CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Zone adviser

 
Post new topic   Reply to topic       All -> FavForums -> x-Wall series [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
x-Wall-team

Corporal
Corporal


Joined: Apr 19, 2004
Posts: 50
Location: USA

PostPosted: Sat Sep 18, 2004 2:08 pm    Post subject: Zone adviser
Reply with quote

We are planning a feature in a next version – so-called Zone Adviser.
It will help to users find and set optimal security zone for applications.
As we know users are often confusing with the proper application’s zone setting.
The new feature will include well-known application names (and\or filenames) and the correspondent (best for the application) zone names.
Every time x-Wall detects new application network activity and prompts the user to set proper security zone, zone adviser will search in the internal database and try to advise the most suitable zone.
For that purpose, we are trying to collect your point of view in zone settings for various applications.
Would you share your experience with us in the following form?
Application name, executable name, selected zone.

Your generalized experience will be included in next versions

Thank you

Back to top
View users profile Send private message Visit posters website
ggsearch

Special Response Team
Premium Member

Joined: Feb 09, 2004
Posts: 702
Location: Netherlands
Premium Team F@H

PostPosted: Tue Sep 28, 2004 5:11 am    Post subject:
Reply with quote

Let's create a list... Smile

Application name: Half-Life Launcher
Executable name: hl.exe
Zone: enable all

Application name: Half-Life2 Launcher
Executable name: hl2.exe
Zone: enable all

Application name: Steam
Executable name: Steam.exe
Zone: enable all

Application name: Ports Of Call XXL
Executable name: pocxxl.exe
Zone: enable all

--------------
Application name: b9
Executable name: b9.exe
Zone: enable all

Application name: Mailwasher
Executable name: mailwasher.exe
Zone: enable all

Application name: Total Commander 32 bit international version, file manager replacement for Windows
Executable name: totalcmd.exe
Zone: enable all

----------
Application name: vncviewer
Executable name: vncviewer.exe
Zone: LAN only

Application name: Winamp
Executable name: winamp.exe
Zone: incomming only

Application name: Adobe Reader
Executable name: acrord32.exe
Zone: Disable all

Application name: Messenger
Executable name: msmsgs.exe
Zone: enable all

Application name: MSN Messenger
Executable name: msnmsgr.exe
Zone: enable all

Application name: Trillian
Executable name: trillian.exe
Zone: enable all

Application name: NewsbinPro
Executable name: nbpro.exe
Zone: enable all

Application name: outlook.exe
Executable name: Microsoft Outlook
Zone: enable all

More to come...

How about an export program rules function Wink


_________________
Do something back for CCSP: Donate!
Back to top
View users profile Send private message Visit posters website Yahoo Messenger MSN Messenger
x-Wall-team

Corporal
Corporal


Joined: Apr 19, 2004
Posts: 50
Location: USA

PostPosted: Tue Sep 28, 2004 7:25 am    Post subject: Application-to-zone export
Reply with quote

Thank you for the apps-to-zones list.
Probably I should become acquainted with some of them in more detail.

>How about an export program rules function.
Unfortunately, no (at least in present version).
x-Wall guards processes (not exe files). Exe file is only a file with no possibility of internet access (strictly speaking). So, there is no need to protect it from the internet access.
Of course, each exe file generates a process with correspondent name when you run\launch exe file and process should be protected.
We should use only process name for unique identification of the internet access requester.
However, we know several situations when exe-file name differs from the process it generates or exe file generates several processes. As the result, the result exe-file name is not enough and such export functionality is useless.

Back to top
View users profile Send private message Visit posters website
ggsearch

Special Response Team
Premium Member

Joined: Feb 09, 2004
Posts: 702
Location: Netherlands
Premium Team F@H

PostPosted: Mon Oct 04, 2004 7:28 am    Post subject:
Reply with quote

Should I continu with this list?


_________________
Do something back for CCSP: Donate!
Back to top
View users profile Send private message Visit posters website Yahoo Messenger MSN Messenger
x-Wall-team

Corporal
Corporal


Joined: Apr 19, 2004
Posts: 50
Location: USA

PostPosted: Mon Oct 04, 2004 7:52 am    Post subject: Zone Adviser + something more
Reply with quote

Yes. Thank you
But, please remember the result list (for zone adviser) will contain only well-known application table.
On the other side, security model may differ from user to user. A zone you have chosen for an application (Ex “EnableAll”) might not satisfy another user preferring more complex rule for the application.

Hint of the last week.
There some information sources telling us about DNS leak vulnerability (http://www.firewallleaktester.com).
One of our users advised to use special DNS zone to solve the problem. He restricted svchost access not only with TCP/UDP port 53, but also with IP address of his primary DNS service.
If you want to add secondary DNS server entry – just add second DNS rule.
Later we will add special DNS IP wizard to x-Wall’s zone manager.
Unfortunately the solution is not universal. There could be no svchost or even binary with similar functionality (Win98\WinME). So it would be difficult to automate completely.
If you have a chance to test the method, it would help us to create the feature in the future.

PS 3.0.087 is coming tomorrow

Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> x-Wall series All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer