Re: A good firewall working fine in default?
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: A good firewall working fine in default?

From: Volker Birk <bumens@dingens.org>
Date: Fri Feb 17 2006 - 23:12:14 CET

Poster 60 <ekron@wapda.com> wrote:
> > http://grcsucks.com
> Not with me.

I fear that you don't understand.

> It saved me from a completely destroyed machine three
> months ago. I dealt with one system that just upgraded to XP and the
> firewall had not been activated. There was no AV program either because
> it needed one for XP instead of ME. Three people had used it for 30
> minutes that way trying to install a program and a wireless usb adapter.
> In that time - 30 minutes - ten trojans had been installed (which I
> found out later).

Of course. And ten other malwares, you didn't find. Better turn on the
Windows-Firewall, _before_ connecting to the Internet.

> I activated the firewall when I noticed it was off, then went to
> GRC.com to test it. To my horror it read wide open on the first test,
> file sharing, was able to connect to that system. That also explained
> why I was getting all sorts of popups wanting to connect to places like
> China and other places all over.

Better learn how to configurate and how to use a port scanner.

> Spyboy Search&Destroy was the progream which alerted me to the
> "Security Center" area in the registry and showed what the settings
> should have been. When I tried to reset them correctly the first time,
> it didn't work because the trojans still had control. After I got rid of
> the trojans with NOD32 and Trojanhunter I could reset the registry
> settings and they didn't change.

Please reaD:

http://www.microsoft.com/technet/community/columns/secmgmt/sm0504.mspx

> Once again I tried all the GRC tests and all the ports read secure.
> No more popups either.

Great. No popups. But some trojan horses left, I bet. And another box
being part of a botnet.

Yours,
VB.

-- 
> My windows XP is updated for all critical updates including survive pack 2.
Norman Perry in c.s.f
Received on Mon May 1 00:51:12 2006