 |
|
11-08-2004, 05:08 PM
|
#1 (permalink)
|
|
Alpha Geek
Join Date: Dec 2003
Location: mumbai
Posts: 522
|
which firewall is the best ?
i m using the sygate personal firewall but still i find that some nasty applications do find their way in.inspite of using nav 04,ad aware se,spyubot SAD anf sysmech.
which cud b the best firewall?
presently using IE 6.0 and soon migrating to mozilla firefox !
|
|
|
|
Advertisements. Register and be a member of the community to get rid of them.
|
|
Advertisement
|
|
11-08-2004, 05:42 PM
|
#2 (permalink)
|
|
Certified Nutz
Join Date: Jan 2004
Location: The 3rd rock from the sun
Posts: 310
|
applications like adware and spyware make their way into the system thru the browser...the firewall cant stop those applications from coming into ur system because u have allowed the browser to communicate with the internet...yes, the softwares u mentioned can stop them from loading in ur pc to a certain extent, but not always.....but u can stop these programs from accessing the internet using the firewall [atleast this is to the best of my knowledge(heard this from some another source) ofcourse i cud be wrong(someone please correct me if so)] 
and u can stop many of these programs from installing in the first place using programs like javacool software's spywareblaster and spywareguard. use a combination of Spybot SnD(1.3) and Spywareblaster and keep updating.
as far as firewalls r concerned, ZoneAlarm is the best according to popular opinion (i'm also usin it and its doing a fine job for me).
but u can try other firewall softwares like blackice and tinyfirewall personal which i heard r also good.
__________________
"Don't take life too seriously. You'll never get out alive!" - Bugs Bunny
|
|
|
11-08-2004, 06:31 PM
|
#3 (permalink)
|
|
Apprentice
Join Date: Aug 2004
Location: Mumbai
Posts: 79
|
yup zone-alarm is probably the best although you'll get annoyed at the number of programs that are trying to access the net! it also slows (my) computer down quite a bit, if you don't have lots of RAM. but its the best in my opinion. can get it from zonelabs.com
|
|
|
11-08-2004, 06:32 PM
|
#4 (permalink)
|
|
Wire muncher!
Join Date: Nov 2003
Posts: 6,164
|
i find mcafee d best......zonealarm uses a lot of sys resources.....
|
|
|
11-08-2004, 06:41 PM
|
#5 (permalink)
|
|
Human Spambot
Join Date: May 2004
Location: off to "never ever" land
Posts: 2,912
|
actually firewalls block certain ports which specific *ware/viruses use
hence preventing an attack
and again im not sure either .. so waiting for confirmation 
and i agree ... its zone alarm for me !
__________________
No Mercy, No Limits.
Oobertech.net - Keeping Knowledge Free
|
|
|
11-08-2004, 07:26 PM
|
#6 (permalink)
|
|
Right Off the Assembly Line
Join Date: Jul 2004
Location: Hyderabad
Posts: 18
|
Go to the following site and find out how good your firewall is.
Symantec Security Check
You can even post your results and we'll know whose firewall is best.
|
|
|
11-08-2004, 08:24 PM
|
#7 (permalink)
|
|
Alpha Geek
Join Date: May 2004
Location: India
Posts: 930
|
ofcourse it will show that norton has the best firewall!!!
Isn't there any neutral site...
|
|
|
11-08-2004, 09:55 PM
|
#8 (permalink)
|
|
Apprentice
Join Date: Aug 2004
Location: Mumbai
Posts: 79
|
why would symantec say that norton is best?
|
|
|
11-08-2004, 10:10 PM
|
#9 (permalink)
|
|
Right Off the Assembly Line
Join Date: Aug 2004
Posts: 3
|
Zone - Alarm is the Best.!
Nothing gets better than it.
Used to use it when i had broadband.
|
|
|
11-08-2004, 10:43 PM
|
#10 (permalink)
|
|
Certified Nutz
Join Date: Jan 2004
Location: The 3rd rock from the sun
Posts: 310
|
__________________
"Don't take life too seriously. You'll never get out alive!" - Bugs Bunny
|
|
|
11-08-2004, 11:14 PM
|
#11 (permalink)
|
|
da' Ťurntable ruleth
Join Date: Dec 2003
Location: Mumbai
Posts: 847
|
if u have no money to spend on a GENUINE firewall
ZONE ALARM
is the best
__________________
| Dell Studio 15 | iPod Touch 16GB (Stolen) | iPod Video 5.5G 30GB | Sony Ericsson W910i |
| Sennheiser PX 100 | Sennheiser HD 202 |Creative EP630 | Altec Lansing ATP 3 |
|
|
|
12-08-2004, 12:17 AM
|
#12 (permalink)
|
|
Apprentice
Join Date: Aug 2004
Location: Relative Time Space
Posts: 84
|
No money no ads Zone alarm is the best..
