Articles

Metasploit Framework Windows Tutorial
Remote Desktop Connection
Windows Processes That May Be Dangerous
How-To use NetCat a Tutorial
Common Linux Commands
Common Ports
Netcat Commands
HTTP Response Codes
War-Google Hack Terms
Wardriving
Avoiding Social Engineering and Phishing Attacks
Intrusion Detection on Linux
Linux Intrusion Detection
Penetration Testing Guide
Penetration Testing Tools
Social Engineering Fundamentals, Part I: Hacker Tactics
Social engineering (computer security)
The Psychology of Social Engineering

The Archives

General GSO
GovernmentSecurity.org News & Suggestions
In The News
Open Topic
General Security Information
Trash Can
Exploit & Vulnerability Mailing List Archives
Trial Member Forum
Product and Program Reviews GSO Tutorials
System Security
Windows Systems
Beginners Section
Linux & Unix Systems
File Downloads
Exploit Research & Discussion Trojan & Virus Errata
Networking Security / Firewall / IDS / VPN / Routers
System Hardening
E-Mail Security
Wifi Security
Trial Member Uploads
Upload discovered Trojans & Mal ware
GSO Programming Section
C , C++ , VC++
Visual Basic.NET
Perl /CGI
Java/Javascript
PHP/XML/ASP/HTML
Assembly + Other
The Cork Board
Network Security Consultant Directory
Network Security Jobs
The Archives
Encryption Information
General Network Security
Internet Anonymity
HTTP Protocol Security
Linux Security
MS IIS Information
Exploit Articles
Programming / Tool Design
GSO Software Projects
Public Downloads
Microsoft Security Questions and Papers

Full Version: Firewall/antivirus
Pages: 1, 2
w00dy
The best firewall for windows i have seen is Tiny. It lets you make very specific rules.
Tho I dont have windows, so I just use freebsd's own firewall and no AV. I dont really download much from untrusted sites, and as long as my firewall stays in tip top shape, noone can upload virus' to me.
Black_hat
I am using WatchGuard (Hardware Firewll)
WinRoute(softwareFirewall) (cuze i can create THe rules manually)
And i like NAV and Dr.Web and KAV (AntiVirusSoftware)

ph34r.gif

Black_Hat
Shade
Which software firewall/antivirus do you use, or which would you rank in the top few?

I'm interested in seeing how many of you use the mainstream firewalls.
dissolutions
Well I've got Firewalls tongue.gif
IPcop
Deerfield Visnetic
AVG (Anti Virus)
woutiir
I just use ZoneAlarm, free, and works good for me (too bad of that vulnerability tho...) Tho, i i would recommend it. For A/V (anti virus) i use norton antivirus, works great, updates are fast etc etc...

Hopefully it helped a bit,

woutiir
DJohn84
Firewall: Zone Alarm Pro

I think I"ll try Tiny Firewall 5.0 soon...whenever they get a comprehensive guide on how to configure that thing out.

Antivirus: http://housecall.trendmicro.com

biggrin.gif
Dillinja
Good old IPtables, and "firestarter" firewall...great to see all those DCOM probes while I sit back and laugh in my Linux castle! biggrin.gif AV? Pfffttttttttttttt!! laugh.gif

For Windows, Norton AV and sygate personal firewall (<----found it to be brilliant).
netcomm
blackice and Norton AV

Peace
NetCOmm
ComSec
Outpost firwall....create your own plugins and rules , etc

f-prot ...antivirus
n3mesis
Kerio Personal Firewall is very good as well, and free. Very configurable, and also allows you to make specific rules about filtering. Has a log, and has all the basic features of a professional firewall
scooby
I use Agnitum outpost firewall. In antivirus solutions f-secure is the fastest and rules my desktop.
MpR
Working Security for an ISP Ive found Firewalls too be as much of a nucense and they can be a god sent .. The best thing you could ever really do is to secure your system from square 1 and being smart about things , Doing Your Updates Turnign off services you dont need or can be easily exploited. When Installing new software think about the out come of things and thake the appropriate course of action to secure it. Port Explorer is one of the best programs Ive seen unlike a firewall it doesnt limit your activity nor close anything, but it fully allows you too see everything that is connected to the internet ports process UID etc.. another thing Ive found useful is changing the root of c$ and d$ ect to an empty directory and kill admin$, so if anyone does get your well thought of blank password the files get routed to that directory could still be executed, but if left behind you have fair enough warning there..(That is if you need shares or even creating your own personal shares) Personally from all the winsock2 errors left behind from every Windows based Firewall mentioned here Id suggest using common sence and think about whats happening, Firewalls can / will limit what you do and can be a huge pain in the ass in the end. Check out Port Explorer just google it youll get a nice trial.

