Re: Online Armor Firewall?
- From: "bassbag" <bassbag@xxxxxxxxxxxxxxxxxxxxx>
- Date: 9 Dec 2007 20:31:31 GMT
Sebastian G. wrote:
bassbag wrote:
Sebastian G. wrote:
bassbag wrote:
- buffer overflows in the kernel-mode driver due to lackingCan you provide links to this ,and also links to show that the
parameter validation - runs a privileged service with 6
invisible windows, making it vulnerable to shatter attacks
vendor is unwilling to fix this?
Sorry, the 30 days of disclosure time aren't over yet. At any
rate, the windows for the shatter attacks are trivial to see with
Spy++.
Are you referring to matousec or secunia advisorys?
Hm? I haven't seen any of those ever discussing shatter attacks. But
well, Google is your friend. I for one only post public advisories on
Bugtraq, if the vendor fails to address the vulnerabilities
appropriately.
Thats true ,and why many prefer a lyered approach to security in
case one part fails.
"Layered security" is a typical buzzword showing a misinterpretation
of "defense in depth". Vertically stacked independent layers with
enforcable security policies increase security, because breaking the
system requires breaking all intermediate layers. Horizontally
side-by-side layers, as you describe your system, decrease security,
because exploiting just one layer compromises all other layers in the
same security context.
Can you give any software examples of vertically stacked independent
layers with enforcable security policies for the home user on a windows
OS?.
What security would you recommend using such as av
,firewall,hips (if any) etc and what would be your reasons?
AV - none at all, since it doesn't even partially solve any problem
and only introduces new vulnerabilities. A plain virus scanner not
using any privileged service serving as a pure host-based intrusion
detection system might be beneficial,but typically not worth the
effort. And it might also be beneficial as a spam filter, but other
kinds of spam filters are typically much better.
Would you recommend that all users i.e new windows pc users, not use an
av or just those like yourself who has some knowledge
Firewall - depends on your system. I'm quite happy with a small
host-based packet filter enforcing some ingress and egress filtering.
HIPS - are you nuts? An automated solution to DoS yourself...
possibly...
--
.
- Follow-Ups:
- Re: Online Armor Firewall?
- From: Sebastian G.
- Re: Online Armor Firewall?
- From: Mr. Arnold
- Re: Online Armor Firewall?
- References:
- Online Armor Firewall?
- From: louise
- Re: Online Armor Firewall?
- From: Sebastian G.
- Re: Online Armor Firewall?
- From: bassbag
- Re: Online Armor Firewall?
- From: Sebastian G.
- Re: Online Armor Firewall?
- From: bassbag
- Re: Online Armor Firewall?
- From: Sebastian G.
- Re: Online Armor Firewall?
- From: bassbag
- Re: Online Armor Firewall?
- From: Sebastian G.
- Online Armor Firewall?
- Prev by Date: Re: Online Armor Firewall?
- Next by Date: Kerio Personal Firewal 2.1.5 not working ?
- Previous by thread: Re: Online Armor Firewall?
- Next by thread: Re: Online Armor Firewall?
- Index(es):
Relevant Pages
|