Re: Ensuring Disabling/Uninstalation of Windows XP Firewall in LAN enviro.

From: Deus, Attonbitus (Thor@HammerofGod.com)
Date: 04/19/02


Date: Fri, 19 Apr 2002 07:48:32 -0700
To: "Nigel Hedges" <evilnigel@iprimus.com.au>, <FOCUS-MS@securityfocus.com>
From: "Deus, Attonbitus" <Thor@HammerofGod.com>


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

At 05:48 PM 4/18/2002, Nigel Hedges wrote:

>Looking up M$ support and the web, I could only find an article pertaining
>to Group Policies and the ability to Prohibit a user being on the domain
>with XP Firewall enabled.
>
>Since this is not an AD environment as yet (NT4 PDC), are there any other
>suggestions as to how they would ensure that XP Firewall is consistently
>disabled or remains uninstalled?

Hi Nigel-

The NETCON_CHARACTERISTIC_FLAGS type will return a value called
NCCF_FIREWALLED to determine in an interface is firewalled or not.
NETCON_CHARACTERISTIC_FLAGS is part of the NETCON_PROPERTIES structure
which is retrieved via the INetconnection::GetProperties method (a function
in HNetCfg library).

Check out the SDK for more info on how to write an app to enumerate this
info.

hth

AD

-----BEGIN PGP SIGNATURE-----
Version: PGP 7.1

iQA/AwUBPMAuQIhsmyD15h5gEQJHHQCgmM+ee7ZqDDXAlKchRoHgD9DciJMAn0+8
3ZSPgEFkV6XMqRjx9Ec434Ku
=3jXA
-----END PGP SIGNATURE-----



Relevant Pages

  • Re: Completely Stumped
    ... If the firewall is completely turned off, ... Do you use Group Policies in your domain? ... Run Resultant Set of Policies for this user on this PC to see ... go down to the client pc and run the netstat -an command. ...
    (microsoft.public.windows.terminal_services)
  • Re: 99.9 % of Software/Hardware Firewalls DO-NOT.....
    ... While you decide to take the easy route and go the TH argument that others have ... thrown out, you still demonstrate a lack of ability to address the real points. ... Pick a firewall, your choice, as I'm sure there's at least ...
    (comp.security.firewalls)
  • Re: Url Block
    ... I would avoid raw sockets. ... most practicle way is to setup a firewall and filter from there. ... can't find a reasonably priced hardware firewall that has this ability - ...
    (microsoft.public.dotnet.languages.vb)
  • New Advanced Firewall Suggestions?
    ... Am I looking for firewall appliance suggestions based on the ... - Proxy/packet filter hybrid firewall technology. ... Ability to use either proxy or packet filter ... - VPN, both IPSEC and PPTP ...
    (comp.security.firewalls)
  • Re: Can a GPO apply after a cached login?
    ... and have group policies updated. ... "Name of Client Side Extension" ... ICMP package to detect a slow link and to connect to a DC is 2KB. ... If the package is fragmented and blocked by the firewall, ...
    (microsoft.public.windows.group_policy)