Preventing urself from the NET
AsYLuM wrote: ZoneAlarm gets annoying if you jsut installed it. It asks for permission to do EVERYTHING!
And that's very good. If ZoneAlarm gives permission to a program because the prog is on a 'safe' list, it's very dangerous and certainly not a good firewall. Ever heard of firewall-injection… or something like that :p
Anyway, please note that ZoneAlarm is just a software firewall and that it's part of the system it needs to protect. To be safe, I recommend that you also use some sort of hardware firewall. I got some good experience with Linksys stuff ;)
Proxies eh ;)
JAP is a very good tool that in my opinion offers very good anonymity
http://anon.inf.tu-dresden.de/
I know, german site, but it's easy to find ;)
http://anon.inf.tu-dresden.de/index_en.html
=> english site ;)
The_Cell wrote: And that's very good. If ZoneAlarm gives permission to a program because the prog is on a 'safe' list, it's very dangerous and certainly not a good firewall. Ever heard of firewall-injection… or something like that :p
Yes, that is a dangerous condition. There are many ways to exploit this. I've seen IE used to go and download rootkits, among other things. I've see people recreate spaceless piping reverse telnet shells (similar to the *nix telnet | sh | telnet, only its telnet | cmd | telnet) using telnet (as its on the allow list). You're only limited by your imagination.
But you want to know whats really scary? You know the commands to manipulate Windows process from sysinternals? Its possible to use the `pskill' command to actually kill the firewall, thus rendering it useless. Attackers can also do this to your AV, your anti-spyware, to anything.
So, once they get access, its game over.