• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

SP2 firewall...Use it?

jamezzz122

Supreme [H]ardness
Joined
Jun 1, 2003
Messages
4,539
I find it annoying and I heard that is causes problems. Should I use it? Do you use it?
 
I didnt find it annoying; i found zone alarm far more intrusive and annoying to be honest. I ended up using the hardware firewall my nvidia chipset has built in now and turned off the XP one. I think its good that its there though, especially for new computer users.
 
The new firewall (not to be confused with the old one) actually has some nifty features in it. While the old one only firewalled incoming connections—outgoing was ultimately ignored for the most part—the new one immediately catches outgoing (TCP/IP) connection attempts. When it finds one, it pops up an alert, where the user has the option to unblock, keep blocking, or make advanced changes. It's not completely all-inclusive yet , as far as I know (wouldn't catch something like UDP, which doesn't require the TCP handshake), but it's now easily comparable to, say, ZoneAlarm.

I run it at home on my machines now, even though I have a firewall in the router. Also, some clients even have it running, and it still works flawlessly with their programs (from Quicken to high-use financial institution terminal apps).
 
I use it because it seems to work pretty well, isn't really intrusive, if you have even an ounce of knowledge on how to use it, and it's built in...no extra software to load or run.
 
I use it on my wireless connection (which is anywhere I'm on a public network) -- don't bother for wired at home, as I've got a router/firewall already.
 
Nice to hear good things I guess...Does wireless work fine with it? I ask because I am having wireless problems and don't know if the firewall in SP2 was to blame. I still have the problem btw...
 
GreNME said:
While the old one only firewalled incoming connections—outgoing was ultimately ignored for the most part—the new one immediately catches outgoing (TCP/IP) connection attempts.

Don't be fooled, it only controls how programs respond to incoming connections. It does not have outbound protection like Sygate or Zone Alarm. It's less resource intensive so it works if inbound protection is all you want.


jamezzz122 said:
Nice to hear good things I guess...Does wireless work fine with it? I ask because I am having wireless problems and don't know if the firewall in SP2 was to blame. I still have the problem btw...
It shouldn't interfere with wireless at all.
 
I use it at home behind a hardware Linksys router/firewall. I've not had any problems with software I use once I specify it in the exceptions tab.
 
I was using it at first, but it never, not in the whole week I was using it ever gave me a pop-up while using BT, firefox, playing online games, using my FTP program, nothing not once asked me if I wanted to allow the connection. I had it set to ask, but nope, nothing. So I went back to kerio, which hassles me everytime something connects, but I prefer it that way.
 
topperharley said:
Don't be fooled, it only controls how programs respond to incoming connections. It does not have outbound protection like Sygate or Zone Alarm. It's less resource intensive so it works if inbound protection is all you want.

This is true, I was very disappointed that they did not include any kind of outbound blocking. However since 99% of windows users run as Admin, which is not really the users fault. Any software firewall is kind of pointless since the user could inadverently run an exe that disables the firewall.

MS really needs to work on pushing the do NOT run as ROOT motto, this is the very basic of computer security. The problem is though not just with MS, so many programs out their assume they are running with root permissions and if you do not they break. Also MS run as user helps but if so many programs require it why bother.
 
topperharley said:
Don't be fooled, it only controls how programs respond to incoming connections. It does not have outbound protection like Sygate or Zone Alarm. It's less resource intensive so it works if inbound protection is all you want.
You are the one being fooled, because you don't seem to understand the basic handshake of TCP/IP to understand what I said. Even Sygate and ZoneAlarm work this way. When a program tries to make a TCP connection, it has to try to establish a confirmation link, and this is when the firewall is alerted. If that initial confirmation cannot be verified—in other words, if the three-way handshake doesn't take place—then no TCP/IP connection happens, meaning the firewall has effectively blocked the attempt of the program to connect to the outside. It's a slightly different technique than ZA, but it's doing basically the same thing.

odoe said:
I was using it at first, but it never, not in the whole week I was using it ever gave me a pop-up while using BT, firefox, playing online games, using my FTP program, nothing not once asked me if I wanted to allow the connection. I had it set to ask, but nope, nothing. So I went back to kerio, which hassles me everytime something connects, but I prefer it that way.
Whatever floats your boat, but I have some questions: did you ever go in and look at the exceptions list in the firewall settings? Windows Firewall has the ability to catch commonly-used programs and automatically add them to the exclusion list, way better than the pre-SP2 firewall did.

