Re: Slippery intruder -- please advise

From: Lars M. Hansen (badnews_at_hansenonline.net)
Date: 10/03/04

  • Next message: Sahikon: "Re: Javascript Insertion exploits"
    Date: Sun, 03 Oct 2004 07:16:05 -0400
    
    

    On Sun, 03 Oct 2004 02:12:37 GMT, chris@nospam.com spoketh

    >
    >NAT isn't a firewall. By default, though it prevents incoming
    >connections without an existing outgoing connection (which arn't
    >blocked).

    I never claimed that it was. However, that fact remains that many people
    do refer to these types of cheap routers as "firewalls", and since the
    OP doesn't specify what sort of "firewall" he has, we're left to
    speculate.

    >
    >
    >> * Software or personal firewalls could potentially have a rule clash,
    >>one where Skype is allowed to make any outbound connection and one where
    >>all access to a give IP address (or range) is denied. In this case, it
    >>appears that the wrong rule wins (the allow-rule) rather than the more
    >>restrictive (and correct) deny rule...
    >
    >The Windows XP SP2 firewall doesn't block outgoing connections and in
    >fact has some connections open by default. Some personal firewall
    >software is just as useless.
    >

    Again, I never claimed that it did.

    Lars M. Hansen
    http://www.hansenonline.net
    (replace 'badnews' with 'news' in e-mail address)


  • Next message: Sahikon: "Re: Javascript Insertion exploits"

    Relevant Pages

    • Re: What is the Pattern here ?
      ... These are all Dialup Connections that I had no connection with at the time. ... It's obviously an enormous security hole, ... > and a real firewall box. ...
      (comp.security.firewalls)
    • Firewalls That Report / Filter Just Incoming Connections?
      ... Is there a "personal firewall" that does a good job of reporting / filtering ... incoming and outgoing connections that violate the firewall policy? ... failed incoming connections. ...
      (microsoft.public.windows.server.security)
    • Re: Understanding NAT, Firewalls, TCP/IP
      ... They may have a home router firewall, ... > outgoing tcp/ip connections to anything other than port 80 or FTP ... have very strict incoming policy. ... But connections initiated from them (any port) will be allowed, ...
      (comp.lang.java.programmer)
    • Re: Black Ice confesses faulty program!!!
      ... > outgoing connections or traffic except in cases where these connections ... > "dangerous/suspicious" traffic by the BlackICE program. ... > get into your machine then even a PC *without* a firewall is completely ... If you don't think "Spyware" is a problem for computer ...
      (comp.security.firewalls)
    • Re: Port 135
      ... The patch doesn't disable DCOM / RPC, so connections can still be made. ... That's why you need a firewall. ... the patch is not the thing to control ... control over your TCP/IP ports and services, ...
      (microsoft.public.security)