Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • E-Books
  • Lounge
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>Insider Tricks>Firewall weaknesses leave users at risk

Firewall weaknesses leave users at risk

Tweet

Our feature in the Nov. 18 issue of the Windows Secrets Newsletter inspired reader Hilton Travis to write in about ways in which software firewalls can bite back:

  • “I’ve always been a proponent of proper network security. I’ve always been a proponent of running decent antivirus and firewalls. I’ve always been a proponent of having a primary firewall that is a hardware firewall — be it a router, m0n0wall box, or whatever product you choose. A hardware firewall that’s not based on an inherently insecure, over-featured operating system, that is.

    “I can understand the use of a software firewall in addition to this primary firewall for home users. A properly designed software firewall (this obviously means not the Windows Firewall) will enable a home user to block all outbound traffic they don’t want to allow out to the Internet. It is an additional line of defense, and generally a good idea.

    “I cannot, however, advocate a similar practice in a business network. Software firewalls only increase the complexity of any network, often to the point where the frustration caused by the ‘over-enthusiasm’ of the firewall is costing the company money. This ultimately results in the firewall being disabled anyway — or defaulting to allow all traffic in and out, effectively disabling it.

    “We’re now at a point where there are at least three worms that can disable the Windows Firewall. This is purely due to a stupidity-encouraged design flaw by the Microsoft Security team. Microsoft decided to implement a mechanism whereby another vendor could disable the Windows Firewall during the installation of its third-party firewall. All these Bagle variants have to do is to trigger this mechanism, and the Windows Firewall is disabled, replaced with nothing — well, nothing enhancing your security.

    “How long will it be before a worm is written that can decode the UPnP [Universal Plug and Play] username and password stored in the Registry, and combine this with the ‘Disable Windows XP SP2 Firewall’ vulnerability to disable not only your personal firewall, but also the firewall of anyone insane enough to enable UPnP? This means that it could disable the hardware firewall on a business or corporate network, if the administrator was ‘green’ enough to believe Microsoft’s hype about UPnP that they preach in their MCP and MCSE courses.

    This article is part of our paid content. Subscribe.

    Already a paid subscriber? Click here to login.

    Related posts:

    1. Dump the Windows Firewall — a primer
    2. AOL (Or Any ISP) Needs No Firewall?
    3. Router Means “No FireWall Needed?”
    4. Promising New Free Firewall!
    5. uPnP
= Paid content

All Windows Secrets articles posted on 2004-12-02:

  • Top Story Secrets of Firefox 1.0
  • Patch Watch Patch for IFRAME hole released off-schedule
  • Insider Tricks Firewall weaknesses leave users at risk
  • Wacky Web Week Print your own 12-sided 2005 calendar
  •  Show all articles on a single page
E-books

We’ve pored through years of back issues, picking the best tips, to create these ebooks:

E-book series
  • PC Maintenance Guide
  • PC Security Guide
  • Windows 7 Guide Vol 1
  • Windows 7 Guide Vol 2
  • Win XP Survival Guide
See the e-book series
Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.53
  • The sorry tale of the (un)Secure Sockets Layer 4.42
  • RPV: Win7′s least-known data-protection system 4.33
  • Recovery: the last step in total data security 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Pros and cons of a ‘keyfile’ password 4.21
  • Beating back Duku and a plethora of other threats 4.21
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • One year and 99 security bulletins later 4.18
  • 1.8TB external drive goes down hard 4.17
  • Don’t pay for software you don’t need — Part 3 4.16
  • Internet Explorer gets another round of patches 4.15
  • Is your free AV tool a ‘resource pig?’ 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Remote access leads to remote attacks 4.15
  • Keeping you up to date: say no to .NET — again 4.14
  • Take control of Google’s privacy policy settings 4.14
  • Office File Validation patch leads to problems 4.14
  • The advanced system-recover toolkit 4.13
  • New “419″ scam involves PayPal and Western Union 4.12
  • Readers’ best personal-privacy tips 4.11
  • Getting the most from Windows Search — Part 2 4.11
  • Re-examining Dropbox and its alternatives 4.10
  • Don’t pay for software you don’t need — Part 2 4.10
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb