Security Basics mailing list archives

Re: Windows 98 box is 'owned'


From: GuidoZ <uberguidoz () gmail com>
Date: Mon, 4 Oct 2004 23:05:04 -0700

I've been going back and forth with Glenn off-list about this. (My
comments would also address Dan Anderson's email.) I'll forward them
to the list for all to read. =)

--
Peace. ~G


On Mon, 04 Oct 2004 15:03:30 -0400, Glenn Sieb <ges () wingfoot org> wrote:
GuidoZ said the following on 10/1/2004 1:15 AM:

While these are all good points, I'd like to make a clarification on one thing.



1)  Complete re-install of the OS with the addition of both a software
firewall (ZoneAlarm) and a Hardware Firewall (Linksys, Dlink, etc).



Linksys, Dlink, etc are routers, not firewalls. While they function
similar to a hardware firewall (providing NAT and blocking the systems
behind them from direct access), they are NOT a substitute for a real
hardware firewall (SonicWall, AlphaShield, etc) when required.
Although, I believe a router would be plenty for your mother. =)

People frequently toss around the term "hardware firewall" (including
vendors), applying it to ANY device that provides NAT translation. In
my eyes, it takes a lot more then NAT to make a firewall. Additional
protection such as SPI, Content filtering, VPN, PKI, etc make up a
true hardware firewall.


Netgear's are firewalls. SPI, NAT, etc.

DLink is also a firewall. I had a DI703 which did SPI.

There *are* just routers that do nothing but NAT--but a lot of these
boxes *do* offer Firewalls as well.

Best,
Glenn

--
"They that can give up essential liberty to obtain a little temporary
safety deserve neither liberty nor safety."
          ~Benjamin Franklin, Historical Review of Pennsylvania, 1759




Current thread: