RE: Linux vs Windows Firewalls

"Ridgeway, Alan" <[email protected]>
Newsgroups gmane.linux.usability.annoyances
Message-ID <[email protected]>
Well John

First you assume that virues only get in from the outside of the firewall.
I guess you do not have mobile workers who bring laptops into the workplace.
I guess you do not have visiting customers or vendors who bring a laptop 
in from their workplace.
I guess your Anti-Virus software can predict the future and catch every potential
virus that will ever exsist.

> Linux keeps them out.
B.S. Netfilter/IPtables keeps them out, Linux is just the kernel. Netfilter/IPtables is the kernel module
and userland utility to write firewall rules. Netfilter is not without it's problems.
http://www.securityfocus.com/bid/8331
http://www.securityfocus.com/bid/8330
http://www.securityfocus.com/bid/6305

Nor the Linux Kernel itself
http://www.securityfocus.com/bid/8233
http://www.securityfocus.com/bid/8042
http://www.securityfocus.com/bid/7797

I guess you do not follow "best practices" as per the SANS Top Twenty:

SQL Slammer's exploit routine is based upon a buffer overflow in the SQL Server Resolution Service.
The most effective means of defense against this worm is diligent patching, proactive system configuration 
practices, and " ingress/egress " UDP port 1434 filtering at network gateways.  

Does egress filtering fix everything ? No. It's all about defense in depth. But if everyone
was egress filtering, then worms would have a lot harder time spreading around. At very least 
they are slowed down.

> Since when do you get to define what a good "internet neighbor" is?

I didn't. SANS, ISC2 (CISSP), and any good security admin all agreee that egress filtering is
being a good neighbor. The reason it is being a good neighbor is if my network gets compromised
I at least keep it in my network and not let it spread beyond my network. Ya a pain for me
but I am a good neighbor so I won't spread my pain to others.

>The idea that you can protect against a trojan that your
>firewall admitted is fundamentally silly.

So it looks like you do not run egress filtering. Then how do you known when you have a Trojan ?
One of many way to identify if a Trojan is on your network is to egress filter spoofed addresses.
Since many scans are sent with spoof addresses to confuse the logs of the potential victims, it is helpful
to see that your firewall logs report these spoofed addresses.

> The only people who would suggest such a thing would be people with a sieve for and operating system.
It sounds like you are the one with the sieve since you don't know how to plug the holes leaving your network.
I at least plug holes coming in and going out.

Alan

-----Original Message-----
From: annoyances-admin-DzJonyRHso41Ayx8vbq1stBPR1lH4CV8@public.gmane.org
[mailto:annoyances-admin-DzJonyRHso41Ayx8vbq1stBPR1lH4CV8@public.gmane.org]On Behalf Of John Andersen
Sent: Friday, September 19, 2003 11:51 PM
To: [email protected]
Subject: Re: [Annoyances] Linux vs Windows Firewalls



On Wednesday 10 September 2003 13:00, Ridgeway, Alan wrote:
> >A firewall is mostly used for stopping bad guys from coming in.
>
> So I guess you aren't a good Internet neighbor and don't run egress
> filtering.

Since when do you get to define what a good "internet neighbor" is?

And why is egress filtering important if no viruses can get in in the
first place?  Closeing the door to trap bugs that have gotten in
seems a little backwards to me.  Linux keeps them out.

Anything that can get in can disable any firewall you may
have set up for egress filtering, and several of the last Microsoft
worms have done similar things to virus checkers.

The idea that you can protect against a trojan that your
firewall admitted is fundamentally silly.  The only people who 
would suggest such a thing would be people with a sieve for
and operating system.

-- 
_____________________________________
John Andersen
_______________________________________________
annoyances mailing list
[email protected]
http://michelangelo.renaissoft.com/mailman/listinfo/annoyances
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.