Hello Technoslick,

Monday, June 16, 2003, 3:21:54 PM, you wrote:

T> Your spyware software, commercial or malicious, is going out ports
T> that would be open in all firewalls that allow HTTP access: port
T> 80.

Not necessarily. Tiny, for example, can be set so that the ONLY app
that is allowed to access port 80 is the browser. You can then browse,
but NO other app can access port 80. Also, a major advantage to using
a non-M$, self-contained browser is that apps using just part of IE
will pop up as non-allowed accesses. Some spyware apps try to 'tag
along' on IE coat tails, to be less evident.

T> The general attacks from the outside are going to come in from port
T> 80 because the attacker only has to find you in your Web browser to
T> get at you.

Not necessarily. A stateful inspection firewall can recognize that
this attempt is not related to your browsers traffic, and will not let
it in even if you are browsing. This would not be the case if you are
being attacked by the site you are visiting, though.

T> I like to think of the hardware firewall as more like heavy armor.

An excellent combination for the truly paranoid is a stateful
inspection firewall protecting the local net, and individual
app-aware fw's in each machine.

T> With plug-ins, NSN IM and Yahoo Messenger can now do Video
T> conferencing.

As more and more apps require flexible multi-port operation, the
protection from fw's is becoming like Swiss cheese. :-)

-- 
Thank you,
 rikona                            mailto:[EMAIL PROTECTED]


Want to buy your Pack or Services from MandrakeSoft? 
Go to http://www.mandrakestore.com

Reply via email to