hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Pages: 1, 2
michael
tried zone alarm and sygate
personally i'd go with sygate
for what i have seen it blocks almost every attack or scan or whatever
blocks things that zonealarm didnt do
s3ntinel
QUOTE (com-techs @ Sep 8 2004, 09:18 PM)
FYI, all firewalls were at default settings. and no rules applied.

you can use the rules and sripts to make intrusion harder.

Aye but did you make sure that the latest and greatest patches were applied before testing?
SoulFly
QUOTE (x303 @ Sep 6 2004, 07:20 AM)
Well, i recommend Sygate Personal Firewall. ..Im using it...
Anyway, its free, and what it does is:

* Protects against Trojans, spyware, worms and other known & unknown threats
* Prevents unauthorized or malicious applications from bypassing the firewall
* Enables even inexperienced users to easily customize and fine-tune security policies
* Provides best of breed evidence logs for intrusion analysis
* Easiest-to-use PC firewall and still free for personal/home use
You can view all Features here: http://smb.sygate.com/products/spf/whatsnew_spf.htm

(any you can download there too) smile.gif
..recently it had one exploit, but i think they released new version after it. Its really good! smile.gif Install it and then take any of those firewall tests! smile.gif

lol!
No it dousnt!
I hacked a puter once with has that firewall!
I run Serv-U server on it
I use it as an dump site
The puter reboots..... and ftp program starts and gets able to work!
Please tell me "Dous the firewall works or not?"

-Fly
3AM
my vote goes for Kerio 2.1.5

Simple too keep it in shape. GUI is excellent, no extra shizzle... its old, but rules still.

Gotta mention 2 fw's that i wouldnt recommend to anyone: Norton personal + zonealarm. Both are simply too horrible to configure and thats the most important part of fw, cause its as good as its rules.
ANORIUS
I would go for norton Internet Security 2003 (not 2004)
or Trend Micro Internet Security.
I tried zonealarm and i hate it (sorry all zonealarm fans)
im currently using the firewall buildt-in my motherboard witch works fine for me
(im useing norton on my old computer)
w33d-m4n
sygate or Tiny Firewall 6.0
Eaglez
McAfee Firewall...pretty KickASS wink.gif
tianzhen
i am still using atguard,
EVIL-INSIDE
Well im using Panda Platinum Internet Security it give u all the things u want
antivirus, firewall every thing It works pretty well & it stops lsass exploit smile.gif
ivanchin99
i use outpost smile.gif very nice interface
zonealarm is bloaty and memory hogging so i dont use it..
kerio and sygate is nice too biggrin.gif
r00t
Hi m8,

I personaly also use @ mom Kerio Firewall.

The only bad thing on it is the GUI !

As AV i use Kapersky Antivirus Personal.
bjn
all the software firewall is not good.....

because torjon Coulds circumvent Firewall easily


By means of that he counterfeits an approval to himself in Firewall
MsMittens
QUOTE(bjn @ Oct 8 2004, 07:46 AM)
all the software firewall is not good.....

because torjon Coulds circumvent Firewall easily


By means of that he counterfeits an approval to himself  in Firewall
*



A trojan can circumvent a hardware firewall as well. It's a question of how well it's been configured and if it's designed to block outgoing traffic. Even then, if the firewall allows any outgoing traffic, regardless of whether it's hardware or software based, the attacker can look for ways to use "legitimate" ports to go out on.

Some software firewalls, like Sygate, are actually pretty decent on this. I'd personally put my vote towards Sygate.


Spookie
Several years back (2000) there was some information floating around about Zone Alarm. A vulnerability was discovered during some testing by a company that develops a trojan horse scanner (DiamondCS).

There was quite a ruckus made about it, and in the end Zone Alarm Upper management sent a reply back after having had 10 weeks notice concerning the vulnerability.

The comments were posted as they were received. I cannot knowingly say the email from then Zone Alarm Preseident Gregor Freund was altered but due to the situation and the continuous postings by various parties I do not recall Zone Alarm refuting the comments.

QUOTE
E-Mail from Gregor Freund, President of Zone Labs
Thanks you for this and your other message. I appreciate the opportunity to address your concerns and apologize for the delay getting back to you - I just came back from a vacation.

Up front: No security is absolute and one hundred percent. This is true for both cyber security as well as the "real world". You can put seat belts in a car, throw in air bags and crush zones and you will still have accidents that you just can't survive. The same principle is true for house or car alarms. Security measures are always a balance between protection, convenience, cost etc. For example I fly small airplanes who have 6-point seat belts which are much better then anything you would find in a car. The reason you don't find them there is that they are inconvenient to put on and restrict your movement so most drivers just wouldn't use them and end up being less secure instead of more. Every security vendor is selling tools to reduce your vulnerability, not to completely eliminate it.

Having said this we set our standard for appropriate security very high. None of the "generic" attacks to break through ZoneAlarm have ever succeeded and believe me, people have tried. In order to compromise a protected system you would have to either break through the integrated firewall or the MailSafe feature in order to run a malicious application on a victim's PC. For the sake of argument let's assume that is possible. If that malicious application then tries to communicate over the Internet (for example to steal your confidential data) we can and will stop it.

That leaves the possibility to attack the ZoneAlarm program itself. We have seen some lab attempts to do this but nothing in the "wild". Of course any of our competitors are subject to the same potential vulnerability. With version 2.1.44 we have changed the software so that even most of those attacks will fail. You still can unload the ZoneAlarm program (there is nothing under Windows that can stop this) but the underlying service will continue to enforce your security settings.

We are currently testing a new version that further improves the security margin. That version will be available towards the end of January. The goal is that ZoneAlarm can not be sabotaged provided that you
- Run on a semi-secure version of Windows (NT, 2000 or Whistler)
- Don't run in administrative mode
- Use the password feature
Under Windows 95/98/ME those margins will be a bit narrower. Please understand that we need the appropriate time to test the new code. Rushing out some pseudo-fix without sufficient quality assurance will have the opposite effect - users would run into all kinds of troubles and might eventually uninstall ZoneAlarm - not exactly an improvement of their online security.

You should also note that any of the potential attacks in this context would succeed with conventional firewalls such as CheckPoint or SonicWall. These products don't have any application-level protection at all and for example they all have to allow outgoing traffic on port 80.

We are extremely proud that we help eight million users to significantly improve their online security and have protected hundreds of thousands of them from serious harm. We take the resulting obligation very seriously and will do everything in our power to continuously improve our products in order to justify the trust of our users.

Best Regards,
Gregor Freund
President, Zone Labs, Inc.


The Forum Broadband Reports forum thread contains most of the information that was being distributed on the mailing list I once belonged to. Being that it was some time ago my memory isnt as good as what it once was. But I hope the information provided will be found informative to the GovSec forum members.

Spookie
belgther
i suggest norton internet security...
it has a nice looking and it can even protect from keyloggers i guess
NuKer
nice reply u guys, interesting stuff, i used Norton inet security 2003 and no probs till now. some1 mentioned combining 2 firewalls to creat a more hermetic defense system and accourding to the replys here sygate and kerio are the leading fw's, so i was wondering if any1 tried installing them both and see if any problems are created by this fusion. hopefully some1 can test this great combo.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.