I only ask this because it did ask me about BT and Filezilla. I don't play online games, but try it with a game that wasn't installed before SP2 and see if the results are the same. As for FF, that was probably because it already had 80 or 8080 open.
 
m1abram said:
This is true, I was very disappointed that they did not include any kind of outbound blocking. However since 99% of windows users run as Admin, which is not really the users fault. Any software firewall is kind of pointless since the user could inadverently run an exe that disables the firewall.
You must not understand how difficult it would be to turn off the firewall now. It's not just some service that can be shut off and not alert the user. Also, assuming it doesn't block programs trying to connect outbound is once again a show of ignorance as to how TCP/IP connects to begin with.

MS really needs to work on pushing the do NOT run as ROOT motto, this is the very basic of computer security. The problem is though not just with MS, so many programs out their assume they are running with root permissions and if you do not they break. Also MS run as user helps but if so many programs require it why bother.
Yes, Apple needs to work on that "run as root" thing too, as does Linspire, as do a vast majority of newer *nix users who can't be bothered to -su into root for certain things.

In other words, the only problem I have with what you said is blaming Microsoft alone.
 
Windows Firewall is going to protect users from viruses and worms like msblaster. That was their main goal with WF. To protect the ignorant users who leave their unprotected boxes on broadband lines 24/7. Also, how many average users with dialup connections have a firewall? I would estimate it as none - .006%. How many of them get infected with blaster type worms? TONS. WF is really going to help alleveate these problems, and that's the bottom line IMO. Obviously it's not as good as ZA or Sygate, but it will be a monumental help for the average user.
 
Can someone please explain to me how it is not as good as ZA or Sygate? Tell me what feature these two have that makes them superior?

Anyone claiming the old "inbound vs outbound traffic" thing simply doesn't understand both the ways TCP/IP requires both to connect in the first place, and the changes in the current Windows Firewall that make it so that spurious programs trying to connect out cannot do so without the same verification that ZA requires to begin with.

Guys, I've tested this. Want me to break out the VMWare install, place programs that make outbound connections, and show screenshots?
 
The only thing I added to my exceptions list was port 6881, for my BT, but that was after I was already using it. It didn't seem to effect my speeds since I was already forward ports 6881-6999 on my router. I was surprised, as I was hoping it would ask. The only warnings I got were the balloon warnings before I installed my av.
 
That's very odd, I'll go test it again. It bugged me for it on my main machine, though.
 
Could it have anything to do with being a slipstreamed install?
I do remember Remote Desktop and a couple of others on the exception list. I can check it when I get home.
I wouldn't see anything wrong with it, as it should be a basic firewall. As long as it asks you what to connect and is rules based, then it's doing its job. Kerio and ZA have just added more features on to the firewall package which aren't exactly firewall exclusive. Like pop-up blocking and filechecking. I made the mistake of installing the new kerio and it blocked gmail in firefox because it saw it as a pop-under. You have an exception list in for the XP firewall and the ability to easily add ports to that list. I don't really see what more you need.

BTW, does anyone know how to add port ranges to the XP firewall exceptions? I couldn't quite figure it out without having to add each port individually.
 
I doubt it was because of the slipstreamed install. For the BT client, I would say that it might have something to do with the UDP nature of the packets it sends (meaning it might not be establishing the three-way TCP handshake), but that wouldn't explain why it popped up for me. This is why I'm interested in testing that, because we might be able to nail something like that down, as opposed to something like FF, which is most likely due to the 80/8080 thing.

The file checking thing sounds interesting with ZA (and kerio), and is certainly not a feature Windows Firewall has. But yeah, I was mostly asking about the firewall part of the software, as it seems like all software today seems to try to include other things not specific to the original task when adding features (not a bad thing).
 
