Unsolved

This post is more than 5 years old

74 Posts

5435

December 24th, 2005 19:00

firewalls blocking incoming only vs. incoming and outgoing traffic

I know this has been brought up before, but sifting through 10 pages of search results didn't answer a question I have about this debate.

What do folks here think about a firewall (such as the native XP) that blocks only inbound traffic, but does nothing about outbound traffic? I keep my computer rather clean from spyware and viruses, and I only have used either a router or XPs firewall (instead of Sygate) for several months now. I have always heard that the main argument against attempting to block outbound traffic is that a worm or trojan or whatever is not going to tell your firewall "Hey Sobig is here! Let me back out!". Instead it is much more likely to camoflauge itself as MS Word or WMP or IE or whatever; in other words, malware will most likely use the programs that you have already given permission to always access the internet.

Comments?

If you have a link to a thread that addresses the question as to whether or not a software firewall can detect a trojan/worm masquerading as IE or Word or whatever, pls feel free to post it, or simply post your thoughts on this issue. Thanks a lot.

74 Posts

December 24th, 2005 20:00

I said nothing of the kind. What I was asking about what the effectiveness of firewalls that block incoming and outgoing traffic, as opposed to incoming traffic only. I have heard that the difference is almost nil, because of the unlikelihood that a trojan will identify itself to a firewall as a trojan (as opposed to a legitimate program). In this scenario, the firewall would let the trojan communicate with its point of origin, because the firewall thought that it was a legitimate program.

What I'm asking for is a consideration of this argument. How realistic is this?

241 Posts

December 24th, 2005 20:00

Are you saying you cannot access webpages?

241 Posts

December 24th, 2005 20:00

May I ask what kind of fire wll software you have?
 

74 Posts

December 24th, 2005 20:00

LCD, I am currently using Windows Firewall (of course, blocking only inbound). I have used a router for the last several months, but then decided to save a few bucks and use my USB cable to go straight from computer to cable modem. This little change brought to mind the question about the usefulness of firewalls.

I am considering the older Kerio 2.1.5, as the freeware firewalls appear to be going out of style, thanks to Symantec. :(

241 Posts

December 24th, 2005 21:00

Well, You may want to contact DennyDenham, he would know more about it then me. Sorry for the inconvenence.

74 Posts

December 24th, 2005 21:00

N/p LCD. No inconvenience. I will pm him tho--thanks for the suggestion. He's an expert on just about everything isn't he? :)

723 Posts

December 24th, 2005 21:00

When you say you've been using a router for the past few months and decided to save a few bucks, how is that you have already bought the router and there is no cost afterwards. The router is also a firewall in effect as it get the ip address which keeps the comp hidden. I personnally use the Windows firewall and a router and it works just fine, no third party firewalls or antivirus with no probs.

241 Posts

December 24th, 2005 21:00

Uh, He doesn't have PM's turned on.

2 Intern

 • 

371 Posts

December 25th, 2005 00:00



psaulm119 wrote:
I have always heard that the main argument against attempting to block outbound traffic is that a worm or trojan or whatever is not going to tell your firewall "Hey Sobig is here! Let me back out!". Instead it is much more likely to camoflauge itself as MS Word or WMP or IE or whatever; in other words, malware will most likely use the programs that you have already given permission to always access the internet.

Comments?


All the major players now have the ability to track and identify when a previously allowed application has changed and will ask for permission to access the network again to thwart just this sort of scenerio. This functionality becomes evident when you update to a new version of an already installed web aware application (an antispyware or IM application for instance) The first time the new version attempts an outbound connection Kerio, Sygate, EZ, ZA, NIS, McAfee et al.. will pop an "application changed" warning and ask you to set a new rule.

My personal view is I would rather run one (bidirectional firewall) than not. My favorite is Kerio. I notice no perceptable performace hit on a machine with a fast processor and at least 512MB of RAM so there is no reason IMO not to.


12 Elder

 • 

45.2K Posts

 • 

172.6K Points

December 25th, 2005 02:00

You might be surprised at just how many apps are "phoning home" if you don't have a firewall monitoring outgoing traffic. There was a small article in PCWorld this month about what are called "heartbeats", short data pulses many apps send out when you're not looking.

I use ZoneAlarm instead of Windows firewall, and alerts pop up about all kinds of things attempting to access the net. And no, they're not malware, just Windows components, and app updaters. Not only do I want to control what's being downloaded onto my system, I want to control what's going out across the web too.

