Do not use free firewalls !

Jun 19, 2006 29 Replies

Superscan is not much better. The Nmap-bases ones are very good, but usually the frontend fucks it up sometimes. Try

formatting link
for a known good one.

Well, I would configure it correctly instead.

*sigh* Why do you think that you'd actually have control? If the program wants to create a connection without your consent (either explicit by configuration or implicit by reaction on user-invoked events), then it will simply bypass your so-called control.

Of course you won't see it because the usual way is to wait until the user starts a trusted program and then hijacks its connections. About every modern malware does so. Or actually most malware starts the program itself using IPC with the Windows shell and then suppresses the screen draws.

Then I wonder how you want to achieve any real security by running one.

Thanks, I'll do that.

Normally I do, but not every program is as user-friendly. Take installers for example. All you see is a dialog with a progress bar, and somewhere during installation it wants to contact some server. And I'm talking legitimate installers here, not malware. For example installers for games or utilities. Even driver setups do it. Maybe it just wants to check for updates or something, but the point is that it's doing it without my consent. And if I didn't have a firewall running it would be doing it without my knowledge as well.

Point taken.

---- 8< ----

Well, consider me educated. You're right, control is a myth.

You'd rather I hooked my machine up to the net without any protection at all? :-)

Anytime an executable starts (either by a user, schedule or invoked by another process), there's a risk. I understand that. Even when my system is "protected" by firewall, AV and HIPS software.

Never seen that. WTF are you installing?

Argh. You don't need any packet filter for finding that out at all. And especially it's no reason to mess up your computer's security with a broken one.

Same as I do? Just shut down all unnecessary services and keep your system patched. And don't any totally broken software. The point is that there's no need for so-called protection if there's nothing broken to protect.

Well, anything using Windows Installer (msiexec.exe) for starters. At one point I found it annoying enough to make a rule specifically blocking that program from accessing the internet. I update my ATI drivers regularly, and each and every time the setup wanted to contact some server (can't remember which one, I blocked it a long time ago). Maybe they're simply keeping track of the number of people using the latest drivers, maybe they're using the information for advertising purposes. Who knows? It certainly isn't needed for a successful installation.

Another example is the setup.exe for MusicMatch, a program I need to upload music to my MP3-player (simply copying tracks doesn't work since it uses an internal database, without the correct entries MM puts in there the MP3-player won't play the tracks). There's nothing wrong with the program itself though, it has an automatic update feature but that can be disabled (which it is).

What would you recommend I use instead? Honestly?

You have a point there. A service/program can't be exploited when it's not running (or installed). Which leaves the matter of finding out what software is safe to use. I can live with that. But that makes me all the more curious as to what you recommend I should be using to monitor my system to make sure nothing bad happens, instead of using a PFW.

Can't argue with that. Very true.

Oh, well, those usually don't work for me because a lot of developers seem to forget setting RequiresAdministratorPrivileges=0. Usually msi2xml does the job as well.

Get a grip at group policies where you can explicitly disable automatic update checks on MSI installer.

Needing a program to put files on a MP3 player certainly is very wrong.

netstat? What about graphical versions like TcpView? Or with extensive logging capabilities like portqry?

Number one place should be the system log. :-) Especially with reasonable auditing settings (f.e. failures on privilege usage).

And not to mention task manager (or, for better comprehension, Process Explorer). You'll learn pretty soon which processes you're commonly running.

Thanks, I'll look into that.

Yeah, I know. I mainly use it as a portable harddisk these days.

Didn't know about portqry. I googled for it and found it on the MS kb. Looks rather handy :-)

That's sound advice, I admit. I think I'm going to dig deeper into it. It's another frame of mind really. Keep an eye on the software you use and configure your system properly instead of relying on some piece of software to handle it for you. Software that can be easily influenced (or even disabled) by malicious programs (which you should avoid running in the first place).

For what it's worth, I'd like to thank you for clearing things up for me. I obviously had a lot of misconceptions about -real- security :-)

Isn't the user the person who should be protected and not protect?

Yours, VB.

Sygate was no problem at all to circumvent, as the rest of those "Personal Firewalls". It took me some minutes to hack PoC code.

Yours, VB.

Precisely, you HAVE to give it access, and who knows what it will do besides allowing you to browse the internet.

"Sebastian Gottschalk" kirjoitti viestissä: snipped-for-privacy@news.dfncis.de...

Well, normally it will only include its associated services network functionality. But in presence of malware, it will have some more services attached.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required