RE: Linux vs Windows Firewalls

"Ridgeway, Alan" <[email protected]>
Newsgroups gmane.linux.usability.annoyances
Message-ID <[email protected]>
It sounds like there may be some confusion here.

>it seems that if you accept packets on, for example, port 80, then -any program- can communicate on 
port 80

It sounds like you are talking about running a server (like a web server) on port 80.
If that is the case, then assigning a program name does not give you anything extra.
If the web server is listening on port 80, then no other program on that machine can 
listen on port 80. 

Now if you are talking about a client going over the Internet to reach a server on port 80
then I think what you are saying is the Windows firewall will only allow, IE to use port 80
as a destination port. If that is what you are saying then, it seem like you might have a point, 
until you realize that the spyware could spawn itself as a web application using IE in the same
manner that web ad companies used to do so. Then I am not so sure you have gained any security.

But security is about defense in depth. Hence adding intrusion detection to the network
and/or a web proxy with an active blacklist for spyware will do a better job at defeating spyware.

I haven't used Windows Firewall much, but with Netfilter I can write my rules in such a way
that nmap in most cases is useless in scanning my firewall for open ports. The only scans that are
useful are heavily logged. Can you write rules like this in Windows Firewall ?
See this the paper I wrote for the firewall rules.
http://www.giac.org/practical/GCFW/Douglas_Ridgeway_GCFW.pdf

So please inform me about what I gain if I used Windows Firewall.

Alan

 

-----Original Message-----
From: annoyances-admin-DzJonyRHso41Ayx8vbq1stBPR1lH4CV8@public.gmane.org
[mailto:annoyances-admin-DzJonyRHso41Ayx8vbq1stBPR1lH4CV8@public.gmane.org]On Behalf Of PK Carlisle
Sent: Monday, September 08, 2003 8:30 PM
To: [email protected]
Subject: [Annoyances] Linux vs Windows Firewalls


I am new to playing with Linux so I admit that I could very well be 
wrong about this...

Looking through the docs for the Linux firewall, it seems that if you 
accept packets on, for example, port 80, then -any program- can 
communicate on port 80, you cannot limit which programs can 
communicate with the internet, so you could not automatically block 
spyware, etc., that is, you cannot automatically block any program 
not on a list approved to communicate with the internet.

OTOH, my Windows firewall lets me say that program X may 
communicate on port n and -only- that program may communicate 
that way unless there's another rule specifically allowing another 
program access on that port; registry checking assures that no 
application masquerades as another.

Am I wrong or can it be that my Windows system is -significantly- 
more secure online than Linux??








================================
PGP Public Key: http://home.earthlink.net/~mrgoodbytes/pkpubpgp.asc
Earthlink, AOL, Yahoo IM: mrgoodbytesIM  VOX: 708-296-2466  FAX: 708-452-8594 

_______________________________________________
annoyances mailing list
[email protected]
http://michelangelo.renaissoft.com/mailman/listinfo/annoyances
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.