Re: Zone Labs Pro question

From: David (davidwnh@adelphia.net)
Date: 03/15/03


From: "David" <davidwnh@adelphia.net>
Date: Sat, 15 Mar 2003 10:05:41 GMT

Thanks again mh...I always call that advanced for some reason...One of these
days I'll
explicitly remember Custom, but I don't use it anymore so I have nothing to
refer to except my aging memory. Oldtimers disease setting in at an early
age or something :)

Anyhow he needs to block them for outbound traffic and they are only blocked
inbound by the normal security level settings. There is no telling whether
this guy has already given some obscure IRC trojan rights under the
application control so he really does need to block those ports going out.
Everyone who doesn't use IRC should explicitly block these to all outbound
traffic because this is what most of the trojans use these days. So even if
they somehow trick the user through the application control they are still
blocked.

> |
> | Hi, thanks a whole lot for this. NetBIOS is disabled but I'm still
> | getting these frequent alerts. Can you tell me how I block outgoing TCP
> | on ports 6665-6669 on ZAP? I went into the Firewall panel, Main tab,
and
> | clicked on the Advanced button but I don't see anything in that dialog
> | that allows me to specify a range of ports to block.
>
> Click on the Custom tab rather than the Advanced tab. Though, you'll
> find based on the verbiage that those ports are implicitly blocked when at
> High security.
>
>