Windows firewall DOES NOT protect outbound connections.

http://comment.zdnet.co.uk/other/0,39020682,39163267,00.htm

http://compnetworking.about.com/od/windowsxpnetworking/a/windowsfirewall.htm

http://forums.us.dell.com/supportforums/board/message?board.id=sw_svcpacks&message.id=278

GreNME - You fail to understand that the windows firewall is STATEFUL, so if you allow outbound traffic it knows that the return traffic is related to the outbound and allows it through.

A simple test is to not allow any firewall exceptions so EVERYTHING is blocked. You will still be able to connect to the web, email, and any game that does NOT require you run the game as a server as most do not.
 
m1abram said:
Windows firewall DOES NOT protect outbound connections.

http://comment.zdnet.co.uk/other/0,39020682,39163267,00.htm

http://compnetworking.about.com/od/windowsxpnetworking/a/windowsfirewall.htm

http://forums.us.dell.com/supportforums/board/message?board.id=sw_svcpacks&message.id=278

GreNME - You fail to understand that the windows firewall is STATEFUL, so if you allow outbound traffic it knows that the return traffic is related to the outbound and allows it through.

A simple test is to not allow any firewall exceptions so EVERYTHING is blocked. You will still be able to connect to the web, email, and any game that does NOT require you run the game as a server as most do not.
:rolleyes:

I'm obviously going to have to do the screenshot thing to debunk the ridiculous ignorance going on here. But first, a quick lesson:

Outgoing TCP connections must establish what is called a "three-way handshake" before anything can be sent or received. This means that the sender, the receiver, and the program itself (on both sides) have to negotiate not only the port, but the protocol and the level of communication. People who think that "incoming" and "outgoing" are the modes TCP communication works on are horribly ignorant to the basic fundementals of networking to begin with.

Windows Firewall, unlike the Internet Connection Firewall that preceded it, can now catch the attempt to verify a TCP connection attempt from an unauthorized program on the OS. It does this because it now can catch the return negotiation of the attempt to establish that "three-way handshake." If not confirmed, the handshake never occurs and the connection remains blocked—meaning that whatever the program was trying to connect to cannot connect to the host computer. If confirmed, Windows Firewall creates a nice little exception to the program itself, stored in the exception list in Windows Firewall. Like so:
winfw.jpg


So, the big flaw in the "incoming and outgoing" argument is that it completely ignores the fundementals of TCP/IP networking. Without the original negotiation between two points on a network, a connection cannot be made, hence even programs trying to connect out are blocked. In other words, the semantics behind the "incoming vs outgoing" arguments are pretty much moot in this case.
 
Interesting that in your screenshot you have nothing that allows HTTP traffic, so how do you browse the web? In fact all the items you allow are local SERVICES which require an outside client to begin the connection.

Their is an incoming and outgoing connection, it is defined by who begins the handshake.

Bottom line is you can NOT block programs like Mozilla, IE, Outlook etc from connecting to services. You can not block AIM connecting out, you can BLOCK AIM from accepting file transfers and direct connects, but not from connecting to the regular AIM server.

If you can not block these types of services, how will it block a trojan from phoning home?
 
m1abram said:
Interesting that in your screenshot you have nothing that allows HTTP traffic, so how do you browse the web? In fact all the items you allow are local SERVICES which require an outside client to begin the connection.
I already said that 80/8080 were automagically excepted for web browsing. You're grasping at straws now.

m1abram said:
Their is an incoming and outgoing connection, it is defined by who begins the handshake.
:rolleyes: You really are not getting it. If an outgoing connection attempt cannot complete the handshake—which is what Windows Firewall prevents—then the connection cannot be made.

m1abram said:
Bottom line is you can NOT block programs like Mozilla, IE, Outlook etc from connecting to services. You can not block AIM connecting out, you can BLOCK AIM from accepting file transfers and direct connects, but not from connecting to the regular AIM server.
Wanna bet? Note the "trillian" listed in the exceptions list, genius. That's because I connected to the regular AIM server.

m1abram said:
If you can not block these types of services, how will it block a trojan from phoning home?
Give me an example of any program or type of connection that will connect in the same way a trojan does, and I will show you how when I put together the little visual debunking of the rest of your ridiculously ignorant claims.
 
GreNME said:
I already said that 80/8080 were automagically excepted for web browsing. You're grasping at straws now.


