XP firewall

  • Thread starter Thread starter Jim Scott
  • Start date Start date
jo said:
The test app tries to connect out using any open program; they do not
have to be "internet aware".
Was your browser open when you ran the test?

That's it jo, stupid me. Closed my browser and my email-client: passed the
test. Shutdown Kerio and started Zonealarm, same thing, test passed. Ran the
test with both firewalls and my email client open: test failed. Same with
only my browser opened: test failed. So I guess as always not accessing the
inetrnet is the safest way to go.

Rod
 
optikl said:
Practice safe computing and stop worrying about subcontracting your
security to software. If you're not indiscriminately installing
programs, or using unsafe P2P file sharing, what you have should be
perfectly adequate. The usefulness in those leak tests is they point
out the foolishness of putting all of your faith in some firewall to
provide 100% protection.

Well said. I'm not putting all my faith in a firewall, but the fact that I
use one tempers my paranoia a bit, my mind loves the sweet taste of a
placebo.

Rod
 
Andy said:
Mike my ZoneAlarm Pro v 3.7.159 did not pass tooleaky test. What do you
recommend ?

Block IE, close other browsers, disallow outgoing tcp traffic on port
80 for all other apps. :-)
 
Rod said:
I guess his point is what's behind: Components Control (Anti-Leak)

Your language, spelling and perception all seem to be more advanced
than Boomer's
Now we just have to wait for her instructions on configuring Outpost
(free).
I have my apology waiting, but doubt it will be needed. :-)
 
Rod said:
That's it jo, stupid me. Closed my browser and my email-client: passed the
test. Shutdown Kerio and started Zonealarm, same thing, test passed. Ran the
test with both firewalls and my email client open: test failed. Same with
only my browser opened: test failed. So I guess as always not accessing the
inetrnet is the safest way to go.

I like the way the test will try to connect out using your firewall...
 
jo said:
I'm curious about your suggestion that Outpost (free) can be
configured to pass the tooleaky test...

So am I. I know **** all about pooters. I just post random bullshit because
it makes me look impotent.
 
jo said:
I'm curious about your suggestion that Outpost (free) can be
configured to pass the tooleaky test...

Forgot to tell you, even though I'm no good at pooters, I can netKKKop real
well, and I'm really good at abusing newbies for cross-posting, top-posting,
binary-posting and for writing about anything I don't understand, which is
most stuff. This is what I do best...

Hello

Hopefully these will help.


http://home.satx.rr.com/badour/html/post.html
http://www.catb.org/~esr/faqs/smart-questions.html#before
http://www.catb.org/~esr/faqs/smart-questions.html#asking
 
The test app tries to connect out using any open program;
they do not have to be "internet aware".

You are correct, but it still fails UNLESS it's a browser.
Was your browser open when you ran the test?

No. It says to use ANY program. So I take it you
are suggesting that this "test" is just a demonstration
of a browser sending information?
 
°Mike°, after spending 3 minutes figuring out which end of the pen to use,
wrote:
On Mon, 21 Jun 2004 00:13:01 GMT, in
<[email protected]>
Andy scrawled:



I wouldn't take too much stock of that test.

Gonna give a ****ing reason, or just hope everyone believes all the shit you
spew without anything to back it up?
 
°Mike° said:
You are correct, but it still fails UNLESS it's a browser.

Not necessarily. I just let it connect out using notepad, and it did
so quite happily. :-)
No. It says to use ANY program. So I take it you
are suggesting that this "test" is just a demonstration
of a browser sending information?

Partly. I'm not sure how to stop it connecting out if a browser is
open and the browser is allowed to connect out on port 80.
It is also a test of how efficiently you have restricted internet
access to your mail client (for example).

The tooleaky test is substantially sneakier. AFAICS it can connect out
using Internet Explorer, even if IE is closed.

The point here, of course, is that firewalls leak and can be
cirrcumvented so you should never put all your trust in one.
 
Not necessarily. I just let it connect out using notepad,
and it did so quite happily. :-)

Oh, well that's reassuring....
For a start, notepad can't connect out; it seems to
me that this program is just capturing text input
and as well as a screen capture, and pasting it
into the browser. It got my IP address wrong, by
the way, THREE times.
Partly. I'm not sure how to stop it connecting out if a browser is
open and the browser is allowed to connect out on port 80.
It is also a test of how efficiently you have restricted internet
access to your mail client (for example).

The tooleaky test is substantially sneakier. AFAICS it can
connect out using Internet Explorer, even if IE is closed.

No it can't, not in the tests that I have done. If my
browser is closed, it fails EVERY TIME.
The point here, of course, is that firewalls leak and can be
cirrcumvented so you should never put all your trust in one.

Nothing is foolproof, nothing at all. I still don't see that
this test proves anything except that it can capture
input and display it into your browser; browsers give
information out, that's a given.
 
°Mike° said:
For a start, notepad can't connect out

Oh. Well I can only report what I saw, which was notepad being hi
jacked to connect out on port 80. The fact that you say 'it can't;
hardly advances the disccussion.
No it can't, not in the tests that I have done. If my
browser is closed, it fails EVERY TIME.

And here, tooleaky can connect out using IE even if it is closed.
Nothing is foolproof, nothing at all. I still don't see that
this test proves anything except that it can capture
input and display it into your browser; browsers give
information out, that's a given.

And, as I have said a few times, it does not have to be your browser;
it's just that the browser seems to be the softest target.
 
Back
Top