Unsolved
This post is more than 5 years old
74 Posts
0
5435
December 24th, 2005 19:00
firewalls blocking incoming only vs. incoming and outgoing traffic
I know this has been brought up before, but sifting through 10 pages of search results didn't answer a question I have about this debate.
What do folks here think about a firewall (such as the native XP) that blocks only inbound traffic, but does nothing about outbound traffic? I keep my computer rather clean from spyware and viruses, and I only have used either a router or XPs firewall (instead of Sygate) for several months now. I have always heard that the main argument against attempting to block outbound traffic is that a worm or trojan or whatever is not going to tell your firewall "Hey Sobig is here! Let me back out!". Instead it is much more likely to camoflauge itself as MS Word or WMP or IE or whatever; in other words, malware will most likely use the programs that you have already given permission to always access the internet.
Comments?
If you have a link to a thread that addresses the question as to whether or not a software firewall can detect a trojan/worm masquerading as IE or Word or whatever, pls feel free to post it, or simply post your thoughts on this issue. Thanks a lot.
What do folks here think about a firewall (such as the native XP) that blocks only inbound traffic, but does nothing about outbound traffic? I keep my computer rather clean from spyware and viruses, and I only have used either a router or XPs firewall (instead of Sygate) for several months now. I have always heard that the main argument against attempting to block outbound traffic is that a worm or trojan or whatever is not going to tell your firewall "Hey Sobig is here! Let me back out!". Instead it is much more likely to camoflauge itself as MS Word or WMP or IE or whatever; in other words, malware will most likely use the programs that you have already given permission to always access the internet.
Comments?
If you have a link to a thread that addresses the question as to whether or not a software firewall can detect a trojan/worm masquerading as IE or Word or whatever, pls feel free to post it, or simply post your thoughts on this issue. Thanks a lot.
No Events found!


psaulm119
74 Posts
0
December 24th, 2005 20:00
What I'm asking for is a consideration of this argument. How realistic is this?
LCDmaster
241 Posts
0
December 24th, 2005 20:00
LCDmaster
241 Posts
0
December 24th, 2005 20:00
psaulm119
74 Posts
0
December 24th, 2005 20:00
I am considering the older Kerio 2.1.5, as the freeware firewalls appear to be going out of style, thanks to Symantec. :(
LCDmaster
241 Posts
0
December 24th, 2005 21:00
psaulm119
74 Posts
0
December 24th, 2005 21:00
1Bowtie
723 Posts
0
December 24th, 2005 21:00
LCDmaster
241 Posts
0
December 24th, 2005 21:00
datapod
2 Intern
•
371 Posts
0
December 25th, 2005 00:00
RoHe
12 Elder
•
45.2K Posts
•
172.6K Points
0
December 25th, 2005 02:00
I use ZoneAlarm instead of Windows firewall, and alerts pop up about all kinds of things attempting to access the net. And no, they're not malware, just Windows components, and app updaters. Not only do I want to control what's being downloaded onto my system, I want to control what's going out across the web too.
Ron
psaulm119
74 Posts
0
December 25th, 2005 05:00
I think I see what you are saying. I recall all the times I updated Mozilla Firefox, and then the firewall would either not let me online, or make me grant permission again. Let's take this scenario of a trojan coming in through a vulnerability in MS Word, WMP, or IE. Kerio or Sygate would detect the new version, and ask me if I want to let WMP through. So far, so good--but I of course would answer yes and the spyware would phone home. Now are you saying that the firewall would see it for what it was (malware) or that it would just tell me that Windows Media Player wants to go out? Because if its the latter, then I'm not sure that an outbound-monitoring firewall would be of much use.
datapod
2 Intern
•
371 Posts
0
December 25th, 2005 10:00
That an applicaton you haven't knowingly changed is suddenly being reported as changed and rerequesting Internet access *is* the warning sign from your firewall. (a reputable application knowingly updated from a trusted source shouldn't be of concern)
I guess I'd have to agree if your response is an unquestioning "but I of course would answer yes" then having a firewall monitoring outbound applications would serve you little purpose. The best security system in the world is of little value if you let anyone who knocks on the door through.
Message Edited by datapod on 12-25-2005 07:45 AM
psaulm119
74 Posts
0
December 25th, 2005 14:00
I think the most significant question at this point would be, have you ever found a trojan or spyware attempting to phone home, masquerading as an MS Word or WMP (or whatever) file?
Message Edited by psaulm119 on 12-25-2005 08:24 AM
datapod
2 Intern
•
371 Posts
0
December 25th, 2005 14:00