:rolleyes: You really are not getting it. If an outgoing connection attempt cannot complete the handshake—which is what Windows Firewall prevents—then the connection cannot be made.


Wanna bet? Note the "trillian" listed in the exceptions list, genius. That's because I connected to the regular AIM server.


Give me an example of any program or type of connection that will connect in the same way a trojan does, and I will show you how when I put together the little visual debunking of the rest of your ridiculously ignorant claims.


So what outgoing ports do they allow then? IMAP, IMAPS, POP, POPS, SSH, TELNET, ALL UT game ports, ALL FARCRY game ports? Cause they ALL work on my end. Trillian is only listed because it opens a port for listening, which is used for Direct Connects and file transfers, but not to connect to the AIM server.

Read up on Stateful packet filtering, that is how it allows the FULL handshake. Also did you look at the few links I found on google regarding Windows Firewall and outbound. They all confirm what I and others are saying.

Trojans just need to send messages out, some may open up a services but the better ones initiate the connection to bypass firewalls that only guard against incoming connections.

edit: to demonstrate, all programs that cause windows firewall to cause a popup will be listed as state = LISTENING when you do a netstat -ano . That gives you the processid you can find out the exe related to that pid by going to Windows Task Manager->Process make sure you add the column for PID

edit: here is another read to back up my claim
http://www.flexbeta.net/main/articles.php?action=show&id=76&perpage=1&pagenum=2
"Though Windows Firewall has done a pretty decent job at protecting a system from inbound traffic, we could not test for any outbound attacks since Windows Firewall does not worry itself about this. So how important is it for a firewall to block both incoming and outgoing traffic? It is very important. Imagine you install a file and God forbid it contains a Trojan. Windows Firewall will let the Trojan connect and your PC will just be another zombie ready for orders to attack. Another draw back to Windows Firewall is that rival firewall makers claim that the API used to manage the Windows Firewall could also be used by attackers to modify the software or turn it off (http://www.pcworld.com/news/arti...7380,00.asp). At the moment, firewall software makers such as ZoneAlarm are working on an update to their products that will disable Windows Firewall upon install and enable it when uninstalled. But if an installer can switch off Windows Firewall, so could an attacker." Quoted for the lazy

edit: another good read
http://www.huitema.net/sp2-firewall.asp

This one actually goes indepth as to WHY they do not block outgoing connections, which is a good reason. However they should have allowed users to be ABLE to block outgoing if they choose to.
 
Do you read your own links? You claimed it doesn't block games, but Flexbeta backed me up showing how it does block games like Doom3. And no installer as of yet can turn off Windows Firewall, so the claim from PCWorld is crappy speculation based on what-ifs.

Being able to search Google does not make you informed. I can search Google and find pages that both support and deny the existence of a god, but neither make it so. QuackViper has his own site, but is filled with horse manure based on crappy reasoning and ignorance about how things work.

*sigh*

I'll explain it to you once I finish the full testing. I'll show you—using screenshots, detailed explanations of protocols, and packet captures using CommView—how the way SP2 Windows Firewall, while doing things differently than Sygate, Kerio, or ZoneAlarm, is doing the same damn thing and is equally efficient as a firewall.
 
GreNME said:
Do you read your own links? You claimed it doesn't block games, but Flexbeta backed me up showing how it does block games like Doom3. And no installer as of yet can turn off Windows Firewall, so the claim from PCWorld is crappy speculation based on what-ifs.

Being able to search Google does not make you informed. I can search Google and find pages that both support and deny the existence of a god, but neither make it so. QuackViper has his own site, but is filled with horse manure based on crappy reasoning and ignorance about how things work.

*sigh*

I'll explain it to you once I finish the full testing. I'll show you—using screenshots, detailed explanations of protocols, and packet captures using CommView—how the way SP2 Windows Firewall, while doing things differently than Sygate, Kerio, or ZoneAlarm, is doing the same damn thing and is equally efficient as a firewall.


Dude you realise DOOM3 has a server component. But you can still connect connect to other doom servers without allowing DOOM3. Please READ. Or atleast try and find a site to backup your claims.

