Re: Windows XP firewall against all others: what's wrong with it?

From: Duane Arnold (notme_at_notme.com)
Date: 06/17/04


Date: Wed, 16 Jun 2004 22:23:22 GMT


"anonimo" <anonimo@anonimo.it> wrote in
news:S6_zc.480287$rM4.19802414@news4.tin.it:

> Hi,
>
> ZoneAlarm 5 crash with eMule.
> Sygate Personal Firewall block my connection when modem adsl
> re-connect
> (so first time is all ok, but if I lost connection and then reconnect,
> no program seems can access to internet).
> Kerio drives me crazy. Each 5 minutes it asks if eMule can accept
> on a
> new port and so on.
>
> I'm bored. I'm using only Windows XP firewall. What's wrong with
> it? Can
> someone tell me a REAL trojan attack this firewall can't block?
>
> Please help.
>
>
>

There is nothing wrong with XP's FW. Currently, the product doesn't have
outbound protection such as application control (stop trojans if you need
that). That will change with the release of SP 2 for XP and it will have
app control. The FW will also be able to get the TCP/IP connection first
at boot as well, which is a vulnerable area for PFW(s) that cannot get
there first.

There is another element on the XP O/S called IPsec which can be used to
supplement the XP FW. IPsec can stop inbound or outbound by port,
protocol or IP.

It's simple to implement with the AnalogX Secpol file.

http://www.petri.co.il/block_ping_traffic_with_ipsec.htm
http://www.analogx.com/contents/articles/ipsec.htm

IPsec is discussed on the XP link.

http://www.uksecurityonline.com/index5.php

You want to watch for Trojans, then use Active Ports (free) and put a
shout-cut for it in the Start-up folder and use it on a routine basis; it
will tell you what is connecting inbound and outbound.

http://www.windowsecurity.com/articles/Hidden_Backdoors_Trojan_Horses_and
_Rootkit_Tools_in_a_Windows_Environment.html

Duane :)



Relevant Pages

  • Re: I am having connectivity problems
    ... firewall and turned ON Windows firewall. ... When I tried to install SP2 I was unable to get it thru Windows Update. ... does the connection problem persist? ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Serious Security Issue in Windows XP SP2s Firewall
    ... Subject: AW: Serious Security Issue in Windows XP SP2's Firewall ... If you update a WinXP SP-1 with enabled Internet ... Connection Firewall ...
    (Focus-Microsoft)
  • RE: Serious Security Issue in Windows XP SP2s Firewall
    ... file and printer sharing is available for network login from any network (I ... Internet Connection Sharing of the PC has to be disabled." ... Serious Security Issue in Windows XP SP2's Firewall ...
    (Focus-Microsoft)
  • Re: Still cant connect to RWW or OWA remotely
    ... No, I don't have a 3rd party firewall, and it's a pretty plain vanilla WinXP ... Connected to the network like the other workstations, ... I could go to any workstation and connect to them just fine. ... match the broadband connection, the two NIC firewall, the remote ...
    (microsoft.public.windows.server.sbs)
  • Re: Big hole??
    ... > firewall then even they can't get in, ... > supposedly safe SP2 for Windows XP invites any Internet ... > Connection Sharing of the PC has to be disabled. ... > in fact is a common configuration and not a rare sight. ...
    (microsoft.public.windowsxp.general)

Loading