Security Basics mailing list archives

RE: Personal Firewall for Business use


From: "Dave Swink (dswink)" <dswink () cisco com>
Date: Thu, 30 Oct 2003 12:29:13 -0600

A quality PF will not allow the malware the ability to respond or to
disable the protection. For example, Cisco Security Agent blocks
software downloaded from the network from executing anything at all.

Dave Swink

-----Original Message-----
From: Ansgar -59cobalt- Wiechers [mailto:bugtraq () planetcobalt net] 
Sent: Tuesday, October 28, 2003 4:11 AM
To: security-basics () securityfocus com
Subject: Re: Personal Firewall for Business use


On 2003-10-27 Ivan Hernandez wrote:

[ Windows TCP filtering ]

does not give you application level protections (your recently 
downloaded trojan horse will go to shop on internet freely).

"Application level protection" is ridiculous if the protecting agent is
running on the same box. I keep wondering how people can expect software
that allows user interaction (like most personal firewalls do) to
prevent other (malicious) software from doint whatever it pleases. Why
wouldn't the malware allow itself internet access when the dialog pops
up? Or even disable/replace the PF?

Regards
Ansgar Wiechers

------------------------------------------------------------------------
---
Forum Systems PRESIDIO: PGP / XML GATEWAY APPLIANCE
The Presidio integrates PGP data encryption and XML Web Services
security to 
simplify the management and deployment of PGP and reduce overall PGP
costs 
by up to 80%.
FREE WHITEPAPER & 30 Day Trial - 
http://www.securityfocus.com/sponsor/ForumSystems_security-basics_031027

------------------------------------------------------------------------
----



---------------------------------------------------------------------------
Forum Systems PRESIDIO: PGP / XML GATEWAY APPLIANCE
The Presidio integrates PGP data encryption and XML Web Services security to 
simplify the management and deployment of PGP and reduce overall PGP costs 
by up to 80%.
FREE WHITEPAPER & 30 Day Trial - 
http://www.securityfocus.com/sponsor/ForumSystems_security-basics_031027 
----------------------------------------------------------------------------


Current thread: