Re: What good is a firewall?

From: Hernán Freschi (hjf.usenet_at_hjf.com.ar)
Date: 04/27/05


Date: Wed, 27 Apr 2005 15:52:19 -0300

Lorenzo wrote:
> I'm doing a paper on home internet security and wanted to ask network
> gurus a couple questions about firewalls:
>
> What is the real benefit of a firewall for a home internet user? If the
> only thing a user does is surf the web and send/receive email. What
> protection does it provide? I know the Windows service port can be a
> target, since it can't be disabled, but that notwithstanding, what does
> a user risk?
Well there is some way that someone might get into your files via SMB,
but thats very unlikely. But now, with the infinity of worms around the
net... Have you heard of blaster? That was a worm which uses a
"vulnerability" in the RPC (remote procedure call) of Windows and makes
the computer to power off. Once and again, every time you connect to the
net. Other worms make your machine a spam server slave.

> I think people see the firewall as a panacea. The problem for most home
> users is not what they block, but what they allow. Email attachments,
> malicious activeX scripts, etc. are the real cuplrits, correct?
Part true. The windows default install (see the paragraph above) is not
secure at all.

> I know that packets arriving at the computer are processed, but if the
> destination port they target has no running service, they're discarded.
No. By default the OS answers "excuse me sir, there is no service
running here". and stuff. when you use linux IPTABLES with a DENY it
does that. If you do a DROP then the packet is silently discarded.

> Of course, DOS attacks can be launched that overwhelm a system but that
> can still happen with a firewall, right?
I don't think so. If the firewall drops packets, then the sending
systems are more likely to stop sending packets at all, because they
will think that either you have a firewall or that your host is down
already, and look for another victim.

> So whats the benefit?

Make a default install of Windows XP not SP1 or SP2 and connect to AOL
(easy target for scanners). Your computer WILL be pwnt in a matter of
hours, if not minutes.

hjf

-- 
Sí esta atascado, fuércelo. Sí se rompe, es que necesitaba ser reemplazado.
http://www.hjf.com.ar/


Relevant Pages

  • Re: Guide to secure installtion of IIS 5
    ... don't forget a well-configured firewall. ... Do not put the computer onto the network or the Internet until after the ... Follow the instructions for hardening Windows and IIS at ... Install all service packs and security fixes from Microsoft and otherwise ...
    (microsoft.public.inetserver.iis.security)
  • Re: Is secedit.exe left by a hacker?
    ... > tested on port 445. ... > I have a Linksys router that I use as a firewall to my ... Secedit.exe is the name of a legitimate Windows file, ... investigate the files on your computer - antivirus with the latest updates ...
    (microsoft.public.win2000.security)
  • Re: Is secedit.exe left by a hacker?
    ... >> tested on port 445. ... >> I have a Linksys router that I use as a firewall to my ... >investigate the files on your computer - antivirus with ... >windows and everything else. ...
    (microsoft.public.win2000.security)
  • Re: How to Maintain an IIS Server?
    ... > server running on a Windows 2000 server. ... before a firewall and antivirus have been installed]. ... open ports; however, this will not identify which program is using the port. ...
    (microsoft.public.inetserver.iis.security)
  • Re: password protection
    ... and cable] and should really consider Windows 2000 / XP. ... sure you're also running antivirus and firewall, ... Internet] to bypass this security. ...
    (microsoft.public.security)