Re: BlackICE config for Kazaa Lite / K++

From: Duane Arnold (notme_at_notme.com)
Date: 02/20/04


Date: Fri, 20 Feb 2004 00:00:43 GMT


"CBP!!!" <nospam@nospam.com> wrote in news:Di9Zb.97$m47.1@newsfe1-win:

> I use Kazaa Lite (K++) and always run it with sharing disabled,
> however, I noticed today that even after a reboot I could not remove a
> file I has downloaded from the "Shared" directory - as K++ was using
> it! Im assuming this is because the file was in fact being shared. I
> have never come accross this problem before - as normally I have my
> BlackICE set to paranoid which I guess has protected me in the past -
> but on this occasion it was set to trusting (as I was using video chat
> on Messenger) and on this setting it only hides ports with services on
> and other ports if it detects a hack attempt - so file sharing via K++
> (since it would be solocited traffic) would not be blocked. My
> question is.... What manual configurations do I need to make to
> BlackICE to ensure that no matter what setting I have BI on, that it
> will never allow any file to be shared via K++ - whilst allowing me
> to still download other users files? I would also welcome feedback
> from Look'n'Stop & Tiny users if they have specific answers how to
> configure their firewalls in this way.
>
>
>

Well, if you're using P2P's then I don't think anything is going to
protect the machine 100% on solicited traffic and you're going to have to
live with that fact, IMHO.

As for using BlackIce, what I like to do is make two Advanced FW rules
for normal operations.

Name: Reject All TCP ports
IP Address: All
Port: 1-66535
Type: TCP
Mode: Reject
Duration: Forever

Name: Reject ALL UDP Ports
IP Address: All
Port: 1-66535
Type: UDP
Mode: Reject
Duration: Forever

I do that so if I go into the DMZ of the router and I am not on Paranoid,
then this insures that BI is still rejecting unsolicited inbound traffic.

Now, for me since my machines are behind a router, I set a rule to ACCEPT
traffic on all ports for my DHCP IP range and (static IP). The ACCEPT in
the rule tells BI to turn on the IDS for the port(s) and start looking.

Name: Linksys DHCP IP(s)
IP Address: 192.168.1.100-192.168.1.110
Port: ALL
Type: IP
Mode: ACCEPT
Duration: Forever

That rule above is turning on the IDS and is looking at the solicited
traffic coming through the router.

So, you can do the same for the P2P inbound port(s) that are being used
by the P2P program, which you can search Google for the application's
inbound ports and/or use Active Ports (free).

Name: P2P port(s)
IP Address: ALL
Port: 2020
Type: TCP or UDP
Mode: ACCEPT
Duration: Forever then MODE: REJECT when you're done.

I think BI really kicks in when it's setting behind another FW
application or an appliance such as a router.

Also, Enable Auto Blocking and Paranoid are set (you may need to adjust
the level) and everything else is disabled on that screen.

You should enable Logging and use VisualIce to review the logs.

Good luck to you on the P2P and know that BlackIce is not a malware
application.

HTH

Duane :)

 

 



Relevant Pages

  • Re: 2 pc network - cant see host files from pc 2 on pc 1
    ... Assuming that you have firewall protection via your internet router try ... workgroup because it will be needed for the network to work correctly. ... see if you can access TCP ports 139 and 445 on computer one of which at ... permissions. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Do I need these services listening?
    ... > first computer that has the modem & router, so I call the second one ... Your Netgear router should connect to the internet. ... Your Netgear router should have the public IP address. ... that if the ports look closed even ...
    (comp.security.firewalls)
  • [VulnWatch] 3Com OfficeConnect Remote 812 ADSL router exposes internal LAN computers ports during ou
    ... ports during outbound and inbound TCP and UDP sessions. ... The 3Com 812 is a widely-deployed router, found in many ISPs ADSL lines. ... for internet access. ...
    (VulnWatch)
  • Re: ATTN Tony Whitmore please
    ... I've not used your router before, but I've just been looking up ... that the router is configured with ports 80 and 23 open on the public ... log into your router using the ARM interface. ... telnet and http access to just your local network. ...
    (comp.security.firewalls)
  • Re: ISA 2004 - How to allow Guest and Client access from wireless
    ... peace and quiet here are great for working; it's just the darn internet ... access and now wireless that are a pain in the rear. ... That could plug into another port on the router. ... The router has 4 "internal" ports; one is taken up by the cable ...
    (microsoft.public.windows.server.sbs)