jamezzz122
Supreme [H]ardness
- Joined
- Jun 1, 2003
- Messages
- 4,539
I find it annoying and I heard that is causes problems. Should I use it? Do you use it?
Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
GreNME said:While the old one only firewalled incoming connectionsoutgoing was ultimately ignored for the most partthe new one immediately catches outgoing (TCP/IP) connection attempts.
It shouldn't interfere with wireless at all.jamezzz122 said:Nice to hear good things I guess...Does wireless work fine with it? I ask because I am having wireless problems and don't know if the firewall in SP2 was to blame. I still have the problem btw...
topperharley said:Don't be fooled, it only controls how programs respond to incoming connections. It does not have outbound protection like Sygate or Zone Alarm. It's less resource intensive so it works if inbound protection is all you want.
You are the one being fooled, because you don't seem to understand the basic handshake of TCP/IP to understand what I said. Even Sygate and ZoneAlarm work this way. When a program tries to make a TCP connection, it has to try to establish a confirmation link, and this is when the firewall is alerted. If that initial confirmation cannot be verifiedin other words, if the three-way handshake doesn't take placethen no TCP/IP connection happens, meaning the firewall has effectively blocked the attempt of the program to connect to the outside. It's a slightly different technique than ZA, but it's doing basically the same thing.topperharley said:Don't be fooled, it only controls how programs respond to incoming connections. It does not have outbound protection like Sygate or Zone Alarm. It's less resource intensive so it works if inbound protection is all you want.
Whatever floats your boat, but I have some questions: did you ever go in and look at the exceptions list in the firewall settings? Windows Firewall has the ability to catch commonly-used programs and automatically add them to the exclusion list, way better than the pre-SP2 firewall did.odoe said:I was using it at first, but it never, not in the whole week I was using it ever gave me a pop-up while using BT, firefox, playing online games, using my FTP program, nothing not once asked me if I wanted to allow the connection. I had it set to ask, but nope, nothing. So I went back to kerio, which hassles me everytime something connects, but I prefer it that way.
You must not understand how difficult it would be to turn off the firewall now. It's not just some service that can be shut off and not alert the user. Also, assuming it doesn't block programs trying to connect outbound is once again a show of ignorance as to how TCP/IP connects to begin with.m1abram said:This is true, I was very disappointed that they did not include any kind of outbound blocking. However since 99% of windows users run as Admin, which is not really the users fault. Any software firewall is kind of pointless since the user could inadverently run an exe that disables the firewall.
Yes, Apple needs to work on that "run as root" thing too, as does Linspire, as do a vast majority of newer *nix users who can't be bothered to -su into root for certain things.MS really needs to work on pushing the do NOT run as ROOT motto, this is the very basic of computer security. The problem is though not just with MS, so many programs out their assume they are running with root permissions and if you do not they break. Also MS run as user helps but if so many programs require it why bother.
m1abram said:Windows firewall DOES NOT protect outbound connections.
http://comment.zdnet.co.uk/other/0,39020682,39163267,00.htm
http://compnetworking.about.com/od/windowsxpnetworking/a/windowsfirewall.htm
http://forums.us.dell.com/supportforums/board/message?board.id=sw_svcpacks&message.id=278
GreNME - You fail to understand that the windows firewall is STATEFUL, so if you allow outbound traffic it knows that the return traffic is related to the outbound and allows it through.
A simple test is to not allow any firewall exceptions so EVERYTHING is blocked. You will still be able to connect to the web, email, and any game that does NOT require you run the game as a server as most do not.
I already said that 80/8080 were automagically excepted for web browsing. You're grasping at straws now.m1abram said:Interesting that in your screenshot you have nothing that allows HTTP traffic, so how do you browse the web? In fact all the items you allow are local SERVICES which require an outside client to begin the connection.
m1abram said:Their is an incoming and outgoing connection, it is defined by who begins the handshake.
Wanna bet? Note the "trillian" listed in the exceptions list, genius. That's because I connected to the regular AIM server.m1abram said:Bottom line is you can NOT block programs like Mozilla, IE, Outlook etc from connecting to services. You can not block AIM connecting out, you can BLOCK AIM from accepting file transfers and direct connects, but not from connecting to the regular AIM server.
Give me an example of any program or type of connection that will connect in the same way a trojan does, and I will show you how when I put together the little visual debunking of the rest of your ridiculously ignorant claims.m1abram said:If you can not block these types of services, how will it block a trojan from phoning home?
GreNME said:I already said that 80/8080 were automagically excepted for web browsing. You're grasping at straws now.
You really are not getting it. If an outgoing connection attempt cannot complete the handshakewhich is what Windows Firewall preventsthen the connection cannot be made.
Wanna bet? Note the "trillian" listed in the exceptions list, genius. That's because I connected to the regular AIM server.
Give me an example of any program or type of connection that will connect in the same way a trojan does, and I will show you how when I put together the little visual debunking of the rest of your ridiculously ignorant claims.
GreNME said:Do you read your own links? You claimed it doesn't block games, but Flexbeta backed me up showing how it does block games like Doom3. And no installer as of yet can turn off Windows Firewall, so the claim from PCWorld is crappy speculation based on what-ifs.
Being able to search Google does not make you informed. I can search Google and find pages that both support and deny the existence of a god, but neither make it so. QuackViper has his own site, but is filled with horse manure based on crappy reasoning and ignorance about how things work.
*sigh*
I'll explain it to you once I finish the full testing. I'll show youusing screenshots, detailed explanations of protocols, and packet captures using CommViewhow the way SP2 Windows Firewall, while doing things differently than Sygate, Kerio, or ZoneAlarm, is doing the same damn thing and is equally efficient as a firewall.
I love how you keep trying to do the "moving target" defense of your claims.m1abram said:Dude you realise DOOM3 has a server component. But you can still connect connect to other doom servers without allowing DOOM3. Please READ. Or atleast try and find a site to backup your claims.
Do you understand the difference between an app that runs as a Listener and one that does not? And just denying the listening part of say DOOM3 just means you can not run the game server, does not mean you can not run the client.
GreNME said:I love how you keep trying to do the "moving target" defense of your claims.
I already pointed out the 80/8080 built-in exception. Thank you, Mr. Obvious
"What about <list of protocols>?"
As I already stated, if it requires the TCP/IP handshake, then it will be caught, 80/8080 excluded. There are a few e-mail clients that get put on the exception automatically, but anything trying to establish an outgoing session outside of this small list will get caught. Once again, it will be demonstrated.
Um, no. You shouldn't make statements like this unless you've used the software. With firewalls like Sygate all applications including those that do not listen to ports are controlled and the user must grant access. In Sygate you enable "act as server" for applications that need to listen to ports.GreNME said:You are the one being fooled, because you don't seem to understand the basic handshake of TCP/IP to understand what I said. Even Sygate and ZoneAlarm work this way.
GreNME said:"The Register" is a steaming pile of ABM crap.
You are grasping at straws, because each time I point out where your idea is flawed you quick-jump to another subject (or protocol).
So, Mr-3rd-tier "expert," got any ideas for any software you want me to include in the debunking? I already have a list of popular trojans, regular user apps, an smtp program, a few IM clients, and a few games that are going to be showing you how incredibly wrong you are, and I'll be using CommView for the packet traceshope that meets your "professional" requirements.
I'm open to any suggestions, and I'll be testing BT for odoe's sake as well (though he brought it up in a far more reasonable and professional manner than you), but with one caveat: I'm not spending fifty bucks a pop on games just to test, as I already have access to plenty of common games to show what a sham your claims are. Bringing up bullshit like "what about Game A or Game X" as an argument literally ignores the fact that games use common protocols on common port ranges, so covering the general areas will cover "games" just fine. You're just looking for a way to save face by demanding I spend the money you may on games I'll never play. Unlike a majority of people on the [H], I'm not a gamer, I am a network security consultant/admin/business manager/developer (yeah, if you want to play the "my job" pissing contest, I can play along, too).
Um, you're the one who needs to read, because that last quote"When an application that needs to listen on a port or ports is being installed by an administrator, the users must indicate whether if they want to allow the application to open ports in the firewall"is exactly what the hell I've been saying. Unless the USER allows the app, it will not be able to finish making the connection.topperharley said:Um, no. You shouldn't make statements like this unless you've used the software. With firewalls like Sygate all applications including those that do not listen to ports are controlled and the user must grant access. In Sygate you enable "act as server" for applications that need to listen to ports.
Here is the only link you need to read.
Technet: Windows Firewall (SP2)
Scroll down to "Outbound connections" and it very clearly states,
"Windows Firewall will automatically allow all outbound connections, regardless of the program and the user context."
and further down,
"When an application that needs to listen on a port or ports is being installed by an administrator, the users must indicate whether if they want to allow the application to open ports in the firewall."
Give this person a cookie. It works that way with almost all TCP/IP connection attempts, and works on both a port and an application level, covering (with different levels of success) two OSI layers.Riftgarde said:Evil Trojan: I want to send you some cd keys and passwords.
Evil Trojan Data Collector: Ok, I am ready send away.
Windows Firewall: Sorry Evil Data Collector, I'm not letting you talk to the Evil Trojan.
Evil Trojan: Hello? Are you there? hello? I give up.
You missed the point yet again.GreNME said:"When an application that needs to listen on a port or ports is being installed by an administrator, the users must indicate whether if they want to allow the application to open ports in the firewall"is exactly what the hell I've been saying. Unless the USER allows the app, it will not be able to finish making the connection.