Re: The Coalition against Personal Firewalls



Leythos wrote:

In article <447a7400@xxxxxxxxxxxxxxx>, bumens@xxxxxxxxxxx says...
Against this stands for example a simple PoC code of mine, which
simply ignored every "Personal Firewall" on the market and phoned
home.

And you've ignored people that stated your POC failed on their
computers with PFW installed.

What does it mean? Volker's PoC failed on some computers, it successed on
others, so it's still possible to circumvent these PFWs. ...

No, what it means is that it only works on computers that were already
vulnerable and where the user has not followed microsofts instructions
on how to secure the browsers.

No, it hasn't had to do with vulnerabilities. There are multiple built in
mechanism in the Windows OS for inter process communications and so for
remote control applications: Windows Messaging (the only thing, what
breakout.c uses), DCOM, ...

here are some more examples:
windows http://copton.net/Personal_Firewalls/ccc-vortrag-en.html

Instead of this I'd try to test a DNS-tunneler as phone home software.

All the POC code does is show that the user is already vulnerable, and
that they may have improperly configured their PFW as it didn't work on
any of the computers I tried it on.

Tell it Mr. Birk. He'd write a special version of the PoC for you ;-)

Wolfgang

.



Relevant Pages

  • Re: Firewall yes, but where?
    ... > Thanks for the router advice. ... >>I would only run ZA or other PFW until you are secure in your ability to ... >>not on any clients computers, but we monitor the logs daily (import them ... I run a $4000 firewall appliance in my home and in my business. ...
    (comp.security.firewalls)
  • Re: Microsoft Windows Firewall
    ... difference if you uninstall the PFW? ... your's is your opinion and your experience which may not match ... cause a lot of problems and consume much CPU. ... experiences with many computers from many people. ...
    (comp.security.firewalls)
  • Re: Win xp sp2 firewall
    ... PFW, they've all been uncompromised and that ... includes the people with several computers and no NAT router. ... The PFW stops the dumb malware which ...
    (comp.security.firewalls)
  • Help with 070-217
    ... The network contains 25,000 computers. ... single Windows 2000 domain named research.contoso.com. ... Server computers that are configured as domain controllers. ...
    (microsoft.public.cert.exam.mcse)
  • Re: Help with 070-217
    ... The network contains 25,000 computers. ... > single Windows 2000 domain named research.contoso.com. ... > Server computers that are configured as domain controllers. ...
    (microsoft.public.cert.exam.mcse)

Quantcast