How many personal firewalls in a system?

Apr 10, 2006 25 Replies

I'm not referring to TCP/IP communication that's initiated 'from' a system. However applications that utilize TCP/IP and place ports upon a system into a 'listening' state DO represent a conduit for entry into a system that otherwise had none.

Yes. I agree that personal firewalls can be confusing to inexperienced users. However part of the problem is that many users all too often do not take the time to understand what it is that they're doing and simply charge ahead. Yes, I also agree that if we lived in a perfect world and if all software were better designed the issues of insecurity could be drastically minimized. Note the use of the word 'minimized' for even if you have the best designed software in place, social engineering always presents opportunity for compromise.

In closing the use of a personal firewall (even one that's not been configured as secure as it can be or one that's configured too secure) augments (e.g. 'adds to') other security practices (devices) that are and should be in place. More important the use of a personal firewall is extremely beneficial to prevent attack from threats that have been introduced into the local environment by means other than their having passed through the gateway.

Where have you been the last five years?

formatting link
An interesting list: the unpatched advisories of Internet Exploder.

formatting link

19 unpatched and 10 only partially patched advisories are in Secunia's list. Among them are advisories regarding Phishing, writing arbitrary files on user's hard disk, spoofing dialog boxes, FTP command injection and Mail relaying, spoofing content of other Windows in other websites, trick users to download malicious files, compromize users system (only partially fixed since 2004-07-13!), cross-side scripting ("This makes it possible for script code in a frame associated with one domain to interact with certain events like keystrokes typed in a frame associated with a different domain", that means: do not use Internet Exploder for Internet Banking or the other window will listen YOUR pin), exploring your system, executing arbitrary scripting code (only partially fixed since 2003-06-17!).

Please compare this for example to Firefox:

formatting link
The two unfixed advisories for Firefox are about cross-domain cookie injection and about Apple Java plugin spoofing. The partial fix is about download dialog file type spoofing.

Yours, VB.

And where were you last week when I explained that all of the above insecurities can be mitigated if IE has been configured appropriately?

For example, you could switch off ActiveScripting and ActiveX. Then you have a browser, which not only is totally unusable (no JavaScript, no AJAX based sites, no Flash, ...), but also infamous for letting attacks come true in spite of having switched off the feature, like with switched off ActiveX and in spite of this fact the exploit with "scripting safe" COM objects.

Really great.

There are people, who want to use their browser. And they want this for using web sites. Surprised? Of course, if you don't want to use most of the common web sites securely, then you may use Internet Exploder. If you trust in a browser, which repeatedly had security problems with features, which were switched off, of course.

I think, your own postings here show, that you're not trusting in Internet Explorer, too:

| The good thing about MS Antispyware is that it prevents | malware from being installed; it pops up a huge red box warning you and also | allows you to see any browser "helpers" that have been or are trying to be | installed.

If you're trusting in your browser, you don't need such features.

Yours, VB.

You mean TCP sockets, when you're referencing "TCP/IP communication", do you?

Ah - yes. And the easiest solution is to configure the applications not to do so, right? Then you don't need filtering here.

Yes. And a very easy solution for this problem is not to show then such useless popups, but filter the traffic away. Right?

Yes. In this perfect world even the manufacturers of "Personal Firewalls" would think about their concepts. Oops, Commodo did here in this group the last days...

And again and again (and again) the same question: please mention one single advantage of a "Personal Firewall" above the Windows-Firewall, which leads into a secure situation against an attack vector of your choice.

If ever one single person here or in other places will show a single feature of a single "Personal Firewall", which does, then please compare to all the threats you're getting by installing one of the common "Personal Firewalls" we tested.

From there:

| "When a person uses a 'Remote Control Trojan', they are provided with | equal, if not greater control of another person's PC than that of the | owner sitting at its keyboard." - Don Kelloway

On

formatting link
I'm finding, that you're teaching people how to remove remote control software (which you call "Trojan", while the Trojan Horse was Greek and full of Greeks, BTW ;-)

Don't you know, that when a PC ever was remotely controlled by an unwanted third party, then you never can trust the system on this PC any more, if you're "removing" the remote control software or not? So it is completely useless to remove such software instead of flattening and rebuild?

You could read this for starting:

formatting link
Yours, VB.

This I'll take exception to Volker, I *do* know I have not been compromised, neither my pc nor my servers, at murrumba.net.

Wayne

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required