Re: Linux vs Windows Firewalls

"PK Carlisle" <[email protected]>
Newsgroups gmane.linux.usability.annoyances
Message-ID <3F5F6C45.5470.981BEB3@localhost>
Correct, protection by filename alone is not security.  However, my 
firewall in Windows does compare the file itself using a given name 
to what it registered when the firewall rule was written.  Once I did 
have to reinstall my browser and the firewall told me that the 
program it understood to have that filename had been replaced and 
what did I want to do about it, so more than filename and directory 
is used in the comparison.  Similarly your virus named svchost.exe 
would cause an alert as it's a replacement file.

I agree that using Outlook, Active X over the net, and executing 
unknown executables is a foolish practice, and I already do none of 
the above / block all of the above in Windows.  

My question revolves around products like RealMedia, etc.  If one of 
these programs uses a commonly used (and so opened) port, 
allowing access by port alone allows these applications to report 
back ... anything they like, and not all programs tell you that they do 
this (Netscape 6 tries to communicate with Netscape's servers 
each time the browser is launched without telling the user).  Also, by 
running a piece of software like Real or Netscape, I in effect initiate 
the communication (whether the programs tells me it's 
communicating or not) so that would slip through a firewall as you 
describe it.

It -is- nice that a virus or data miner can only access my login 
account, but I guess it seems little comfort considering what 
programs want to store and send.  Linux appears to be wide open 
to this exploitation.   Is it possible that the only reason this exploit 
has not yet taken off is that Linux does not have enough market 
share to be *worth* attacking in bulk, but that someday it possibly 
might (if you took out 1% of the world's computers, would anyone 
even notice)?

Somebody mentioned GID matching to compare files in Linux.  MY 
QUESTION IS THIS: Does this GID matching also *selectively 
allow* access or does it just *report* attempted replacements??

(Please explain in concepts rather than Linux  procedures-- I'm new 
to Linux!)


> Date: Wed, 10 Sep 2003 10:50:02 -0400
> From: Lawrence MacIntyre <[email protected]>
> Subject: Re: [Annoyances] Linux vs Windows Firewalls
> To: [email protected]
> Organization: High Performance Information Infrastructure Group
> Reply-To: [email protected]
>
> So if I name my worm svchost.exe, the MS firewall will allow it to use
> your interface, but if I foolishly name it myworm.exe, it won't.  That
> doesn't buy you much security.  Firewalls must use ports, addresses,
> and protocol elements to be effective.  Filenames don't provide any
> meaningful security.
> 
> Filenames are simpler for users to understand, but unfortunately for
> them, not really effective means of protecting their machines.  You
> are much safer with the RedHat Linux default installation, which
> basically allows anything outgoing and nothing incoming except for DNS
> and responses to connections initiated by the local machine.
> 
> Remember that Linux doesn't have Outlook so the danger of executing
> random executables that have been received in email is only as great
> as the liklihood that the user will save and execute the file
> manually.=20 Also activeX doesn't work on any Linux browsers, so that
> mass of security holes isn't present either.  Assuming that the user
> doesn't log in as root, any worm or virus that might be written for
> Linux can only infect that user's files.  It can't affect the OS or
> other users.
> 
> On Wed, 2003-09-10 at 10:10, PK Carlisle wrote:
> > Care to add some substance regarding HOW I'm wrong? =20
> > Precisely how, given the limitation in the Linux firewall pointed
> > out,=20 is Linux to be made more secure?  Opening a port to every=20
> > program that wants to communicate over that port seems sloppy=20 and
> > risky.





------------------------ 

But nobody did come, because nobody does.... - Thomas Hardy, Jude the Obscure 


Earthlink, AOL, Yahoo & MSN/Hotmail IM: mrgoodbytesim  ICQ:13418006
PGP Public Key: http://home.earthlink.net/~mrgoodbytes/pkpubpgp.asc
VOX: 708-296-2466  FAX: 708-452-8594
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.