Do you understand the difference between an app that runs as a Listener and one that does not? And just denying the listening part of say DOOM3 just means you can not run the game server, does not mean you can not run the client.
 
m1abram said:
Dude you realise DOOM3 has a server component. But you can still connect connect to other doom servers without allowing DOOM3. Please READ. Or atleast try and find a site to backup your claims.

Do you understand the difference between an app that runs as a Listener and one that does not? And just denying the listening part of say DOOM3 just means you can not run the game server, does not mean you can not run the client.
I love how you keep trying to do the "moving target" defense of your claims.

"It can't stop IM clients..."

Sure it can.

"Yeah, well, it doesn't stop browsers..."

I already pointed out the 80/8080 built-in exception. Thank you, Mr. Obvious

"What about trojans?"

You have no clue how trojans work. However, for the sake of educating you, I'll be demonstrating how a few of the more popular trojans out there cannot make an outgoing connection.

"What about <list of protocols>?"

As I already stated, if it requires the TCP/IP handshake, then it will be caught, 80/8080 excluded. There are a few e-mail clients that get put on the exception automatically, but anything trying to establish an outgoing session outside of this small list will get caught. Once again, it will be demonstrated.

"Where are your Google links?"

Dude, I don't need to grasp at google-straws to make my claim. I will perform the tests, record the tests (screenshots included), and put the results on my own site, where anyone can go read at their liesure. Get over yourself. Posting loads of links doesn't make you more correct. Actually understanding the fundementals of the things you are talking about—in this case, basic TCP/IP and stateful filtering—makes you more correct. You have demonstrated a significant lack of understanding of the fundementals, but don't worry, because I'll clear it up for you...
 
GreNME - I am not grasping at straws or doing the moving target.

Windows Firewall will NOT block ANY local initated OUTGOING connection.

I have just been trying to explain that to you. You obviously have a much better understand of how IP works, cause I have only been coding various 3tier server archs for the better part of 6 years.

Test my theories and you will see that Windows Firewall acts the way I claim. What you see with Trillian and AIm is just the part of that app that acts like a server (parts that allow Direct Connect and file transfers) block AIM and you will see you can still IM people, you just will have issues with people DirectConnectin to you.

Same with games, you can block the game if you do not plan to run a game server. It will not prevent you from playing on others servers since it DOES NOT block locally initated OUTGOING connections.

Since it does not block locally initated OUTGOING connections then any trojan will work just fine. I do know how trojans work.
 
GreNME said:
I love how you keep trying to do the "moving target" defense of your claims.

I already pointed out the 80/8080 built-in exception. Thank you, Mr. Obvious

"What about <list of protocols>?"

As I already stated, if it requires the TCP/IP handshake, then it will be caught, 80/8080 excluded. There are a few e-mail clients that get put on the exception automatically, but anything trying to establish an outgoing session outside of this small list will get caught. Once again, it will be demonstrated.

So your saying it allows, SSH,IMAPS, IMAP, POP3, POPS3, SMTP, and even imap server that runs on the obscure port of 9143 are in that list. That is a very broad list. Note I have tested this behaviour. I also have tried obsurce mail clients as well with the same obscure ports. I then setup my linux server to respond on ALL ports, and then from my SP2 XP box began to just attempt to telnet to each port. Guess what I was able to connect on EVERYONE I tried. I quit after about 30 attempts.
 
Here is another very good article on SP2.
http://www.theregister.co.uk/2004/09/02/winxpsp2_security_review/

Page two they mention the lack of the outbound(they call it egress) filtering.

They go onto to mention of how SP2s firewall is of no value protecting a user from "malware, spyware, and adware".

And another quote "Nevertheless, Windows users must monitor outgoing connections, and must therefore continue to deploy a third-party firewall or packet filter capable of egress filtering in order to run Windows XP safely."

This is all from "The Register"
 
"The Register" is a steaming pile of ABM crap.

You are grasping at straws, because each time I point out where your idea is flawed you quick-jump to another subject (or protocol).

So, Mr-3rd-tier "expert," got any ideas for any software you want me to include in the debunking? I already have a list of popular trojans, regular user apps, an smtp program, a few IM clients, and a few games that are going to be showing you how incredibly wrong you are, and I'll be using CommView for the packet traces—hope that meets your "professional" requirements.