__________________
;) ~~EiNsTeIn~~ ;)
http://www.tejuspratap.co.cc
|
|
|
12-08-2004, 01:20 AM
|
#13 (permalink)
|
|
Broken In
Join Date: Aug 2004
Posts: 190
|
zone alarm is the best .. but it eats up a lot of resources
u can opt for other options like
tiny firewall
sygate firewall
norton internet security
..
__________________
Attack life, it\'s going to kill you anyway.
|
|
|
12-08-2004, 01:27 AM
|
#14 (permalink)
|
|
Alpha Geek
Join Date: Dec 2003
Location: mumbai
Posts: 522
|
well guys this is te result fm symantec
Your Results:
Port Description Status
ICMP Ping Ping. Ping is a network troubleshooting utility. It asks your computer to acknowledge its existence. If your computer responds positively to a ping, hackers are more likely to target your computer. :STEALTH
21 FTP (File Transfer Protocol). FTP is used to transfer files between your computer and other computers. Port 21 should be open only if you're running an FTP server.:OPEN
22 SSH. TCP connections to this port might indicate a search for SSH, which has a few exploitable features. SSH is a secure replacement for Telnet. The most common uses of SSH are to securely login and copy files from a server.:STEALTH
23 Telnet. Telnet can be used to log into your computer from a terminal anywhere in the world. This port should be open only if you're running a Telnet server. :OPEN
25 SMTP (Simple Mail Transfer Protocol). A protocol for host-to-host mail transport. This port should be open only if you're running a mail server.:STEALTH
79 Finger. Finger is an Internet utility that allows someone to obtain information about you, including your full name, logon status, and other profile information. :STEALTH
80 HTTP (Hypertext Transfer Protocol). HTTP is used to transfer Web pages over the Internet. Port 80 should be open only if you're running a Web server. :OPEN
110 POP3 (Post Office Protocol). Internet mail servers and mail filter applications use this port. This port should be open only if you're running a mail server. :STEALTH
113 Ident / Authentication. This service is required by some mail, news, or relay chat servers to allow access. A stealth result on this port could cause performance problems.:STEALTH
119 NNTP (Network News Transfer Protocol). A service used by News servers to distribute Usenet articles to newsreader applications and between other servers.:STEALTH
135 Location service (loc-srv). This port is used to direct RPC (Remote Procedure Calls) services to the appropriate dynamically mapped ports. Hackers can use this to determine which port is used by several Windows services. This port should not be visible from the Internet.:STEALTH
139 NetBIOS. NetBIOS is used for Windows File & Print sharing. If port 139 is open, your computer is open to sharing files over the Internet. Other components of NetBIOS can expose your computer name, workgroup, user name, and other information. To learn more about preventing connections to your NetBIOS ports, see: NetBIOS Information and Configuration Instructions :STEALTH
143 IMAP (Internet Message Access Protocol). IMAP is a sophisticated protocol for electronic mail delivery. This port should be open only if you're running an IMAP server. :STEALTH
443 HTTP over TLS/SSL. A protocol for providing secure HTTP communication. It should be open only if you're running a Web server. :STEALTH
445 Windows NT / 2000 SMB. A standard used to exchange Server Message Blocks, and can be exploited in multiple ways, including gaining your passwords. :STEALTH
1080 SOCKS. This protocol allows computers access to the Internet through a firewall. It is used when one IP address is shared among several computers. Generally this protocol only allows access out to the Internet. However, it is frequently configured incorrectly to allow hackers to pass traffic inwards through the firewall.:STEALTH
1723 PPTP (Point-to-Point Tunneling Protocol). This service is used for virtual private networking connections. :STEALTH
5000 UPnP (Universal Plug and Play). This service is used to communicate with any UPnP devices attached to your network.:STEALTH
5631 pcAnywhere. This port is used by Symantec pcAnywhere when in host mode. :STEALTH
so what do i do about items 21,23 and 80 ?
|
|
|
12-08-2004, 01:29 AM
|
#15 (permalink)
|
|
Apprentice
Join Date: Aug 2004
Location: Relative Time Space
Posts: 84
|
But security : system resources .. which one will you choose?
