a dummy shell account on an anonymous *nix shell account (easily aquired on the net) to be picked up later and sifted through. Then it's just one small step to doing identity theft and buying what we want with YOUR info and ID..... Remember you don't have to have a street address to get a PO Box, and Mailboxes Etc. and the like can appear the same as a business adress and they don't check up on their information.
So that's why you don't want to be giving out IP addresses. And I would prefer not going anymore into detail as to what and how things can be done, or how anyone might know this stuff.
|