I'm open to any suggestions, and I'll be testing BT for odoe's sake as well (though he brought it up in a far more reasonable and professional manner than you), but with one caveat: I'm not spending fifty bucks a pop on games just to test, as I already have access to plenty of common games to show what a sham your claims are. Bringing up bullshit like "what about Game A or Game X" as an argument literally ignores the fact that games use common protocols on common port ranges, so covering the general areas will cover "games" just fine. You're just looking for a way to save face by demanding I spend the money you may on games I'll never play. Unlike a majority of people on the [H], I'm not a gamer, I am a network security consultant/admin/business manager/developer (yeah, if you want to play the "my job" pissing contest, I can play along, too).
 
I turned mine of for a few reasons:

1. I'm behind 3 Hardware firewalls

2. I'm also behind 1 software firewall on my server

3. Seems like a lot of people are having trouble and I don't want to take a chance
 
GreNME said:
You are the one being fooled, because you don't seem to understand the basic handshake of TCP/IP to understand what I said. Even Sygate and ZoneAlarm work this way.
Um, no. You shouldn't make statements like this unless you've used the software. With firewalls like Sygate all applications including those that do not listen to ports are controlled and the user must grant access. In Sygate you enable "act as server" for applications that need to listen to ports.

Here is the only link you need to read.

Technet: Windows Firewall (SP2)

Scroll down to "Outbound connections" and it very clearly states,

"Windows Firewall will automatically allow all outbound connections, regardless of the program and the user context."

and further down,

"When an application that needs to listen on a port or ports is being installed by an administrator, the users must indicate whether if they want to allow the application to open ports in the firewall."
 
GreNME said:
"The Register" is a steaming pile of ABM crap.

You are grasping at straws, because each time I point out where your idea is flawed you quick-jump to another subject (or protocol).

So, Mr-3rd-tier "expert," got any ideas for any software you want me to include in the debunking? I already have a list of popular trojans, regular user apps, an smtp program, a few IM clients, and a few games that are going to be showing you how incredibly wrong you are, and I'll be using CommView for the packet traces—hope that meets your "professional" requirements.

I'm open to any suggestions, and I'll be testing BT for odoe's sake as well (though he brought it up in a far more reasonable and professional manner than you), but with one caveat: I'm not spending fifty bucks a pop on games just to test, as I already have access to plenty of common games to show what a sham your claims are. Bringing up bullshit like "what about Game A or Game X" as an argument literally ignores the fact that games use common protocols on common port ranges, so covering the general areas will cover "games" just fine. You're just looking for a way to save face by demanding I spend the money you may on games I'll never play. Unlike a majority of people on the [H], I'm not a gamer, I am a network security consultant/admin/business manager/developer (yeah, if you want to play the "my job" pissing contest, I can play along, too).

Ok you are either a troll or a moron at this point. I have been very calm with you for the most part. I am not sure how much more proof you need on the subject. I do not EXPECT you to buy any game. Nor do you need to use any software for packet traces. If you can make an outgoing connection or block an outgoing connection then you prove or disprove the point.

I have NOT once changed the subject. I have always from my first post said exactly this.

Windows Firewall does NOT block and does not ALLOW one to block ANY locally initated outgoing connection.

That is all. I bring to you MANY articles online from respected sites confirming my claims, you have not brought one single thing that proves yours. I also provide detailed examples of how you can simply test if I am right or not. You have not provided one way to show me how to block a single APP from making an outgoing connection.

Here is a question, if windows firewall can block outgoing ports how can I make it so that I can no longer connect to the web? How can I block port 80 outgoing?

Just read what the text says AROUND the config parts of the firewall. It only speaks about incoming services.
 
You really are being dense. I am not saying it does outgoing packet blocking, I've been saying from the start that the "outgoing vs incoming" argument is fucking stupid. If the connection cannot be negotiated, outgoing packets are not going to happen. What XP Firewall does is not block outgoing packets, it stops connection attempts.

Yes, keep posting links to articles claiming to be explaining it while judging it not on what it does, but what they think it should do. If you think the Reg is reputable, you've pretty much just lost all credibility as far as I'm concerned.

