RE: Linux vs Windows Firewalls
"PK Carlisle" <[email protected]>
| Newsgroups | gmane.linux.usability.annoyances |
|---|---|
| Message-ID | <3F60F612.1289.F841C71@localhost> |
OK, for clarity, I use my system only as a client. As you note, the one potential security flaw that I can see is a spawned application. I can (and do) to some degree avoid this and acheive security in depth in several ways: I use less widely used (and coincidentally higher quality) applications -- Pegasus Mail instead of Outlook, Netscape instead of MSIE. I do also scan the system for spyware regularly. I do not allow Dial Up Networking to even have the password necessary to dial out, that is retained by another product entirely so that nothing can spoof another program and dial out, because nothing at all can dial out on its own. I do not have unnecessary protocols even installed in DUN. This makes for an uncommmon configuration which would defeat quite a few attacks / exploitations based on a default configuration. Also for clarity, I am definitely NOT talking about the firewall built into Windows XP. :-) It also works on general concepts such as 'allow mail', and leaves the user to guess what that means with regard to what can access the internet. That made me nervous when I first saw it in Windows and that is why the apparently similar approach in Linux made me wonder about the security aspect. The firewall I use is Tiny Personal Firewall: http://www.tinysoftware.com/tiny/files/docs/pf2.pdf and a sample basic rule set runs thusly: http://www.dslextreme.com/users/surferslim/tpf.txt Not being familiar with nmap, and being never having set up a network as complicated as your document describes (but I kept a copy to give me ideas, thank you), I cannot attempt a comparison with nmap, but I am going to say that my perception is this: My firewall obviously cannot *prevent scanning* on any port, but if I am scanned on a disallowed port, or if access to a unallowed application even on an otherwise allowed port is attempted, that activity is simply dropped. I had assumed that this would be readily available in Linux. I will have to look into GID matching for Linux. Thus spake Ridgeway, Alan: > > It sounds like there may be some confusion here. > > >it seems that if you accept packets on, for example, port 80, then > >-any program- can communicate on > port 80 > > It sounds like you are talking about running a server (like a web > server) on port 80. If that is the case, then assigning a program name > does not give you anything extra. If the web server is listening on > port 80, then no other program on that machine can listen on port 80. > > Now if you are talking about a client going over the Internet to reach > a server on port 80 then I think what you are saying is the Windows > firewall will only allow, IE to use port 80 as a destination port. If > that is what you are saying then, it seem like you might have a point, > until you realize that the spyware could spawn itself as a web > application using IE in the same manner that web ad companies used to > do so. Then I am not so sure you have gained any security. > > But security is about defense in depth. Hence adding intrusion > detection to the network and/or a web proxy with an active blacklist > for spyware will do a better job at defeating spyware. > > I haven't used Windows Firewall much, but with Netfilter I can write > my rules in such a way that nmap in most cases is useless in scanning > my firewall for open ports. The only scans that are useful are heavily > logged. Can you write rules like this in Windows Firewall ? See this > the paper I wrote for the firewall rules. > http://www.giac.org/practical/GCFW/Douglas_Ridgeway_GCFW.pdf > > So please inform me about what I gain if I used Windows Firewall. > > Alan > > > > -----Original Message----- > From: annoyances-admin-DzJonyRHso41Ayx8vbq1stBPR1lH4CV8@public.gmane.org > [mailto:annoyances-admin-DzJonyRHso41Ayx8vbq1stBPR1lH4CV8@public.gmane.org]On Behalf Of PK Carlisle > Sent: Monday, September 08, 2003 8:30 PM To: > [email protected] Subject: [Annoyances] Linux vs Windows > Firewalls > > > I am new to playing with Linux so I admit that I could very well be > wrong about this... > > Looking through the docs for the Linux firewall, it seems that if you > accept packets on, for example, port 80, then -any program- can > communicate on port 80, you cannot limit which programs can > communicate with the internet, so you could not automatically block > spyware, etc., that is, you cannot automatically block any program not > on a list approved to communicate with the internet. > > OTOH, my Windows firewall lets me say that program X may > communicate on port n and -only- that program may communicate > that way unless there's another rule specifically allowing another > program access on that port; registry checking assures that no > application masquerades as another. > > Am I wrong or can it be that my Windows system is -significantly- more > secure online than Linux?? > ------------------------ Mistresses are a direct function of the economy. -Divorce lawyer Raoul Felder Earthlink, AOL, Yahoo & MSN/Hotmail IM: mrgoodbytesim ICQ:13418006 PGP Public Key: http://home.earthlink.net/~mrgoodbytes/pkpubpgp.asc VOX: 708-296-2466 FAX: 708-452-8594