Re: guidance sought
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: guidance sought

From: ArtDent <par@noyd.invalidname>
Date: Fri Mar 31 2006 - 18:01:34 CEST

On 30-Mar-2006, Volker Birk <bumens@dingens.org> wrote:

> ArtDent <par@noyd.invalidname> wrote:
> > The WindowsXP firewall only blocks incoming, it does not even look at
> > outgoing, pretty much what your router already does.
>
> *sigh* - the "outgoing" argument again. Do you have anything new to add
> to
> this discussion, "ArtDent"?

Not really, but I felt it was relevant to the OP question(s).

>
> > Again, there seems to be a very vocal group here saying to turn off /
> > do
> > not use software firewalls, I just wonder if that has anything to do
> > with
> > the million machine bot-net that was just 'discovered'. When someone
> > tells me to turn off my firewall, I _seriously_ wonder about their
> > motivation for such advice.
>
> It seems, that you're trying to replace arguments you don't have with
> weak
> allegations. But for that point:
>
> Whom should be trusted - a person, who writes with full name here, and
> who
> easily can be found in real life, or an anonymous, who even is too
> chicken-
> hearted to stand behind what he or she is publicizing?

If you truly want to 'find' me, do a whois on my organization name with a
dot com or a dot net after it. I use a 'nym' because of the bots that
troll these ng's looking for email addresses to send their spam to.
Saying that, I am not sure what your 'problem' here is, I was putting
forth my personal opinion there, just like many others have done in this
ng.
I figured the OP should at least have the option of hearing a dissenting
view.

>
> > forgetting that everyone that comes here is not up to their level in
> > understanding this stuff.
>
> Please decide, what you want to allegate. Your two accusations are
> conflicting.

I was trying to say that it seems to me that some of the 'regs' here seem
to think that everyone that finds their way here is up to the 'guru'
level. They seem to like to give technical answers when the questions are
'beginning' level.
Again, just my opinion.

>
> > So, with the router and XP firewall on, you should be fairly well
> > covered
> > from unrequested incoming stuff, but if anything is already on, or
> > somehow
> > gets onto your machine, they will not even blink an eye when all of a
> > sudden your machine is sending out 1,000 emails an hour. Actually, for
> > that, even other firewall programs will let them go out _if_ you have
> > given the sending program permission, but the router and XP firewall
> > will
> > not even ask.
>
> And the "other" firewalls won't, too, if the malware is not completely
> dumb
> and does not use one of the well-known possibilities to communicate
> ignoring
> any "Personal Firewall".
>

That has changed 'lately'. Quite a few personal firewalls now do
checksums or some other method to make sure that the program(s) you give
permissions to acces the net, stays its pristine self.
Yes, ok, _some_ malware can 'sneak' past _some_ personal firewalls, but,
having one is USUALLY better than not having one - FOR THE NEWER USERS,
whom are the ones usually asking the questions about this.

> VB.

Let me ask you, do you LIKE having all these bot-nets available to the
highest bidder to do whatever illegal activities the 'customer' desires?

-- 
We apologize for the inconvenience
Received on Mon May 1 01:03:37 2006