I think todays sstem can handle the resources needen for zone alarm.
mine is just an amd 1800+ but zone alarm runs fine on it.
__________________
;) ~~EiNsTeIn~~ ;)
http://www.tejuspratap.co.cc
|
|
|
12-08-2004, 06:31 AM
|
#16 (permalink)
|
|
The Photoshop Guy
Join Date: Jun 2004
Location: On Your monitor!
Posts: 562
|
I use Nortorn Firewall. I think it's cool. My other fav's are Sygate Personal Firewall .
..:: peace ::..
Jeba
|
|
|
12-08-2004, 09:11 AM
|
#17 (permalink)
|
|
Wise Old Owl
Join Date: Feb 2004
Location: Palghar, Mumbai
Posts: 1,000
|
Norton Internet Security
__________________
i generally prefer quality over quantity
1 aadi + 1 aadi = 1 full ;)
|
|
|
12-08-2004, 09:16 AM
|
#18 (permalink)
|
|
Wise Old Owl
Join Date: Feb 2004
Location: Palghar, Mumbai
Posts: 1,000
|
also check ur firwalls at
https://grc.com/x/ne.dll?bh0bkyd2
check for common ports and messenger spam
do put ur results here
__________________
i generally prefer quality over quantity
1 aadi + 1 aadi = 1 full ;)
|
|
|
12-08-2004, 09:25 AM
|
#19 (permalink)
|
|
Apprentice
Join Date: May 2004
Location: Chandigarh
Posts: 71
|
well i just shifted to SUSE Linux, so now i'll now see how to configure the firewall inside it.
__________________
~Therez a difference between knowing the path and walking the path ~
|
|
|
12-08-2004, 09:29 AM
|
#20 (permalink)
|
|
Apprentice
Join Date: May 2004
Location: Chandigarh
Posts: 71
|
__________________
~Therez a difference between knowing the path and walking the path ~
|
|
|
13-08-2004, 12:45 AM
|
#21 (permalink)
|
|
Version 2.0
Join Date: Jan 2004
Location: Mumbai
Posts: 977
|
I use my all time fav Norton Internet Security..
no problems at all :d
Deep
__________________
- Deep Ganatra -
www.whoisdeep.com
www.twitter.com/DeepXP/
|
|
|
13-08-2004, 01:47 AM
|
#22 (permalink)
|
|
Alpha Geek
Join Date: Dec 2003
Location: mumbai
Posts: 522
|
well guys i m still waiting for ur responses on hjow to close ports 21,23 and port 80 as these seem to be the trouble makers.
|
|
|
13-08-2004, 07:12 AM
|
#23 (permalink)
|
|
Version 2.0
Join Date: Jan 2004
Location: Mumbai
Posts: 977
|
Quote:
|
Originally Posted by mariner
well guys i m still waiting for ur responses on hjow to close ports 21,23 and port 80 as these seem to be the trouble makers.
|
atually this test will work properly only if you ave Public IP, i.e. with IPs other than 172.16.x.x, 10.x.x.x,172.168.x.x
anyways to cross check these ports... do this..
in IE write this
For Port 80: http://127.0.0.1/
For Port 21: ftp://127.0.0.1
for Port 23
Start - Run - Telnet
in the new window write o 127.0.0.1 it should not show
"Connecting To 127.0.0.1...Could not open connection to the host, on port 23: Connect failed"
if it shows above message then it means you dont have port 23 open..
and for port 80 it should say page cannot be found or something..
21 should say something like unable to connect..
lemme know what happens after u do above things..
Deep
__________________
- Deep Ganatra -
www.whoisdeep.com
www.twitter.com/DeepXP/
|
|
|
13-08-2004, 08:10 AM
|
#24 (permalink)
|
|
Right Off the Assembly Line
Join Date: Jan 2004
Location: [undisclosed]
Posts: 46
|
Quote:
|
Originally Posted by mariner
well guys i m still waiting for ur responses on hjow to close ports 21,23 and port 80 as these seem to be the trouble makers.
|
You can easily do that using a firewall..
