|
|
|
|
#1 |
|
16-Bit Addicted
Join Date: Apr 2004
Posts: 3,494
|
How secure is Windows XP Firewall?!
![]() I guess, no more words are needed.
My Winamp Info Report Own Projects: | Nullsoft Tray Control Icon Pack v3.1 | Winamp Essentials Pack v5.63a | Winamp Backup Tool v1.0 | >> Winamp Info Tool v4.0 << | German Translations: | Offizielle Deutsche Winamp Sprachdatei v5.63 | Offizielle Deutsche Winamp Sprachdatei Plus Version 5.63 | Useful Winamp Plug-ins: | SNESAmp | 64th Note | NotSo FatSo | in_zip | Highly Experimental PSF Player | Yar Matey! Playlist Copier v1.11 | |
|
|
|
|
|
#2 |
|
Forum King
Join Date: Jul 2001
Location: London
Posts: 5,989
|
![]() Is that Laurel & Hardy I see pulling up at the kerb. UJ |
|
|
|
|
|
#3 |
|
DRINK BEER NOW
(Forum King) |
Shit, I'd be careful with that one. It may have rained the past night, meaning I'd get my pants wet trying to pass through that.
Don't forget to live before you die.
|
|
|
|
|
|
#4 |
|
Forum King
|
Hey, someone needs to pick up the doggy doo in the yard as well. That's a safety hazard.
1001. FM - Megarock Radio - St. Louis Since 1998! Tune In Now! Corporate Radio Sucks! No suits, all rock! |
|
|
|
|
|
#5 |
|
Forum Domo
Join Date: Jan 2004
Location: Everyone, get over here for the picture!
Posts: 4,329
|
XP's firewall isn't any worse than any other software firewall.
If you want real protection you need to sit behind an NAT router. elevatorladyelevatorladyelevatorladyelevatorladyelevatorladylevitateme |
|
|
|
|
|
#6 |
|
\m/
(Forum King) |
it's sure not as good as iptables.
Never underestimate the bandwidth of a station wagon full of tapes hurtling down the highway. |
|
|
|
|
|
#7 |
|
Forum Domo
Join Date: Jan 2004
Location: Everyone, get over here for the picture!
Posts: 4,329
|
ok so...
XP's firewall isn't any worse than any other windows software firewall. elevatorladyelevatorladyelevatorladyelevatorladyelevatorladylevitateme |
|
|
|
|
|
#8 |
|
\m/
(Forum King) |
Except that it doesn't do anything for outbound traffic.
![]() Neither does a NAT router, for that matter. Never underestimate the bandwidth of a station wagon full of tapes hurtling down the highway. |
|
|
|
|
|
#9 |
|
Forum Domo
Join Date: Jan 2004
Location: Everyone, get over here for the picture!
Posts: 4,329
|
No software firewall can fix a compromised system.
Monitoring outbound traffic is for NRA members with carpal tunnel (aka people with a illogical obsesesson for protection who like to close pop-ups). elevatorladyelevatorladyelevatorladyelevatorladyelevatorladylevitateme |
|
|
|
|
|
#10 |
|
\m/
(Forum King) |
It's a symptom of malware infection. If my system had caught some malware and it was phoning home, I'd sure want to know about it.
Never underestimate the bandwidth of a station wagon full of tapes hurtling down the highway. |
|
|
|
|
|
#11 |
|
Forum Domo
Join Date: Jan 2004
Location: Everyone, get over here for the picture!
Posts: 4,329
|
but an outbound-monitoring-firewall is no guarantee you'll know about it (because it too may be compromised)
But you sure are guaranteed to be bothered by any number of legitiment programs you run. Not a particularly valuable trade-off, IMO. elevatorladyelevatorladyelevatorladyelevatorladyelevatorladylevitateme |
|
|
|
|
|
#12 |
|
\m/
(Forum King) |
It's my job to worry about such things.
Never underestimate the bandwidth of a station wagon full of tapes hurtling down the highway. |
|
|
|
|
|
#13 |
|
Forum King
|
I find an outbound monitoring software firewall is good for catching malware trying to phone home, or even non-malware trying to phone home without permission. And it was less of a system strain to run a firewall all the time instead of an Antivirus scanner.
| Brought to you by ^V ^C | |
|
|
|
|
|
#14 |
|
DRINK BEER NOW
(Forum King) |
All of the firewalls I have tried have proven ineffective at blocking fire.
Fucking ripoff. Don't forget to live before you die.
|
|
|
|
|
|
#15 | |
|
Forum King
Join Date: Jan 2002
Location: the nether reaches of bonnie scotland
Posts: 13,378
|
Quote:
|
|
|
|
|
|
|
#16 |
|
Forum King
Join Date: Jun 2003
Location: Milwaukee
Posts: 4,577
|
I run neither a software firewall or anti-virus. Rarely ever have any problems.
|
|
|
|
|
|
#17 |
|
\m/
(Forum King) |
Correct. Good browsing habits will avoid almost any problem. However, it never hurts to be safe.
