Please login or register.

Login with username, password and session length
Advanced search  

News:

You..Are..Rad

Pages: 1 [2] 3 4   Go Down

Author Topic: Firewalls?  (Read 14215 times)

0 Members and 1 Guest are viewing this topic.

arkabee

  • VIP
  • -=Ray=-
  • *
  • Tiny cans of Dr Pepper: 153
  • Offline Offline
  • Gender: Male
  • Posts: 1280
  • i still hate the new forum software.
    • View Profile
Firewalls?
« Reply #15 on: March 24, 2004, 07:04:50 pm »

Quote from: "Nabubrush drinks (a lot)"
Well, I'll be home in a week and I'll try that. We'll see if we have the internet back - we've had nothing but problems with Qwest, so who knows.


you have dsl, your modem, is it an internal modem (a card that was inserted into the computer) or an external modem?

if external, is it USB, or Network-based (network- the cord plug would look like an extra wide phone cord plug, usb- the cord would look nothing like a phone cord plug.)?
Logged
"God forbid I'd ever be separated from my Duran Duran for a single minute!"
-August West
"Maybe Hanson or the Jonas Brothers might finally lose their shit one day."
-Nabubrush

arkabee

  • VIP
  • -=Ray=-
  • *
  • Tiny cans of Dr Pepper: 153
  • Offline Offline
  • Gender: Male
  • Posts: 1280
  • i still hate the new forum software.
    • View Profile
Firewalls?
« Reply #16 on: March 24, 2004, 07:08:27 pm »

Quote from: "jough"
I would highly recommend against using either Windows XP's built-in firewall OR McAfee Firewall - they cause more trouble than they solve.

The best thing to do is to have your Cable/DSL modem go straight into a hardware firewall and then into a network switch.

The entire solution costs about $250, but it's well worth it.


i'm curisous as to where you get the $250 approximation?  are you including the price of a network-based cable/dsl modem?

i've never been a fan of "walmart el-cheapo" stuff, but the "Netwok Everywhere" "brand" at walmart herebouts is simply rebranded Linksys with less support.  a Nat lan to lan router with 4 port hub or switch (can't remember) is ~~ $50 or so.

have them in use at a couple of places, and they are definitely not bad as a SOHO device.

i completely agree, though, that having a network-based modem and a router is generally better solution, especially from a troubleshooting standpoint or making changes to the pc down the line, etc.
Logged
"God forbid I'd ever be separated from my Duran Duran for a single minute!"
-August West
"Maybe Hanson or the Jonas Brothers might finally lose their shit one day."
-Nabubrush

jough

  • God's Own Dick
  • Administrator
  • Philippe is standing on it.
  • Tiny cans of Dr Pepper: 948
  • Offline Offline
  • Gender: Male
  • Posts: 6871
  • If you've got the time, we've got El Guapo.
    • View Profile
    • poetry archives
Firewalls?
« Reply #17 on: March 24, 2004, 07:45:11 pm »

Quote from: "arkabee"

i'm curisous as to where you get the $250 approximation?  are you including the price of a network-based cable/dsl modem?


No.  People usually either rent them month-to-month or buy them upfront - so I'm not including the hardware that they've already purchased in my estimation.

Figure about $50 for a decent 4-port switch, and about $200 for a decent hardware firewall (sometimes you can get a combo firewall/router/switch but I recommend against it).

You could probably get the firewall cheaper, but again, I wouldn't recommend it.

jough

  • God's Own Dick
  • Administrator
  • Philippe is standing on it.
  • Tiny cans of Dr Pepper: 948
  • Offline Offline
  • Gender: Male
  • Posts: 6871
  • If you've got the time, we've got El Guapo.
    • View Profile
    • poetry archives
Firewalls?
« Reply #18 on: March 24, 2004, 07:46:59 pm »

If you want to check out your own PC to see if you have open ports or vulnerabilities, check out http://grc.com (and click on "Shields Up!").

You can do all kinds of useful scans and probing from that site, and at least will know if you have ports that are open.

CortJstr

  • Moderator
  • Philippe is standing on it
  • Tiny cans of Dr Pepper: 338
  • Offline Offline
  • Gender: Male
  • Posts: 9819
  • Which gives us AN EXCUSE TO DRINK!
    • View Profile
Firewalls?
« Reply #19 on: March 24, 2004, 10:00:17 pm »

Quote from: "Asherdan"
Quote from: "CortJstr"
There are several programs out there that just do port scans to try and get in. A decent router should stop it but I wouldn't rely on it.


Interesting.  I've got three PC's sitting behind a Netgear MR814 at home.  I've questioned the real need to go behind a software firewall as well.

