Re: I am sick of windows firewall



V S Rawat wrote:
Volker Birk wrote:


V S Rawat <VSRawat@xxxxxxxxxxxx> wrote:

I had uninstalled zone alarm 6.1 free, and gone to xp
firewall a week ago.
But, it seems I am more sick of windows firewall because
programs keep on accessing net without having a mention in
windows firewall. I am using Thunderbird, Firefox, Free
download manager, hamster, and several such software that I
see connecting to net. But, there is not mention of them in
firewall window.

Yes. And this is intended.


Zonealarm was at least having a mention of each program that
was connecting to net.

No. Zone Alarm was tricking you by claiming this - as a matter
of fact, Zone Alarm only shows what it notices - it only
controls, what lets Zone Alarm control it.

So this is useless anyways.


- yesterday, bloody autoupdate downloaded some full 36
updates and I could not find any way of stopping that in
windows firewall.

Better keep your system up to date. A firewall cannot protect
you from every exploit in your operating systems or
applications.

So, Windows-Firewall does a good job here.

Yours,
VB.


Nice to find three die-hard Gates fans in Duane, Sebastian and
Volker.

What's Gates got to do with it?


That does bring some question about basic working of net
connections before I decide upon firewall.

My advice is turn the crap off it's got you paranoid needlessly.


I use Thunderbird as mail reader. It directly connects to net
and fetches mails. Then Why should it not appear in the list of
windows firewall?

Why do you care you know it's legit?

I use Hamster to download my news. It directly connects to net
and fetches newsposts. Then Why should it not appear in the list
of windows firewall?


Both the above are appearing in za.

Why do you care you know it's legit?


Now, I use xananews as my newsreader, but it doesn't connect to
net. it connects to localserver in hamster which has got
downloaded posts, and fetches posts from there.

It is not connecting to net, then why does it appear in za list?
It is not appearing in windows firewall list.

Why do you care you know it's legit.


I use firefox for browsing, it is not appearing in windows
firewall list. it is appearing in za list.

Why do you care you know it's legit?


I use free download manager. it is not appearing in windows
firewall list. it is appearing in za list.

Why do you care you know it's legit?


When I click on a link in metapad (a notepad replacement), that
link should open in firefox. Thus, metapad doesn't directly
connect to net. firefox does.

Why do you care you know it's legit?


In that case, why the hell za asks internet access permission
for metapad?

Why do you care? Why don't you ask Firefox and metapad if it's that much of a concern to you?


hope that will clear the fog and would help me see clearly.

You're being blinded by snake-oil and smoke being put into your eyes.


You are sure using ZA or any personal FW like some kind of a crutch. You should know what's running on your machine and what's accessing the Internet and not a PFW trying to tell you what's going on. By using tools like Active Ports, Process Explore, TCPview and other such tools as needed, one can easily see what is running and accessing the Internet. In addition, tools like Process Explorer and Prcview allow you to drill down into a running process that is accessing the Internet and tell you the program/process that is making the request to the program/process that is accessing the Internet on it's behalf.

Stand on your feet and get off the crutch. You go find out for yourself what's running on the machine with you making some kind of determination as to what is legit to be running on the machine, needs to be assessing the Internet on its own, what it is piggy backing off a running process to access the Internet or what's legit or dubious traffic between your machine and a remote site it may be trying to connect with over the Internet.

In other words, you need to learn what is happening and how to go look for yourself and not use something like ZA or any other personal FW with their worthless Application Control features in the solutions to tell you what is happening on the machine that can easily be circumvented and defeated by malware.

Long

http://www.windowsecurity.com/articles/Hidden_Backdoors_Trojan_Horses_and_Rootkit_Tools_in_a_Windows_Environment.html

Short

http://tinyurl.com/create.php

Let the PFW or personal machine level packet filter (you don't have a FW as it doesn't separate two networks the one it's protecting from and the one it's protecting) do its job of filtering unsolicited inbound packets to the machine or stop outbound packets from leaving the machine for those PFW solutions that you can set outbound packet filtering rules and forget the rest of the worthless sake oil and window dressing in those solutions that can be defeated.

Also, the link below is where you need to be configuring in the protection of the Windows XP O/S that has a direct connection to the Internet and not the PFW solution as it starts and stops with the O/S and not some PFW solution.

http://labmice.techtarget.com/articles/winxpsecuritychecklist.htm

Duane :)






.



Relevant Pages

  • Re: Problems researching in Office (MS Word)
    ... For people who are not inclined to "install" malware, the Windows firewall is adequate. ... Lsuzuki wrote: ... As the error message keeps informing me, the problem is that Word thinks I'm not connected to the internet when I try these research options. ... Even though I am connected to the internet and my firewall allows MS Word to access internet stuff associated with it, I get the following message if I try to research Encarta, eLibrary, Factiva iWorks, or MSN Search: ...
    (microsoft.public.office.misc)
  • Re: Internet Connection Sharing not working (WINXP PRO)
    ... One adapter is connected to the Internet and has a static public IP. ... The second adapter is connected to my second computer using a crossed cable. ... On my HOST computer i enabled Internet connection sharing for my Internet adapter. ... I have turned OFF Windows Firewall on both machines. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Internet Connection Sharing not working (WINXP PRO)
    ... One adapter is connected to the Internet and has a static public IP. ... The second adapter is connected to my second computer using a crossed cable. ... On my HOST computer i enabled Internet connection sharing for my Internet adapter. ... I have turned OFF Windows Firewall on both machines. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Work to Home Computer "Remote Desktop Disconnected"
    ... management to not allow the machine to go into standby. ... > and then try connecting again." ... Turned off all firewalls except for the Windows firewall. ... The home computer has DSL internet access via a Speedster modem. ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: Unable to access internet with MSIE
    ... It is likely that the windows firewall has become active and is blocking ... >I am now unable to access the internet using my portable computer. ... All parameters on examination are normal, (wireless>network connection strength is excellent),etc. ... I uninstalled SP2 and everything ran>normallywith SP2 uninstalled. ...
    (microsoft.public.windowsxp.help_and_support)