Never underestimate the bandwidth of a station wagon full of tapes hurtling down the highway. |
|
|
|
|
|
#18 |
|
Forum King
Join Date: Jun 2003
Location: Milwaukee
Posts: 4,577
|
I do a pandascan every 45 months
|
|
|
|
|
|
#19 | |
|
Forum King
Join Date: Jun 2004
Location: Oregon
Posts: 10,593
|
Quote:
If you want to run your computer and don't want to spend $100 a year for virus packages, Firefox is the bullet. Using IE with a virus scanner is possibly risky. Using IE with no virus protection is instant death. Firewalls will stop incoming attacks, but it won't stop an infected computer from transmitting private information. Rather than running the windows firewall I prefer to set the firewall manually in the TCP/IP filter. I trust that more than windows firewall and it's less of a nuisance. And you're right, it's sure not ipchains. This gets really obvious in the windows 2003 server dedicated machine I lease. Global Movies and TV God grant me the serenity to accept the things I cannot change; courage to change the things I can; and wisdom to hide the bodies of people who pissed me off. |
|
|
|
|
|
|
#20 |
|
\m/
(Forum King) |
Server 2003 really is a good OS though. We use it on almost all of the windows servers here and it works very well.
Never underestimate the bandwidth of a station wagon full of tapes hurtling down the highway. |
|
|
|
|
|
#21 | |
|
Forum Domo
Join Date: Jan 2004
Location: Everyone, get over here for the picture!
Posts: 4,329
|
Quote:
elevatorladyelevatorladyelevatorladyelevatorladyelevatorladylevitateme |
|
|
|
|
|
|
#22 |
|
\m/
(Forum King) |
pretty good is a lot better than zero
Never underestimate the bandwidth of a station wagon full of tapes hurtling down the highway. |
|
|
|
|
|
#23 | |
|
Major Dude
Join Date: Apr 2005
Location: Earth
Posts: 756
|
Quote:
|
|
|
|
|
|
|
#25 | |
|
Forum King
Join Date: Jan 2002
Location: the nether reaches of bonnie scotland
Posts: 13,378
|
Quote:
This is a tremendous return on investment for the system resource and training cost. |
|
|
|
|
|
|
#26 |
|
Forum King
Join Date: Jun 2004
Location: Oregon
Posts: 10,593
|
In other words.
Your computer wont notice a firewall in operation. Most users won't notice the firewall software much because they don't run servers. Don't load software when you don't have good reason to trust it. Firewall software doesn't usually require that you know anything. It's not worth it to learn to do this "by hand" for most people. Leave it on, because "pretty good is a lot better than zero" ![]() About the only exceptions you're gonna need from filesharing software is bittorrent type stuff. The temptation will be to switch the firewall off rather than configure it right. Don't. You are broadcasting your IP all over. If you ever needed security software, it's when you are making yourself public, as with gameservers, bittorrent etc. You'd be amazed at how many computers are wide open. Type in their IP and you're looking at their hard disk. No router, no firewall
Global Movies and TV God grant me the serenity to accept the things I cannot change; courage to change the things I can; and wisdom to hide the bodies of people who pissed me off. Last edited by rockouthippie; 29th November 2006 at 02:59. |
|
|
|
|
|
#27 |
|
DRINK BEER NOW
(Forum King) |
^Mine was like that till the computer teacher at my school visited for a get-together last year and bitched me out for it. Now all's well.
Don't forget to live before you die.
|
|
|
|
|
|
#28 | |
|
Forum King
Join Date: Jun 2003
Location: Milwaukee
Posts: 4,577
|
Quote:
|
|
|
|
|
|
|
#29 | |
|
Forum King
Join Date: Jan 2002
Location: the nether reaches of bonnie scotland
Posts: 13,378
|
Quote:
|
|
|
|
|
|
|
#30 |
|
Forum King
Join Date: Jun 2004
Location: Oregon
Posts: 10,593
|
Usually you can print on their printer too.....
For curiousity, I had this program that would scan IP blocks for open windows shares. You wouldn't get through 8 bits of the internet and not find a computer that was sharing stuff that you would figure the owner wouldn't want to share. Without giving a hacking class, the vulnerability zootm mentions here was easily exploitable to gain full control of the machine. But yeah, 2001 would be about right.... some of these holes are probably plugged, even if you were stupid enough not to use a router. Global Movies and TV God grant me the serenity to accept the things I cannot change; courage to change the things I can; and wisdom to hide the bodies of people who pissed me off. Last edited by rockouthippie; 29th November 2006 at 22:27. |
|
|
|
|
|
#31 | ||
|
Forum King
Join Date: Jan 2002
Location: the nether reaches of bonnie scotland
Posts: 13,378
|
Quote:
Quote:
|
||
|
|
|
|
|
#32 |
|
\m/
(Forum King) |
[nitpick]
A real router lets all traffic pass to the IP. Only a NAT router stops unknown traffic. [/nitpick] Never underestimate the bandwidth of a station wagon full of tapes hurtling down the highway. |
|
|
|
![]() |
|
|||||||
| Thread Tools | Search this Thread |
| Display Modes | |
|
|