I've come across a few windows exploits which were defeated
by a firewall before they were eventually patched.
As are many spyware apps and probably some trojans etc.
(I've removed a few supposed freeware apps after my
firewall has caught them sending out data.)
Here is a current example - a demo IE exploit
(or any other app that supports WebBrowser control >=5.5)
Warning clicking this link from a vulnerable app downloads
mal-ware.exe to the desktop and runs it.
It will however produce an outgoing firewall alert for
MSHTA.exe.
http://www.malware.com/greymagic.html
No doubt like me you already have this issue covered,
but many windows 98 users won't.
But it's basically a wrong headed approach. You should address browser
vulnerabilities and exploits in the first place. Eradicating IE and
using Mozilla or one of its cousins is the way to address these
issues. Similarly, OE should be replaced with sane apps designed with
security in mind such as Pegasus and Free Agent.
The freeware firewalls leak like a sieve and cannot be depended on to
alert you to malicious apps trying to call out. The idea is to not let
malicious code to run in the first place since it can do as it wishes
and disable your software "protection". And I know it can be done in
practice since I've been doing it for years.
Firewalls shouldn't be depended on to protect you from malformed
packets and DOS attacks either. Win 98 and ME with all critical OS
patches pass the Exploits tests at PC Flank just fine. Back when I was
testing the freeware firewalls, I found that unpatched Win 98 was
vulnerable but Kerio in particular didn't mask the problem in the OS.
So again, it's an issue of addressing the basic problems rather than
hoping to mask them with additional software which might add it's own
new set of vulnerabilities.
In my view, only after you've done the "hardening" I've mentioned
might you consider adding additional software "protection". I like to
keep Sygate on hand since I like its traffic log. But I rarely use it
any more. No need for it. I do keep AdAware and Spybot up to date just
in case, but they never find anything either. Neither do my three DOS
antivirus scanners.
Art
http://www.epix.net/~artnpeg