Counter hint to Doc: Routers exist that will use an analogue dial up modem as their outbound device.
Most commonly these interfaces are deployed as backups to a highspeed intereface, but they can be the primary also.
-Russ.
Counter hint to Doc: Routers exist that will use an analogue dial up modem as their outbound device.
Most commonly these interfaces are deployed as backups to a highspeed intereface, but they can be the primary also.
-Russ.
Volker Birk wrote in news: snipped-for-privacy@news.uni-ulm.de:
Mmmhmm... that's fine for ingress but what about egress?
"Somebody." wrote in news:uGcAf.9713$ snipped-for-privacy@nnrp.ca.mci.com!nnrp1.uunet.ca:
Care to offer some viable suggestions? I'm interested.
What do you mean with "egress"?
Yours, VB.
Volker Birk wrote in news: snipped-for-privacy@news.uni-ulm.de:
outbound connection attempts
Like from potentially malicious software
Do you know that "blocking outbound" does not work at all?
Yours, VB.
Volker Birk wrote in news: snipped-for-privacy@news.uni-ulm.de:
Making such a sweeping statement without any kind of proof doesn't really make me believe you I'm sorry to say.
Yours, VB.
Volker Birk wrote in news: snipped-for-privacy@news.uni-ulm.de:
The first didn't work because I don't have IE open (and I have it tightly filtered to only go to Windows update anyway). Trying it anyway, even knowing how tightly IE is filtered, results in the attempt being denied. Not seeing the proof of concept here. It relies on IE which is a security hole in and of itself. It also relies on the user not being capable enough to lock IE down suitably.
The second was caught by the software firewall I use and likewise didn't work. I'm not seeing the proof of concept here either.
So your comment "Do you know that 'blocking outbound' does not work at all?" is still unproven at least with respect to these two proofs of concept.
I will give you the fact that the Windows firewall (from Microsoft and whomever they leeched the code) would have allowed both of those POC to go right out the door and make mad, passionate love to the internet. But the software firewall I'm using at the moment, Kerio PC Firewall 4.2.3 blocked both. Or rather, blocked the first and asked me about the second. Either way, nothing went out.
This is PoC code, not working attack code. If you're telling me your default web browser, then it will work with it. If you're disabling IE, and testing with the PoC code for the scenario "IE as default browser", then of course this cannot work.
No.
Of course, you have to have a working Mozilla Firefox 1.0.x on your box, not deinstalling or filtering it before testing ;-)
What was the result? The second one is only tested with Zone Alarm Pro, because the new Zone Alarm Pro versions are filtering Windows messages. This makes Windows unusable, but instead this PoC code works perfectly.
BTW: the second one uses ActiveDesktop. If you disabled ActiveDesktop, it cannot work. It's just PoC code, remember, not working attack code.
It does not show, that there is no way to prevent this speacial kind of attack, it only shows, that it is not your "Personal Firewall", which can protect against such attacks.
No. You said in this posting: "The first didn't work because I don't have IE open (and I have it tightly filtered to only go to Windows update anyway)."
This is PoC code for the scenario "Internet Explorer" as your default browser. Your Kerio software filtered nothing.
Anyway, we tested the first one with Kerio Personal Firewall 4.1.2, and there were no problems. What does your Firewall ask, when you're testing with the right PoC code for your webbrowser?
Yours, VB.
Sorry, I will not write special PoC code for your configuration. If you're too dumb or not willing to understand, then this is your problem.
I'm not claiming, that my PoC code is running in every configuration, because this I only would try to achive if I would write attack code.
Yours, VB.
Volker Birk wrote in news: snipped-for-privacy@news.uni-ulm.de:
What does that matter? The firewall asked my permission and I denied access. I could have set the firewall to automatically block anything I hadn't pre-approved. I'm using Firefox 1.5 stock from Mozilla's own server.
You're obviously not understanding plain English. The firewall is what is preventing IE from accessing the net for anything but windows update. I didn't touch IE's own configuration. Continuing to call me dumb only proves that you are trying too hard to make your flawed PoC work...
No. As I said above, I use 1.5 and your code didn't work [and read this part carefully] BECAUSE THE FIREWALL ASKED ME WHAT TO DO AND I SAID TO DENY ACCESS.
I blocked your PoC from accessing the net through Firefox. That you don't understand this is not my issue.
Can't understand so you call me a name. Translation: you are too ignorant to support your own PoC.
*You* are obviously not understanding what a Proof-of-Concept is.
So tell me: how is a PoC of how to remotely control an application THAT IS ALLOWED TO COMMUNICATE supposed to work if the application IS NOT ALLOWED TO COMMUNICATE?
It's not the PoC that is flawed, but your understanding.
cu
59cobalt
So you don't have a working web browser, I understand. You're just not using the web.
My PoC code requires a working web browser. And it will work only on all those PCs and for those users, who're using the web - this will be everybody with the exception of you, as an estimation.
Yours, VB.
Have something to add? Share your thoughts — no account required.
Ask the community — no account required