Re: BlackICE & SQL Slammer

From: David (davidwnh@adelphia.net)
Date: 01/31/03


From: "David" <davidwnh@adelphia.net>
Date: Fri, 31 Jan 2003 09:09:18 GMT

Mike,
 I tested BI on a laptop with win2k pro. Worked great and I was actually
surprised at how low it's CPU usage was. It did install smoother than any
other personal firewall I have tested. It is not the easiest that I have
seen to configure, but it is not difficult either. Maybe just a little
different from some others. It is great for someone who wants to allow
services open to the internet because of the IDS, but it lacks some outgoing
protection. It does do MD5 digests on "all" executables,dlls etc which is
also a plus as far as downloading malware from the web,etc. is concerned. I
was using a different MD5 application which you could schedule file checks,
but this one is real time so I may use just the application protection since
it doesn't seem to add much to the CPU usage and the firewall lacks some
outgoing functionality that I desire.

You have very limited control of outbound access with BI. You either allow a
program or not. You cannot control which IP's, DNS addresses, or destination
ports that any specific application uses going outbound. Many people using
personal firewalls don't fine tune their application access to this degree
so it wouldn't be a minus for everyone, but for someone who wants to it
falls short. I like to block certain destination ports overall, ie. IRC,
for programs which I don't use. It is also nice to have content management
in which to block specific DNS and IP addresses overall. Only recently are
the other personal firewalls adding this type of feature and hopefully ISS
will follow suit. If ISS adds this functionality and the ability to control
outbound access for apps on a per port and per IP basis in the next version
then will truly have something far above the rest. In any case though, for
someone opening a server to the internet, that server is their big hole, and
the IDS might make BI a better choice even in light of it's shortcomings.
Many of the IDS signatures are for specific vulnerabilities in specific
servers to start with. Overall this product looks good for a home user who
wants to occasionally have a server open to the internet. Otherwise it may
fall short for someone who wants more control over outgoing access.

"Mike" <spamlessmike@spamcop.net> wrote in message
news:7k2h3vk1fud1lk7k0u82mppbsgilof1046@4ax.com...
> David,
>
> Thank you for your informed response. I ran BI in the past. The
> majority of the time it worked fine. Are there issues to be aware of
> with Windows 2K Pro systems? I'd like to install a PF on my Winproxy
> computer.
>
> Mike



Relevant Pages

  • Asp.net Important Topics.
    ... ASP.NET server controls contained within the page. ... A custom server control is ... can also perform validation using client script. ... Where does the Web page belong in the .NET Framework class hierarchy? ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Entwicklung von Unix-Anwendung mit C++ (m/w)/ NRW : Ref.-Nr.: 37302/1
    ... I am responsible for design and implementation of the persistent data server working with mySQL. ... Developed within very short time the product was successfully installed ... Reengineering and implementing a display tool for Experimental Physics Industrial Control System ... Developed an operator interface under X Window for High Energy Physics Accelerator Control System. ...
    (de.markt.arbeit.d)
  • Software engineer
    ... I have a BS in Electrical Engineering and computer science and worked on my ... I have also been involved in hardware design. ... Developed an ATL DCOM based Server and MFC client GUI using Visual C++6.0. ... User can control the data acquisition parameters by modifying the script file. ...
    (FreeBSD-Security)
  • WWWOFFLE - Web proxy with features for dial-up users
    ... The WWWOFFLE programs simplify World Wide Web browsing from computers that use ... The WWWOFFLE server is a proxy web server with special features for use with ... Interactive or command line control of online/offline/autodial status. ... Requests compressed pages from web servers (compile time option). ...
    (comp.os.linux.announce)
  • Re: OWC and Analysis Services (cross-post)
    ... server himself. ... Server B on same domain hosts web-page with the PivotTable control. ...
    (microsoft.public.sqlserver.olap)

Quantcast