Am I hiding behind the equivalent of a candy-filled toy* here?  Do I really need to 'double-bag' my home junk?

*credit to FJ for that phraseology


Run Shields Up! as Jough recommended. If you get a perfect score (total stealth) then you're probably okay. Unless you also game online or use any P2P software. Because to use them you have to tell your router to open certain ports no matter what comes through.

A software firewall like ZoneAlarm sets up a 2nd line that makes sure that only the programs you specified can talk and/or listen on those ports. This way eMule can accept traffic on port 4662 but some random virus/worm probing your computer on 4662 will be stopped by ZA.

Oh, and totally run Ad-Aware and Spybot S&D at least monthy. More if you do high risk stuff (like P2P).
Logged

slink

  • Moderator
  • Ocular Shenanigans
  • Tiny cans of Dr Pepper: 47
  • Offline Offline
  • Gender: Male
  • Posts: 3051
  • Слінк Ядранко
    • View Profile
    • OMD on MySpace
Firewalls?
« Reply #20 on: March 24, 2004, 10:02:29 pm »

OK.
Erm, lots of activity here.
BlackIce, as I mentioned above, got in bed with Microsoft. So you can't assume that you can block certain things that MS don't want you to. Which sucks!

As for port tweakage, Zone Alarm pro does let you. The new versions of Pro are actually very good, and I find preferable to hardware firewalls, which by their very nature suck. I was having various problems with freeing up individual ports for certain purposes and found the new version of Pro let me do so, with, well I won't say ease for most people.

Oh, and as for Outlook, since I don't know if this was addressed... It's dangerous too. I don't know how well they fixed problems with it, since well, it's MS, but the preview pane and the lack of real options allow it to selfrun macros through HTML emails. This is not good.
I stuck with Eudora, since it allowed text only email (all you should need, though I'm a utilitarian geek), for years, until switching to Thunderbird recently.
More info may be needed on the Outlook issues, since I knew of this problem a year or so ago, and have just laughed at the idea of using it ever since. And this is Express I am talking about at any rate.
Logged
FOOD CHAIN! GET USED TO IT!

jough

  • God's Own Dick
  • Administrator
  • Philippe is standing on it.
  • Tiny cans of Dr Pepper: 948
  • Offline Offline
  • Gender: Male
  • Posts: 6871
  • If you've got the time, we've got El Guapo.
    • View Profile
    • poetry archives
Firewalls?
« Reply #21 on: March 24, 2004, 10:23:06 pm »

Oh, and for the love of god, no matter what e-mail client you use, disable the "preview" pane.  It pretty much just lets scripts run on your computer just by "previewing" the message.

slink

  • Moderator
  • Ocular Shenanigans
  • Tiny cans of Dr Pepper: 47
  • Offline Offline
  • Gender: Male
  • Posts: 3051
  • Слінк Ядранко
    • View Profile
    • OMD on MySpace
Firewalls?
« Reply #22 on: March 24, 2004, 10:58:11 pm »

Quote from: "jough"
It pretty much just lets scripts run on your computer just by "previewing" the message.


And regardless, it's ugly as hell and totally anti-good-UI-practice!
Apparently it was the use of Outlook and the preview pane that caused Valve to let keyloggers at their system and thus free up the possibility of cracking.

But still, the issue with Outlook wasn't fixed like this. It could essentially, at one point at least, have macro scripts run in stealth.
Logged
FOOD CHAIN! GET USED TO IT!

Choop

  • Mod Squad
  • LAZARUS, Tasseled Loafer of the Powerful
  • Tiny cans of Dr Pepper: 1010
  • Offline Offline
  • Gender: Male
  • Posts: 4260
  • www dot at rick and morty dot com www
    • View Profile
Firewalls?
« Reply #23 on: March 24, 2004, 10:59:27 pm »

I don't believe Thunderbird's preview pane ("Message pane") allows any scripting to process. By all means, though, only open it when you're focused on a message you believe to be safe to read. And activate the Junk filters, and train them (by marking any junk or virus-looking mail as junk).
Logged
Nobody exists on purpose; nobody belongs anywhere; everybody's gonna die. Come watch TV?

slink

  • Moderator
  • Ocular Shenanigans
  • Tiny cans of Dr Pepper: 47
  • Offline Offline
  • Gender: Male
  • Posts: 3051
  • Слінк Ядранко
    • View Profile
    • OMD on MySpace
Firewalls?
« Reply #24 on: March 24, 2004, 11:32:59 pm »

Quote from: "Choopernickel"
I don't believe Thunderbird's preview pane ("Message pane") allows any scripting to process.


