Re: Linux vs Windows Firewalls

Lawrence MacIntyre <[email protected]>
Newsgroups gmane.linux.usability.annoyances
Organization High Performance Information Infrastructure Group
Message-ID <1063283847.2256.7.camel@nautique>
On Wed, 2003-09-10 at 19:24, PK Carlisle wrote:
> Correct, protection by filename alone is not security.  However, my 
> firewall in Windows does compare the file itself using a given name 
> to what it registered when the firewall rule was written.  Once I did 
> have to reinstall my browser and the firewall told me that the 
> program it understood to have that filename had been replaced and 
> what did I want to do about it, so more than filename and directory 
> is used in the comparison.  Similarly your virus named svchost.exe 
> would cause an alert as it's a replacement file.

Hopefully the user would not then assume that the firewall made a
mistake, and knowing that svchost.exe is supposed to get access,
reenable it...

> I agree that using Outlook, Active X over the net, and executing 
> unknown executables is a foolish practice, and I already do none of 
> the above / block all of the above in Windows.  
> 
> My question revolves around products like RealMedia, etc.  If one of 
> these programs uses a commonly used (and so opened) port, 
> allowing access by port alone allows these applications to report 
> back ... anything they like, and not all programs tell you that they do 
> this (Netscape 6 tries to communicate with Netscape's servers 
> each time the browser is launched without telling the user).  Also, by 
> running a piece of software like Real or Netscape, I in effect initiate 
> the communication (whether the programs tells me it's 
> communicating or not) so that would slip through a firewall as you 
> describe it.
> 
> It -is- nice that a virus or data miner can only access my login 
> account, but I guess it seems little comfort considering what 
> programs want to store and send.  Linux appears to be wide open 
> to this exploitation.   Is it possible that the only reason this exploit 
> has not yet taken off is that Linux does not have enough market 
> share to be *worth* attacking in bulk, but that someday it possibly 
> might (if you took out 1% of the world's computers, would anyone 
> even notice)?

But how do you put the trojan executable in a place where it will be
executed?  The problem with outlook is that it will automatically
execute attachments to email.  On a unix box, I have to save the
attachment and change the protection to make it executable and then
execute it manually. 

> Somebody mentioned GID matching to compare files in Linux.  MY 
> QUESTION IS THIS: Does this GID matching also *selectively 
> allow* access or does it just *report* attempted replacements??

Either one.  Or both.

> (Please explain in concepts rather than Linux  procedures-- I'm new 
> to Linux!)
> 
> 
> > Date: Wed, 10 Sep 2003 10:50:02 -0400
> > From: Lawrence MacIntyre <[email protected]>
> > Subject: Re: [Annoyances] Linux vs Windows Firewalls
> > To: [email protected]
> > Organization: High Performance Information Infrastructure Group
> > Reply-To: [email protected]
> >
> > So if I name my worm svchost.exe, the MS firewall will allow it to use
> > your interface, but if I foolishly name it myworm.exe, it won't.  That
> > doesn't buy you much security.  Firewalls must use ports, addresses,
> > and protocol elements to be effective.  Filenames don't provide any
> > meaningful security.
> > 
> > Filenames are simpler for users to understand, but unfortunately for
> > them, not really effective means of protecting their machines.  You
> > are much safer with the RedHat Linux default installation, which
> > basically allows anything outgoing and nothing incoming except for DNS
> > and responses to connections initiated by the local machine.
> > 
> > Remember that Linux doesn't have Outlook so the danger of executing
> > random executables that have been received in email is only as great
> > as the liklihood that the user will save and execute the file
> > manually.=20 Also activeX doesn't work on any Linux browsers, so that
> > mass of security holes isn't present either.  Assuming that the user
> > doesn't log in as root, any worm or virus that might be written for
> > Linux can only infect that user's files.  It can't affect the OS or
> > other users.
> > 
> > On Wed, 2003-09-10 at 10:10, PK Carlisle wrote:
> > > Care to add some substance regarding HOW I'm wrong? =20
> > > Precisely how, given the limitation in the Linux firewall pointed
> > > out,=20 is Linux to be made more secure?  Opening a port to every=20
> > > program that wants to communicate over that port seems sloppy=20 and
> > > risky.
> 
> 
> 
> 
> 
> ------------------------ 
> 
> But nobody did come, because nobody does.... - Thomas Hardy, Jude the Obscure 
> 
> 
> Earthlink, AOL, Yahoo & MSN/Hotmail IM: mrgoodbytesim  ICQ:13418006
> PGP Public Key: http://home.earthlink.net/~mrgoodbytes/pkpubpgp.asc
> VOX: 708-296-2466  FAX: 708-452-8594 
> 
> 
> _______________________________________________
> annoyances mailing list
> [email protected]
> http://michelangelo.renaissoft.com/mailman/listinfo/annoyances
-- 
    Lawrence MacIntyre     865.574.8696     [email protected]
               Oak Ridge National Laboratory
High Performance Information Infrastructure Technology Group
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQA/YGyHCNjP8rawCW4RArwCAJ9/4reMSCD6VswptRu0YC8qgpzWmQCfRSgq
zEBe9qbBQdgdTl8/ATxaXc8=
=tnLh
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.