Re: [fw-wiz] Personal Firewall Rules

From: Ng Pheng Siong (ngps_at_netmemetic.com)
Date: 07/26/04

  • Next message: Paul D. Robertson: "Re: [fw-wiz] iso 17799"
    To: "Marcus J. Ranum" <mjr@ranum.com>
    Date: Mon, 26 Jul 2004 11:08:20 +0800
    
    

    On Sun, Jul 25, 2004 at 01:56:06PM -0400, Marcus J. Ranum wrote:
    > - if you must allow something incoming allow it only to software
    > you have good reason to trust

    I use Kerio 2.x. It keeps (MD5?) checksums of network-using executables
    (both clients and servers) and warns you "program xxx.exe has changed, do
    you want to continue?" when you replace such a program, e.g., after
    upgrading IE.

    On a consumer Windows box, this might be the right balance between no
    checking of executables and accounting for every file and every registry
    entry a la Tripwire and clones, perhaps coupled with public repositories of
    MD5 digests for "well-known" programs. (I think I saw such a thing before.
    Anyone has a URL handy?)

    Cheers.

    -- 
    Ng Pheng Siong <ngps@netmemetic.com> 
    http://firewall.rulemaker.net -+- Cisco PIX & Netscreen Config Version Control 
    http://sandbox.rulemaker.net/ngps -+- M2Crypto, ZServerSSL for Zope, Blog
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Paul D. Robertson: "Re: [fw-wiz] iso 17799"

    Relevant Pages

    • Re: Spoofing file information?
      ... >>So, if you use md5 to compare files, there are those two critera for being ... around all day in "Internet Caffes", looking for *available* servers out ... there that they can exploit and put their damn IRC scripts there. ...
      (FreeBSD-Security)
    • Re: An attack on MD5
      ... > We have launched a new project "An Attack on MD5". ... > about running the project or helping out with programming the clients, ... I like the idea of attacking MD5, but couldn't you make a more basic ... Mads ...
      (sci.crypt)
    • MD5
      ... I find two thing higly illogical, first is using MD5 in souch matter and the second id definig a variable first time then re-refining it later via array. ... User inputs a password in the registration, MD5 hash is stored in the database, every time user logs on servers generates the hash of the inputed pass and compares... ...
      (alt.php)