manu
For Windows, I prefer to use SYGATE personal firewall. Simple and nice one.. Using Norton Anitivirus with it... I completely stand with Dillinja... In my experiance, both are excellent.... ZONE alaram too is good one..
dissolutions
zone alarm in my experience has proven to be a crappy firewall... mainly because the ability to make your own rules doesn't quite exist in it. While Sygate and Deerfield and a few others have that ability, Zone Alarm does not...
donfrabrizio
I use norton personal firewall and in combination with panda antivirus.
I have the panda in a trial version but I re-install it every 30 days and get a free update.

It's been a nice panda. cool.gif
ifhope
as far as antivirus is concern... there is no concern

regarding firwall top one which is like most but a P-II machine recommended. It is MNF from Mandrake... which has great look as well as no need for plugin or addons...

if u don't have high processing machine... then use IPCop... and remember Addons are necessary...
starsky32
I use LOOK'N'STOP Firewall (windows version), very good, low cost and low ressource needed.
MacAffe VirusScan as an antivirus, as i found it seems to be more difficult to make trojans or virii 'undetectable' for him.
dstevens1958
QUOTE (Dillinja @ Aug 16 2003, 07:47 PM)
Good old IPtables, and "firestarter" firewall...great to see all those DCOM probes while I sit back and laugh in my Linux castle!  biggrin.gif AV? Pfffttttttttttttt!!  laugh.gif

I agree with this. I use iptables behind a router with a NAT firewall and updated firmware. I feel pretty safe as I haven't detected an attack inside that router since I set it up over a year ago now. Even if someone gets through it, I still have my trusty iptables and SuSE Firewall2. As for AV, I feel pretty safe again, but just to be sure I use chkrootkit and F-Prot AV for Linux.

Um, on the other machine running WindozeME I use NIS 2003. Only thing I don't like is it eats up a lot of overhead. I prefer using Sygate personal for a firewall and I think its av-personal as antivirus on windows. These programs are small and fast, and don't use much overhead and allow more memory for multitasking! smile.gif I put them on my sisters Win2k box and it works really well too. But I still like my iptables! wink.gif

Just my cheap two cents. (Canadian currency and all... lol)

Dave
starsky32
Yeah, I aggree with you wicked, but i have not the same conclusion.
- Control & Monitor both IN Traffic and OUT Traffic
- ability to Set up Rulesfor Applications/Networks
- surf the Web Stealthly
- be warned when-ever a potential intruder try's to get into my system
- ability to block all internet Traffic and provide me with a detailed log of all attempts for future Hunting.
For all you said, Look'N'Stop seems to be better than Za.
I admit that maybe it seems not too easy to configure, but it's just an impression : in fact it's so simple you'lle be surprised.

Ok, Za is correct, but take look at this page:
http://www.pcflank.com/art41c.htm

Look'n'stop very light , effective and allows good fine-tuning.
Give it a try ;-)
(i'm NO member of the looknstop team -lol- , just like very much this product ;-) )
Chris.ology
AV = NOD32 That is the best AV I have used. Norton takes up far too much memory and CPU cycles for a 2003-grade software package and it does not always detect virii, certainly not as well as Nod32!
KuunLB
i don't run antivirus programs constantly on my machine

i have been online for almost 8 years and never contracted a virus.

i will occasionally run the housecall remote scan

but as far as a proggie.. nope... waste of resource and cpu cycles imho

firewall

i use a router instead of a firewall.. i block most ports and forward a very narrow range for all my applications to use
tibbar
anyone who uses Norton AV should be aware that any kiddie can make an undetectable trojan for it with relative ease. Mcaffe is a much stronger AV and in my experience tends to get updated more quickly to new hostile code.

RAV is the best, but...M$ now own it for inclusion in Longhorn.

I guess what im saying is that using Norton is a quick way to get owned.

Personally, I dont rely on Firewalls, and prefer using a router with just the bare min ports forwarded. Its never been penetrated so far...

