Re: Bypassing Personal Firewalls

From: Zow (zow@llnl.gov)
Date: 02/24/03

  • Next message: Martin Schulze: "[SECURITY] [DSA 253-1] New OpenSSL packages fix timing-based attack vulnerability"
    To: Shaun Clowes <shaun@securereality.com.au>
    Date: Mon, 24 Feb 2003 12:18:39 -0800
    From: "Zow" Terry Brugger <zow@llnl.gov>
    
    

    Shaun,

    While I've just been skimming this discussion, I felt the need to respond to
    one of the points you make:

    > While I can see your point here, from the OS's perspective a user doesn't
    > need to be protected from themselves.

    On the contrary -- process separation is one of the fundamental concepts in
    modern operating systems. If you have the misfortune of remembering the DOS 5
    / Windows 3.0 days, you'll appreciate how important this function is. The
    need to protect the user from something running with their privileges is also
    important for protecting against Trojan horses, such as Outlook-based mail
    worms. The easiest way to protect against such attacks is via sandboxing.

    While I personally would like to see such sandboxing functionality integrated
    directly into operating systems, it can be added via a third-party extension,
    such as Janus for Solaris and Linux, or one of the PFW products for Windows.

    Terry

    use StandardDisclaimer.pm



    Relevant Pages

    • Re: virus in windows system
      ... >> their in my windows operating system help if u can. ... > better protect your Windows system: ... You should at least turn on the built in firewall. ... That's one facet of a secure PC, ...
      (microsoft.public.windowsxp.security_admin)
    • Re: protecting computer
      ... > are 3 steps to protect our computer. ... Microsoft gives you the base guidelines. ... disable your Windows Messenger service. ... by the normal home user and in cooperation with a good firewall, ...
      (microsoft.public.security)
    • Re: Intel VPro
      ... Build a Virtual Machine Monitor (VMM) into the firmware so that the PC ... sysadmin locked down Windows and installed something else and cut them off ... that you have an API to attack and malformed data attacks to try. ... It also doesn't protect against Trojans, by the time it has been executed ...
      (comp.arch)
    • Paul Daniels makes a very valid comment about micro$oft
      ... by the companies that protect and 'cure' them.... ... COMPUTER TIPS - Live OneCare for Windows XP ... Because it's made by Microsoft, the same people that make the Windows XP ...
      (uk.politics.misc)
    • Re: Why does Windows allow Worms?
      ... non-fool for the operating system. ... If Windows were to disappear tomorrow, someone else would inherit all those ... it better and protect themselves better. ... Cedar Park TX 78613-1419 | WFTPD, WFTPD Pro are Windows FTP servers. ...
      (comp.security.misc)