Ron

74 Posts

December 25th, 2005 05:00


@datapod wrote:



All the major players now have the ability to track and identify when a previously allowed application has changed and will ask for permission to access the network again to thwart just this sort of scenerio. This functionality becomes evident when you update to a new version of an already installed web aware application (an antispyware or IM application for instance) The first time the new version attempts an outbound connection Kerio, Sygate, EZ, ZA, NIS, McAfee et al.. will pop an "application changed" warning and ask you to set a new rule.

My personal view is I would rather run one (bidirectional firewall) than not. My favorite is Kerio. I notice no perceptable performace hit on a machine with a fast processor and at least 512MB of RAM so there is no reason IMO not to.







I think I see what you are saying. I recall all the times I updated Mozilla Firefox, and then the firewall would either not let me online, or make me grant permission again. Let's take this scenario of a trojan coming in through a vulnerability in MS Word, WMP, or IE. Kerio or Sygate would detect the new version, and ask me if I want to let WMP through. So far, so good--but I of course would answer yes and the spyware would phone home. Now are you saying that the firewall would see it for what it was (malware) or that it would just tell me that Windows Media Player wants to go out? Because if its the latter, then I'm not sure that an outbound-monitoring firewall would be of much use.

2 Intern

 • 

371 Posts

December 25th, 2005 10:00



@psaulm119 wrote:

@datapod wrote:



All the major players now have the ability to track and identify when a previously allowed application has changed and will ask for permission to access the network again to thwart just this sort of scenerio. This functionality becomes evident when you update to a new version of an already installed web aware application (an antispyware or IM application for instance) The first time the new version attempts an outbound connection Kerio, Sygate, EZ, ZA, NIS, McAfee et al.. will pop an "application changed" warning and ask you to set a new rule.

My personal view is I would rather run one (bidirectional firewall) than not. My favorite is Kerio. I notice no perceptable performace hit on a machine with a fast processor and at least 512MB of RAM so there is no reason IMO not to.







I think I see what you are saying. I recall all the times I updated Mozilla Firefox, and then the firewall would either not let me online, or make me grant permission again. Let's take this scenario of a trojan coming in through a vulnerability in MS Word, WMP, or IE. Kerio or Sygate would detect the new version, and ask me if I want to let WMP through. So far, so good--but I of course would answer yes and the spyware would phone home. Now are you saying that the firewall would see it for what it was (malware) or that it would just tell me that Windows Media Player wants to go out? Because if its the latter, then I'm not sure that an outbound-monitoring firewall would be of much use.

That an applicaton you haven't knowingly changed is suddenly being reported as changed and rerequesting Internet access *is* the warning sign from your firewall. (a reputable application knowingly updated from a trusted source shouldn't be of concern)

I guess I'd have to agree if your response is an unquestioning "but I of course would answer yes" then having a firewall monitoring outbound applications would serve you little purpose. The best security system in the world is of little value if you let anyone who knocks on the door through.

Message Edited by datapod on 12-25-2005 07:45 AM

74 Posts

December 25th, 2005 14:00

Hmm so you are saying that you don't give permanent "Always" permission to MS Word, WMP, and the lot? That every time you play online content, or click on a link in a word document, etc., you have your firewall request permission? If I'm understanding you correctly, that sounds rather cumbersome to me. Or is it that you do give them permanent permission, but that fact that they have changed (i.e., been modified by a trojan) makes the firewall ask you again--so you would figure out what is going on--is that what you are saying folks should do?

I think the most significant question at this point would be, have you ever found a trojan or spyware attempting to phone home, masquerading as an MS Word or WMP (or whatever) file?

Message Edited by psaulm119 on 12-25-2005 08:24 AM

2 Intern

 • 

371 Posts

December 25th, 2005 14:00

--Responses inline--


psaulm119 wrote:
Hmm so you are saying that you don't give permanent "Always" permission to MS Word, WMP, and the lot? That every time you play online content, or click on a link in a word document, etc., you have your firewall request permission? If I'm understanding you correctly, that sounds rather cumbersome to me.

No that is not what I'm saying. Agreed that would be cumbersome.

 Or is it that you do give them permanent permission, but that fact that they have changed (i.e., been modified by a trojan) makes the firewall ask you again--so you would figure out what is going on--is that what you are saying folks should do?

Yes that is what I'm saying.

I think the most significant question at this point would be, have you ever found a trojan or spyware attempting to phone home, masquerading as an MS Word or WMP (or whatever) file?

No I have not.

Message Edited by psaulm119 on 12-25-200508:24 AM



No Events found!

Top