And to protect from undetectable trojans, always run tcpview in the background, and have a quick peek now and then to see if any unusual progs are connecting to unknown ip's.
billy1816
I uses the firewall that comes with XP, and the Firewall That Comes with the Antivirus package. But rather than depending on fw, and av, which isn't really safe, i usually turn off my computer which saves energy for it as well
akis
hello.i am using Zone Alarm as a firewall and norton 2003(with live update on!)as an antivirus.
net
i'm using the built in NAT firewall of my smc barricade smile.gif

sometimes scannin' my sys with norton antivir.

greetz
FakoLy
i am using AntiVirusKit professional 11 (for me, the best you can find. It uses kaspersky and KAV scanner for virus detection)
firewall i have BlackIce smile.gif
PaRaDiSo
Hmmmm, well after i had some problems with Tiny and Windows XP i just turned to good old Zonealarm Pro and for Antivirus I use NOD32...very little overhead, works great!!! (Tiny used to leave ports 1025-1026-1027 in a not stealthed state!)
8XyuVmUB
ph34r.gif Blackice and Symantec
dozolax
norton
Nightdemon
Norton AntiVirus is the best (I think tongue.gif )
passi
Use everything but not spftware that has a "norton" in it's name. I used it for jears and many peple told me, it's crap. the sygate firewall is good, but the newest version sucks.

Now I use McAfee AntiVirus v7.00. It has Firewall includet and is quick and simpel. It can delete every infected file (even when it's running, mcafee stops it) and it even checks your memory for virij. this are only one of the options that NAV has not included. And McAfee is smaller and faster, and does not slow don't your whole machine.....

NAV: mad.gif
McAfee: smile.gif
skydance
firewall: tiny
antivirus: kaspersky AV, the best money can buy :-)
GSecur
kaspersky AV is good but for some reason I always find it bogs down my system.
beardednose
I use Trend OfficeScan and Blackice on one system, Panda Platnium AV & firewall on another (YUK on that), and Outpost and Trend on another.

I dislike Panda with a passion and hate outpost even more. BOth are cumbersome. Outpost crashes my system.

I like Norton the best, but too cheap to purchase it. It seems to catch the most stuff that I load onto other systems wink.gif

Still working on my Linux boxes. Most don't connect to the net very often, so nothing on them yet.
blixz
Have someone a Test report over FW/AV ?
The Storm
i use the Norton ANtivirus and i must say it realy sucks the only thing working is deleting al scan progs i have on my pc!
It`s crap!
Spookie
For AV- Nod32

TDS-3 vs TauScan. My preference is TDS-3.

For FW- I prefer Outpost



here's a site some may be interested in.

AV Testing

mal.one
Firewall : Sygate Personal Firewall Pro (Also used ZoneAlarm , Norton , Atguard ....)

and AV currently none beacause i'm stil searching for one ...
Flatscreen
I Use Mc Afee Virus Scan & Sygate Firewall
raif
Win2k:
ZoneAlarm for a firewall and eTrust for AV

Linux:
custom iptables firewall cool.gif
Maffuster
AV: Nav 2004
FW: Cisco Pix 501
ST.
every body use this - outpost firewall
evoLv3
i used tiny personal2 for a long time. now im using kerio4. it is very good and free for private use smile.gif
http://www.kerio.com/kerio.html
Silent Bob
i use sygate pro + avg free edition
forza
firewall: Kerio
antivirus: trend micro

DumpZ
Firewall : Zonealarm 4.5 pro
AV :McAfee 7.0 Pro

First i always used Norton as Antiv virus but allot of trojans i used weren't detected by norton and the were detected McAfee so that's why i switched. And also exculsion is harder with Norton
digitalk2003
Personally
AV: Norton 2004
FW: Sygate 5.5 Pro - very customized rule sets let you block as you see fit smile.gif
Also running Snort IDS.

Company
AV: Symantec Corporate
FW: Checkpoin FW-1 / Pix

Ciau..

digitalk2003
sp4rk
i use BlackIce and Norton Antivirus. I had ZoneAlarm but uninstalled it after few days smile.gif never liked it.
robmilman
Work:

FW: Checkpoint FW1
AV: Symantec Corporate on desktops and servers and McAfee Webshield for SMTP traffic (stop 'em before they get in)

Home:

FW: DLink Cable/DSL router (got tired of playing with FreeBSD)
AV: Symantec Corporate (borrowed from work ;-)
pr0t0type
At home I've got.

Cisco Router. Port Blocking and logging to my linux box
AVG antivirus

Seems to work pretty well smile.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2005 Invision Power Services, Inc.