outbound filtering

Dec 26, 2006 63 Replies

Thanks for your informative and considerate response, Lethos - a complete contrast to the spiteful and vituperate replies by Sebastian Gottschalk. I'm sure the O.P. and others on this forum also appreciate your contributions.

Jim Ford

Careful, if you say nice things about me SG will kill-file you as a troll :)

Really, I design secure network for a living, at the medical, government, intel, military levels, and have never had a compromised network. I'm sure the SG and his group could help if they were not so stuck on their own importance.

Let me know if you need anything else.

And a useless one. The things stated above won't stop just the littlest program from "phoning home".

You still don't get it? This is no forum, this is Usenet.

I recall I did not see mention of port range 1024-1030 as blocked or otherwise restricted, even though some ports in that range seem to gather considerable non-solicited attention:

formatting link
There are particular applications like instant messaging clients etc. using some of them, but still, does blocking that range prevent Windows from working otherwise? I seem to do well enough without them.

Killfile

There, that's better. You can call me names all you want now, since I won't have to listen to it. Anyway, to the OP, seriously, listen to the rest of us, but pay no attention to Sebastian Gottschalk. He really gives the usenet community a bad name.

Will

Hehe...do you suffer from any form of personality disorder sebastian? or do you have a doppelganger? me

I actually have rule in our firewalls (yes, multiple units at many locations) that will auto-block any host probing 1026 or 1027, for 20 minutes. On our developers network, where we do the same for 445 probes, we're currently blocking about 60 sites that have probed or been classified as unapproved probing. This list has been as high as 300+ sites, but it's dynamic - meaning they are blocked for 20 minutes automatically, then resets. If I see them in the logs to many times I just setup a permanent ban on that IP.

Well, do you know why? Windows tries to assign the lowest ephemeral ports to RPC services, so they usually end up at 1025-1030. Task Scheduler, if not unbound, is such a very typical service. It usually ends up at 1025, and had various security vulnerabilities.

Ehm... these are ephemeral ports, thus they can be used by ANY application.

Eh... exactly ANY application?

Sure, you won't notice it. Windows by default choses ephemeral ports from

1025-5000, thus if you block 6 out, your chance of noticing an application error is 6/(5000-1025+1) ~ 0.15 %. Unlikely that you could contribute such a seldom error to such a misconfiguration

At any rate, it would be a much wiser choice to exclude this range from being used by applications. Heck, you can do this even in Windows!

I got that impression a few days ago but it was fun watching you two banter. Don't give up on him yet!

I decided to reinstall a PFW for outbound control. For now I am trying to learn Comodo PFW, although it seems more complicated than the Sygate

5.6 I was using before.

That contributes nothing to the discussion at hand other than to illustrate your limited understanding of the English language.

"a medium (as a newspaper or online service) of open discussion or expression of ideas"

If you take a look at you might learn to remedy your deficiency so you don't look so foolish in the future.

It does. Usenet is not a support medium, it's a medium for discussion. As such, there's no reason for answering questions to a poster just because he asks, or to stick with his intended topic, or even refer to the original discussion point.

In fact, a well-known Usenet law states that every sufficient long discussion ends up with the topic "beer", no matter what the original topic was. :-)

Seems like your understanding is limited as well. It doesn't mean that every such medium is a forum. Just like a blackboard that can be used for discussion isn't a forum, Usenet as the digital variant of a blackboard isn't either.

You mean as foolish as you're looking now for not checking , which explicitly differs between forums and newsgroups?

Where in the sentence "I'm sure the O.P. and others on this forum also appreciate your contributions." do you see "Internet forum"?

For your education:

Maybe you should stick to your area of expertise and avoid advising others about the English language.

And what is context?

Nah, I just missed to insert the fup2.

Discussion encompasses support questions - which is one of the reasons that Usenet was started. Usenet was setup so that GROUPS of people in different locations could communicate with each other in specific topic areas and most all of them were questions/answers.

You are way off base again SG.

Well, that's good. Best of luck to you. I guess one of the perks (and curses as well) to usenet is it's more or less unmoderated, so free speech slices both ways.

There's nothing about the context that limits the meaning of "forum" to mean "Internet forum" or, as you seem to want to further limit things, "web based forum".

We can continue this as long as you like but you should be aware that your ineptitude is quite obvious to readers for whom English is their first language.

It occurs to me that someone who pretends to be an English language expert might also pretend to be an expert in other areas.

Hey, I'm missing Mr Nasty already - I'm un-filtering him now!

Jim Ford

Great, I'm not. For some reason, I get the feeling that somehow reading his posts makes my intelligence quotient drop a few points. Is it possible to get dumber from reading someone else's rantings even if you don't subscribe to their ideas?

No William let's face it, he's too smart for us. Not only is he an expert on computer security, but he's an expert in the English language. Why, if I was to suggest that he was a bit of a 'Douglas', the geezer would cotton on quicker than the proverbial - if you follow my drift! It would also be no good at all to suggest that he frequently puts 'is tootsie in 'is norf 'n sarf 'cos 'eed be onto our malarky in a flash - even if he is a 'Hampton'! (I hope I haven't lost out Transatlantic friends here!)

;^)

Sincere condolences, that you're fooled.

Yours, VB.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required