Indeed, as far as I am aware, it is safe. And it would certainly be an anomaly* on the part of the Moz Foundation to leave such a glaring and obvious error present in their software, particularly when designed from the groundup so recently.


*This of course, does not apply to the slackwristed, assmonkeys at Microsoft.
Logged
FOOD CHAIN! GET USED TO IT!

andalucia

  • Onstad's Left Shoe
  • Tiny cans of Dr Pepper: 2
  • Offline Offline
  • Posts: 1680
    • View Profile
    • http://www.awesomeblurry.com
Firewalls?
« Reply #25 on: March 24, 2004, 11:45:49 pm »

Quote from: "slink"
Moz Foundation




hehehehe.
Logged
goose means greedy

sjlimmer

  • Illegal Ghost Bikes
  • Todd
  • Tiny cans of Dr Pepper: 3
  • Offline Offline
  • Gender: Male
  • Posts: 317
  • Insert witty remark here...
    • View Profile
Firewalls?
« Reply #26 on: March 24, 2004, 11:53:55 pm »

Quote from: "andalucia"
Quote from: "slink"
Moz Foundation




hehehehe.


Yeah, don't you just love the mental image of Morrissey coding away furiously for the safety of our computers?

</tangent>
Logged
"That's because you're a mean drunk, and nobody loves you."

CortJstr

  • Moderator
  • Philippe is standing on it
  • Tiny cans of Dr Pepper: 338
  • Offline Offline
  • Gender: Male
  • Posts: 9819
  • Which gives us AN EXCUSE TO DRINK!
    • View Profile
Firewalls?
« Reply #27 on: March 25, 2004, 01:01:50 am »

Quote from: "arkabee"
CortJstr, if you ever come across a copy of Signal 9's PC Conseal, i'd recommend it to you.  it's learning curve is astronomical compared to the point and click of ZA, but it's entirely customizable with a text editor.  on the flip side, it got bought out by McAfee 3-4 years ago or so, and i'm not really sure how well it would operate with the differences in win2k & Xp's network stacks as opposed to nt4/win9x.  i think i remember it running ok on win2k, but can' be sure.


I'd heard that PC Conceal was a god among firewalls but that MacAfee claimed they aquired it to integrate into and improve their own product. But in reality they just wanted the competition gone because the code bases were so different integration was impossible.

This was in Eric Szulczewski's column, the same place the Sygate firewall was recommended and a source of techological and political blatherings that would make James Lileks plead for mercy.
Logged

Nabubrush

  • Nightlife Mingus
  • VIP
  • Philippe is standing on it
  • *
  • Tiny cans of Dr Pepper: 448
  • Offline Offline
  • Gender: Male
  • Posts: 8782
  • The cat wonders if the camera is a foodstuff.
    • View Profile
    • Intonarumoron
Firewalls?
« Reply #28 on: March 25, 2004, 02:45:36 am »

Quote from: "arkabee"
Quote from: "Nabubrush drinks (a lot)"
Well, I'll be home in a week and I'll try that. We'll see if we have the internet back - we've had nothing but problems with Qwest, so who knows.


you have dsl, your modem, is it an internal modem (a card that was inserted into the computer) or an external modem?

if external, is it USB, or Network-based (network- the cord plug would look like an extra wide phone cord plug, usb- the cord would look nothing like a phone cord plug.)?

Well, I haven't actually seen it because I've been at work, but it's definitely external, and I'm 95% sure it's network-based.

Also, you people may know too much, because this is mostly way above my head. I'm hoping at the end of this someone will boil this down to a simple, three-step procedure for me.
Logged
Never feel that you're out of the loop, because the loop is you. - Platon

CortJstr

  • Moderator
  • Philippe is standing on it
  • Tiny cans of Dr Pepper: 338
  • Offline Offline
  • Gender: Male
  • Posts: 9819
  • Which gives us AN EXCUSE TO DRINK!
    • View Profile
Firewalls?
« Reply #29 on: March 25, 2004, 03:23:51 am »

0) Step 0 is stuff you should've been doing on dial-up anyway: have a virus scanner and update it frequently, use Windows Update (and Office Update, if you have MS Office), don't use the preview pane in e-mail programs, don't use IE if you can help it, and don't open strange attachments or lick people with open wounds.

1) This depends on if you have a router and if so, what brand.

2) Download the free version of ZoneAlarm and install it.

3) Go to www.grc.com and click "Shields Up!" on all ports. The test should come back green and happy. If not come back here for further advice.
Logged
Pages: 1 [2] 3 4   Go Up