Re: A password problem about Zone Alarm.. really need help!
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: A password problem about Zone Alarm.. really need help!

From: Volker Birk <bumens@dingens.org>
Date: Tue Feb 07 2006 - 12:00:19 CET

Cliff Wild <CliffWild@xemaps.com> wrote:
> I don't see how this is a security group

Have a look on the _name_ of the group, please.

> > BTW: this is, what providers of "Personal Firewalls" are selling:
> > the illusion to be in control. They're selling dreams.
> I still don't see you as making any sense. I don't set any warning other
> than my PFW telling me if any part of what I am installing wants to monitor
> my keystrokes.

This is technically not possible to do realiably. For example, there
are hardware keyloggers. If we're talking about software keyloggers, I
personally would implement them in kernel space. There they cannot be
controlled by any software program, which is running on the same machine
by concept.

So if you're installing software on Microsoft Windows, then usually you
have to do this with administrative rights. And then your "Personal
Firewall" loses anyway, if in doubt.

> If I have a keylogger or spyware how do you tell other than
> running a scan which takes longer than a pop-up.

I already showed, how easy it is to communicate ignoring "outbound control"
of "Personal Firewalls". Exactly _not_ _a_ _single_ "Personal Firewall"
managed to prevent this. You can find my PoCs for this topic, if you're
searching in this group.

Yours,
VB.

-- 
> was ist wenn $BACKUPSERVER und $PRODUKTIVSERVER in einem Gebäude, Stockwerk
> oder Serverraum stehen und die Löschanlage (Fehlfunktion oder Brandfall)
> die komplette IT zerstört
Murphy meets Darwin. (Timm Thiemann zu Thomas Wildgruber in d.a.s.r)
Received on Tue Feb 7 20:59:27 2006