Search Members Help

» Welcome Guest
[ Log In :: Register ]

Page 1 of 212>>

[ Track This Topic :: Email This Topic :: Print this topic ]

reply to topic new topic new poll
Topic: Personal Firewalls and Windows< Next Oldest | Next Newest >
 Post Number: 1
Observer Search for posts by this member.
I once watched, but I have left.
Avatar



Group: Members
Posts: 912
Joined: May 2000
PostIcon Posted on: Oct. 11 2001,23:03  Skip to the next post in this topic. Ignore posts   QUOTE

So I was chatting with someone and they mentioned that they run a firewall to keep the kiddies out of their box. It got me thinking, why run a personal firewall if:


  • You aren't serving anything (HTTP, FTP, SSH, File & Print Shares, etc.)
  • NetBIOS is disabled (or just doesn't reveal any useful info)
  • You don't run trojans/spyware.
  • You are the only one who uses your computer.

If those criteria are met, isn't a personal firewall just a waste of resources? Other than a ping flood, what could a person gain by portscanning your computer?

Now I realize with NT/2K there are some ports that would have to be blocked, but I wondered what all your experience has led you to believe.

------------------
When 1337 hax0rs start impaling each other with swords and typing code with a hook on one hand, then they can modify the term "pirate."

Offline
Top of Page Profile Contact Info 
 Post Number: 2
MattimeoZ80 Search for posts by this member.
Purveyor of Untimely Wisdom
Avatar



Group: Members
Posts: 397
Joined: Nov. 2000
PostIcon Posted on: Oct. 11 2001,23:14 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

i run zonealarm "just in case" (tm). i don't know, even if they can't hack, i still wouldn't want to be on a list of computers that can be pinged. zonealarm hasn't interfered with anything so far; you can set what programs can receive incoming connections and whatnot, and best of all its free.
Offline
Top of Page Profile Contact Info WEB 
 Post Number: 3
CatKnight Search for posts by this member.
Jedi Republican
Avatar



Group: Members
Posts: 3807
Joined: Dec. 2000
PostIcon Posted on: Oct. 11 2001,23:31 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

zonealaram is useful for preventing some programs from having internet access (like windvd...why the fuck does windvd need to connect to the internet?). Unfortunately it is really useless otherwise because programs can still do stuff you don't want them to do. For example, in order to surf the web you have to give access to win32 services. other programs can use it to get out, bypassing zone alarm. it can't distunguish from legitimate uses and harmful stuff within a program.
Offline
Top of Page Profile Contact Info WEB 
 Post Number: 4
askheaves Search for posts by this member.
Ack!!!
Avatar



Group: Members
Posts: 1955
Joined: Sep. 2000
PostIcon Posted on: Oct. 12 2001,00:07 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

I have ISA set up on my server computer, with all ports wide open, no patches installed, and directly connected to the internet. I think it's time I learn something about networking.
Offline
Top of Page Profile Contact Info 
 Post Number: 5
Beldurin Search for posts by this member.
Mayor of Detnet
Avatar



Group: Members
Posts: 1242
Joined: Aug. 2001
PostIcon Posted on: Oct. 12 2001,14:04 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

quote:
Originally posted by askheaves:
I have ISA set up on my server computer, with all ports wide open, no patches installed, and directly connected to the internet. I think it's time I learn something about networking.

lol...naw, you sound a lot like the network admin at my last job.

Personally, I run my house behind a linux router which acts as a pseudo firewall. I just disabled ftp and telnet on it, installed ssh, set the hosts.deny to all and the hosts.allow to a set list if IP's that I could possibly be connecting from (work, my friend's house, etc.). This works well enough for me.

------------------

quote:
Originally posted by Dark-Angel99:
How come {name removed} doesn't like you? I find you really funny :D


Never argue with an idiot...he may be doing the same thing

Offline
Top of Page Profile Contact Info WEB 
 Post Number: 6
incubus Search for posts by this member.
mack daddy
Avatar



Group: Admins
Posts: 1316
Joined: May 2000
PostIcon Posted on: Oct. 12 2001,21:45 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

Do you run ipchains too?
Offline
Top of Page Profile Contact Info WEB 
 Post Number: 7
Spydir Search for posts by this member.
proof that humans suck (www.netsyndrome.net)
Avatar



Group: Members
Posts: 1089
Joined: Apr. 2001
PostIcon Posted on: Oct. 12 2001,22:54 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

iptables! natd! nt connection sharing! wait...

------------------
Net Syndrome - www.netsyndrome.net
Catch The Sickness

Offline
Top of Page Profile Contact Info WEB 
 Post Number: 8
Beldurin Search for posts by this member.
Mayor of Detnet
Avatar



Group: Members
Posts: 1242
Joined: Aug. 2001
PostIcon Posted on: Oct. 13 2001,02:31 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

quote:
Originally posted by incubus:
Do you run ipchains too?

But of course.

------------------

quote:
Originally posted by Dark-Angel99:
How come {name removed} doesn't like you? I find you really funny :D


Never argue with an idiot...he may be doing the same thing

Offline
Top of Page Profile Contact Info WEB 
 Post Number: 9
askheaves Search for posts by this member.
Ack!!!
Avatar



Group: Members
Posts: 1955
Joined: Sep. 2000
PostIcon Posted on: Oct. 13 2001,04:18 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

quote:
Originally posted by incubus:
Do you run ipchains too?

If it's a default setting for ISA, then I'm running it baby!

Offline
Top of Page Profile Contact Info 
 Post Number: 10
Beldurin Search for posts by this member.
Mayor of Detnet
Avatar



Group: Members
Posts: 1242
Joined: Aug. 2001
PostIcon Posted on: Oct. 13 2001,04:22 Skip to the previous post in this topic.  Ignore posts   QUOTE

quote:
Originally posted by askheaves:
If it's a default setting for ISA, then I'm running it baby!

Wait, by ISA do you mean MS's ISA? (Internet Security and Acceleration Server) If so, then you're NOT running ipchains...it's a UNIX/Linux feature that you use for IP forwarding, etc.

------------------

quote:
Originally posted by Dark-Angel99:
How come {name removed} doesn't like you? I find you really funny :D


Never argue with an idiot...he may be doing the same thing

Offline
Top of Page Profile Contact Info WEB 
11 replies since Oct. 11 2001,23:03 < Next Oldest | Next Newest >

[ Track This Topic :: Email This Topic :: Print this topic ]


Page 1 of 212>>
reply to topic new topic new poll

» Quick Reply Personal Firewalls and Windows
iB Code Buttons
You are posting as:

Do you wish to enable your signature for this post?
Do you wish to enable emoticons for this post?
Track this topic
View All Emoticons
View iB Code