CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Stealth??

 
Post new topic   Reply to topic       All -> FavForums -> Firewalls [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
!claire

General
General
Premium Member

Joined: Apr 21, 2002
Posts: 8380

Premium

PostPosted: Sat Aug 03, 2002 9:01 am    Post subject: Stealth??
Reply with quote

Hi,
An intrigating test atwww.isa-llc.com

Back to top
View users profile Send private message
JackBenny

Sergeant
Sergeant


Joined: Jul 12, 2002
Posts: 140
Location: USA

PostPosted: Sat Aug 03, 2002 2:12 pm    Post subject:
Reply with quote

Yeah I've tried it. Here's a few more:

http://keir.net/firehole.html

http://grc.com/lt/leaktest.htm

http://www.testmysecurity.com/index.php

http://www.soft4ever.com/security_test/En/

http://cryptome.org/dirty-antisec.htm

http://tooleaky.zensoft.com/

http://www.hackbusters.net/ob.html

Back to top
View users profile Send private message
!claire

General
General
Premium Member

Joined: Apr 21, 2002
Posts: 8380

Premium

PostPosted: Sat Aug 03, 2002 2:16 pm    Post subject: PC AUDIT
Reply with quote

Hi Jackbenny,
Thank you for the links.BTW did you succesfully past the test?
Regards

Back to top
View users profile Send private message
JackBenny

Sergeant
Sergeant


Joined: Jul 12, 2002
Posts: 140
Location: USA

PostPosted: Sat Aug 03, 2002 2:40 pm    Post subject:
Reply with quote

Yep, passed them all. Most rely on IE to get out, but I use an IE shell (MYIE), with no permissions allowed for IE in my firewall (OutpostPro). That defeats most. I also have a global rule that prevents any DNS resolution, except for what I allow in individual program permissions. That stops them. And last, I use System Safety Monitor, that among other things, can prevent any unauthorized programs or processes from running. That one catches all of them.

Here it is, if you want to have a look:
http://maxcomputing.narod.ru/ssme.html

Back to top
View users profile Send private message
jmn1207

Lieutenant
Lieutenant


Joined: Jun 07, 2002
Posts: 173
Location: USA

PostPosted: Sat Aug 03, 2002 10:09 pm    Post subject:
Reply with quote

Great links! Both of you.

The only problem I ever had with these outbound leak tests is that code was inevitably required to be downloaded and installed by the user. A simple file can be created if allowed to be installed that could turn some people's computers on in the middle of the night and format the entire contents of the disk, not to mention writing itself to piggy back within another trusted application to get through your firewall.

That said, I suppose the greatest threat from this type of vulnerability would be from legitimate software that would be used to spy on you, sending personal data out. A very realistic threat in my opinion.

From what I have seen with the latest versions of ZA+ and Pro, even without component control enabled, the slightest change in the application has required a renewed user acceptance for the program to access the internet. Just adding the Acrobat Reader plug-in to Opera and ZA+ will ask for permission to connect even if I had previously granted permanent permission.

This type of protection evidently can be accomplished without setting rules and limiting your browser to a handful of specific ports and types of packets.

Outbound leak tests have apparently made the firewall developers change the way their products handle this type of threat. For the most part, it appears that they have found a way to defeat this type of security breach. The warnings are there, if only you heed to them.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Firewalls All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer