Re: Linux vs Windows Firewalls
Lawrence MacIntyre <[email protected]>
| Newsgroups | gmane.linux.usability.annoyances |
|---|---|
| Organization | High Performance Information Infrastructure Group |
| Message-ID | <1063283847.2256.7.camel@nautique> |
On Wed, 2003-09-10 at 19:24, PK Carlisle wrote: > Correct, protection by filename alone is not security. However, my > firewall in Windows does compare the file itself using a given name > to what it registered when the firewall rule was written. Once I did > have to reinstall my browser and the firewall told me that the > program it understood to have that filename had been replaced and > what did I want to do about it, so more than filename and directory > is used in the comparison. Similarly your virus named svchost.exe > would cause an alert as it's a replacement file. Hopefully the user would not then assume that the firewall made a mistake, and knowing that svchost.exe is supposed to get access, reenable it... > I agree that using Outlook, Active X over the net, and executing > unknown executables is a foolish practice, and I already do none of > the above / block all of the above in Windows. > > My question revolves around products like RealMedia, etc. If one of > these programs uses a commonly used (and so opened) port, > allowing access by port alone allows these applications to report > back ... anything they like, and not all programs tell you that they do > this (Netscape 6 tries to communicate with Netscape's servers > each time the browser is launched without telling the user). Also, by > running a piece of software like Real or Netscape, I in effect initiate > the communication (whether the programs tells me it's > communicating or not) so that would slip through a firewall as you > describe it. > > It -is- nice that a virus or data miner can only access my login > account, but I guess it seems little comfort considering what > programs want to store and send. Linux appears to be wide open > to this exploitation. Is it possible that the only reason this exploit > has not yet taken off is that Linux does not have enough market > share to be *worth* attacking in bulk, but that someday it possibly > might (if you took out 1% of the world's computers, would anyone > even notice)? But how do you put the trojan executable in a place where it will be executed? The problem with outlook is that it will automatically execute attachments to email. On a unix box, I have to save the attachment and change the protection to make it executable and then execute it manually. > Somebody mentioned GID matching to compare files in Linux. MY > QUESTION IS THIS: Does this GID matching also *selectively > allow* access or does it just *report* attempted replacements?? Either one. Or both. > (Please explain in concepts rather than Linux procedures-- I'm new > to Linux!) > > > > Date: Wed, 10 Sep 2003 10:50:02 -0400 > > From: Lawrence MacIntyre <[email protected]> > > Subject: Re: [Annoyances] Linux vs Windows Firewalls > > To: [email protected] > > Organization: High Performance Information Infrastructure Group > > Reply-To: [email protected] > > > > So if I name my worm svchost.exe, the MS firewall will allow it to use > > your interface, but if I foolishly name it myworm.exe, it won't. That > > doesn't buy you much security. Firewalls must use ports, addresses, > > and protocol elements to be effective. Filenames don't provide any > > meaningful security. > > > > Filenames are simpler for users to understand, but unfortunately for > > them, not really effective means of protecting their machines. You > > are much safer with the RedHat Linux default installation, which > > basically allows anything outgoing and nothing incoming except for DNS > > and responses to connections initiated by the local machine. > > > > Remember that Linux doesn't have Outlook so the danger of executing > > random executables that have been received in email is only as great > > as the liklihood that the user will save and execute the file > > manually.=20 Also activeX doesn't work on any Linux browsers, so that > > mass of security holes isn't present either. Assuming that the user > > doesn't log in as root, any worm or virus that might be written for > > Linux can only infect that user's files. It can't affect the OS or > > other users. > > > > On Wed, 2003-09-10 at 10:10, PK Carlisle wrote: > > > Care to add some substance regarding HOW I'm wrong? =20 > > > Precisely how, given the limitation in the Linux firewall pointed > > > out,=20 is Linux to be made more secure? Opening a port to every=20 > > > program that wants to communicate over that port seems sloppy=20 and > > > risky. > > > > > > ------------------------ > > But nobody did come, because nobody does.... - Thomas Hardy, Jude the Obscure > > > Earthlink, AOL, Yahoo & MSN/Hotmail IM: mrgoodbytesim ICQ:13418006 > PGP Public Key: http://home.earthlink.net/~mrgoodbytes/pkpubpgp.asc > VOX: 708-296-2466 FAX: 708-452-8594 > > > _______________________________________________ > annoyances mailing list > [email protected] > http://michelangelo.renaissoft.com/mailman/listinfo/annoyances -- Lawrence MacIntyre 865.574.8696 [email protected] Oak Ridge National Laboratory High Performance Information Infrastructure Technology Group
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQA/YGyHCNjP8rawCW4RArwCAJ9/4reMSCD6VswptRu0YC8qgpzWmQCfRSgq zEBe9qbBQdgdTl8/ATxaXc8= =tnLh -----END PGP SIGNATURE-----