By the way, I'll be using Microsoft as my documentation source, instead of "I heard it on the intarweb" crap you're using.
 
topperharley said:
Um, no. You shouldn't make statements like this unless you've used the software. With firewalls like Sygate all applications including those that do not listen to ports are controlled and the user must grant access. In Sygate you enable "act as server" for applications that need to listen to ports.

Here is the only link you need to read.

Technet: Windows Firewall (SP2)

Scroll down to "Outbound connections" and it very clearly states,

"Windows Firewall will automatically allow all outbound connections, regardless of the program and the user context."

and further down,

"When an application that needs to listen on a port or ports is being installed by an administrator, the users must indicate whether if they want to allow the application to open ports in the firewall."
Um, you're the one who needs to read, because that last quote—"When an application that needs to listen on a port or ports is being installed by an administrator, the users must indicate whether if they want to allow the application to open ports in the firewall"—is exactly what the hell I've been saying. Unless the USER allows the app, it will not be able to finish making the connection.

Why is everyone being so dense?
 
Evil Trojan: I want to send you some cd keys and passwords.
Evil Trojan Data Collector: Ok, I am ready send away.
Windows Firewall: Sorry Evil Data Collector, I'm not letting you talk to the Evil Trojan.
Evil Trojan: Hello? Are you there? hello? I give up.
 
Riftgarde said:
Evil Trojan: I want to send you some cd keys and passwords.
Evil Trojan Data Collector: Ok, I am ready send away.
Windows Firewall: Sorry Evil Data Collector, I'm not letting you talk to the Evil Trojan.
Evil Trojan: Hello? Are you there? hello? I give up.
Give this person a cookie. It works that way with almost all TCP/IP connection attempts, and works on both a port and an application level, covering (with different levels of success) two OSI layers.

Granted, there are basic API references to work with the firewall's boundaries, but the concept works just as well as ZoneAlarm does. It just does it differently.

[edit] As odoe mentioned, there may be non-firewall additions that make one prefer another product, but all I'm talking about here are the firewall properties.
 
I must be eating paint chips in cheerios.
I disabled Kerio, turned on the XP firewall and away I went. Now, at first I missed some things. As it turns out, I found out why I didn't some things and saw others. My BT client is Azureus. It shows in the exceptions list as javaw. Now I installed suns java the same time I installed azureus, so I assumed the javaw on the list was for Suns java, well it isn't it was for Azureus. That one is down. As it turns out, I hadn't used filezilla yet. I installed it, but was still using IE for my ftp. When I fired up a connection on filezilla, I got a warning. Now, it does bother me a bit that no warning came up while using IE, but I suppose it's not a big concern for now. Xfire has the same issue as Azureus, an obscure name in the exceptions list. Miranda IM doesn't seem to need an exception. Part of the problem is my habit of hiding my toolbar and using windows key+d to show my desktop, so I may have missed a couple of pop-ups. It popped up for Steam as well but it did not pop up for UT2K4 or BFV.

So I was mistaken on my part. However, I still prefer the rules based method and allowing what I want to allow as I go along. Even if it just my browser and mail client, and as said before kerio/ZA will tell me if the application has been changed such as after an application upgrade.
 
That's all good, odoe. I still have a terminal app to track down in a bank client of mine in the exceptions list, so I know personally how it's easy to miss at the first glance-over.

As far as the port range thing, this might have something that might help, but I think you may have hit upon something that Microsoft has to work on for the next iteration of the firewall. In fact, I plan on hitting up MSWish as well as bug a few of the local reps here for some answers.

In other words, thanks for bringing that up! :)
 
GreNME said:
"When an application that needs to listen on a port or ports is being installed by an administrator, the users must indicate whether if they want to allow the application to open ports in the firewall"—is exactly what the hell I've been saying. Unless the USER allows the app, it will not be able to finish making the connection.
You missed the point yet again.

*IT WILL ONLY ALLOW THE USER TO BLOCK APPS THAT NEED TO LISTEN TO A PORT*

Do all apps including viruses, trojans, and worms listen to ports when connecting outbound? NO.

Technet: Windows Firewall (SP2)

Scroll down to "Outbound connections" and it very clearly states,

"Windows Firewall will automatically allow all outbound connections, regardless of the program and the user context."
 
Back
Top