Re: Win xp sp2 firewall



Sebastian Gottschalk wrote:
Mr. Arnold wrote:


Volker Birk wrote:

Hexalon <Hexalon@xxxxxxxxx> wrote:


Microsoft would have a lot less security problems if people would stop
running as admins. I really doubt if that is going to happen anytime
soon. People tend to be resistant to change unless change is forced on
them.

Beside that all "Leythos" said is nonsense (as usual from him), the best
way Microsoft could stop people to work as Administrator would be not to
have this as a default.

Well, it's not and there is no sense crying over it. The XP FW does have some issues in it that it will allow FW rules to be set for an application that the end-user has no clue about upon installation of the application.


This requires Administrator rights. And then it applies to any Personal
"Firewall".


I have seen this with some .NET Windows applications that were using .NET remoting that I have developed and installed on XP with the FW active.


Yeah, actually one should be happy that Microsoft offers an explicit
interface for adding appropriate rules.

I am suppose to have some kind if warm and fuzzy felling about that, with MS track record? I don't think so.

For typical PFWs you either have to
use some dirty tricks (while risking that some idiots will scream "HACK
ATTEMPT !!!11")

At most, the application would say that an unauthorized program was trying to access the Internet, that you the user didn't approve. I am not a proponent of Application Control in PFW(s) but at least ask me.

If I don't want to be asked, then I'll disable it. But don't *you* the PFW start making rules, because I installed an application on the computer.

or you'll have to ask the user to add the rules (which
they're usually incapable of).

And MS and its PFW somehow knows the intent and knows the correct decision to make? MS has no business making any rules that the user doesn't know about, period. PFW, will you please prompt someone about what you're about to do?

I don't want MS with some FW to be making any rules without user permission about anything. I would say I don't want this and I would say that most wouldn't want it either.


There is no way that the XP O/S or the XP FW knew the intent of that application good or bad as a client or server. And yet rules were set for the applications to punch through the FW. You name another PFW that allows this kind of rule setting, which is ridiculous.


Any does. By design.

We are not talking about any. We are talking about the XP FW that will set rules dead in your face, if one knew to go check.


Unfortunately, Windows Vista makes it worse on total.

That's what I read.
.



Relevant Pages

  • Re: HP ScanJet 6200C USB Problem
    ... Nach erfolgreicher Installation kann ich den Kerio PFW dann wieder ... Die HP PrecisionScan Pro (HP Scan Software) ... nach Hause telefonieren und verweigerte solange die weitere Installation? ...
    (microsoft.public.de.german.windowsxp.hardware)
  • Re: ActiveSync 4.0.0. stellt keine Verbindung her
    ... Herumdoktorns, mich dazu entschlossen, mein Windows 2000 neu aufzusetzen und dann als erstes die Verbindung zu meinem WM5-PPC über AS 4.1 herzustellen. ... Bei jeder weiteren Installation wurde die ... dass AS keinen Kasperky Virenscanner mag und auch keine Sygate PFW. ...
    (microsoft.public.de.german.windowsce)
  • Re: Der Sinn von Personal Firewalls
    ... Da bringt dann auch 'ne PFW oder AV Software nichts. ... Der gleiche, der es auch bei PFW/AV tut: ... warum mir die Firewall gute ... Da Microsoft inkompetent ist. ...
    (microsoft.public.de.security.heimanwender)
  • Re: Kerio Alternative - mit Verbindungsmanager
    ... > eine PFW MS nicht am Datenversenden hindern kann. ... Exakt, wenn man annehmen würde, dass Microsoft unbemerkt Daten ... Nein, nur in Fachzeitschriften schreiben in der Regel nicht, wie der ... Beispielsweise diskreditierte er die XP-Firewall in einem PFW-Test, ...
    (de.comp.security.firewall)
  • RE: Microsoft Cant Win.
    ... Subject: Microsoft Can't Win. ... What is the use of bringing in a PFW if the user himself ... >>that's regarded as secure ... How many linux admins are keeping up with 1000 - 10,000 linux boxes?? ...
    (Focus-Microsoft)