If you dont have / want to use it then you can try > portblocker
Just run it, it automatically blocks the ports that u've mentioned (by default)
(:
|
|
|
13-08-2004, 09:20 AM
|
#25 (permalink)
|
|
TE God
Join Date: Jul 2004
Location: Goa
Posts: 88
|
Hey i am using sygate (v 5.5, build 2156) with the latest updates and avg. If you keep updating your firewall just like ur antivirus it will work much better. By the way zonealarm is crap as the free edition takes too much system resources and has a very childish and non-geeky interface. if you can pay Rs.1500 mcafee is great. norton is not bad as well but just too expensive.
|
|
|
13-08-2004, 01:49 PM
|
#26 (permalink)
|
|
Alpha Geek
Join Date: Dec 2003
Location: mumbai
Posts: 522
|
ok guys i got the following from symantec today
How to close ports that should not be open
Situation:
You ran Symantec Security Check or a similar type of security scanning tool and the results indicate that certain "well known" ports are open. "Well known" ports can include any port from 0 to 1023, but the most commonly used ports are 23, 25, 80, and 110.
Solution:
"Well-known" ports are generally reserved for services such as email, Web services, Internet protocols, and so forth. If a security scanner indicates that some of these ports are open and you are not running services related to those ports, then an unknown process - like a Trojan - may be running on your computer.
To correct this situation, run the current version of an antivirus program to detect and eliminate the Trojan, and then install Norton Internet Security or Personal Firewall and re-scan your computer to confirm that the suspect port is now closed.
The following table identifies ports that should not be open unless you are running services (servers) relating to them. If any of these ports are reported as being open, then a component of a service or server may be running on your computer. An example of a service or server component running on your computer is INETINFO.EXE from Microsoft. This component is used to run the Personal Web Server feature of Windows.
Port Service Type of Server Description
23 Telnet telnet server allows another computer to log into yours
25 SMTP mail server email protocol that sends mail out
80 HTTP web server web protocol
110 POP mail server email protocol that receives mail
To determine if INETINFO.EXE is running on your computer, follow one of these procedures:
Windows 95/98/ME/XP
Click Start then Run.
Type MSCONFIG in Open box.
Click OK or press the Enter key. The System Configuration Utility screen will appear.
Select the Startup tab.
See if INETINFO.EXE is running. If you do not need this feature running, uncheck the box then click OK. Reboot your computer and run Symantec Security Check again.
Windows NT/2000
Open the Task Manager by right clicking the Task Bar.
Select Task Manager.
Click the Processes tab.
See if INETINFO.EXE is running. If you do not need this feature running, you must remove the Internet Information Services (IIS) feature from the Add/Remove Windows Components in the Control Panel.
going to try out the same and will post results
|
|
|
13-08-2004, 07:55 PM
|
#27 (permalink)
|
|
Version 2.0
Join Date: Jan 2004
Location: Mumbai
Posts: 977
|
u shall read what i had said in my post..
regards
Deep
__________________
- Deep Ganatra -
www.whoisdeep.com
www.twitter.com/DeepXP/
|
|
|
13-08-2004, 08:39 PM
|
#28 (permalink)
|
|
Alpha Geek
Join Date: Dec 2003
Location: mumbai
Posts: 522
|
ok deep i did what u said and got the following results
port 80 : cannot be found
port 21 : windows cannot access this folder.make sure u have typed the file name correctly and u have the permission to access this folder
details: a connection with the server cannot be established
port 23 :connecting to 127.0.0.1....cud not open connection to the host,on port 23 connect failed.
ok so tell me
1.does it mean that my pc is safe ?
2.and if it so than why do symantec and shields up tell me that my pc is at
gr8 risk?
|
|
|
14-08-2004, 02:28 AM
|
#29 (permalink)
|
|
In The Zone
Join Date: Aug 2004
Location: Bhubaneswar
Posts: 339
|
zone alarm is the best .. but it eats up a lot of resources
u can opt for other options like
tiny firewall
sygate firewall
norton internet security
..[/quote]
I have Used Zone Alarm & I find it slows down the net speed!
|
|
|
14-08-2004, 09:42 AM
|
#30 (permalink)
|
|
Version 2.0
Join Date: Jan 2004
Location: Mumbai
Posts: 977
|
Quote:
|
Originally Posted by mariner
ok deep i did what u said and got the following results
port 80 : cannot be found
port 21 : windows cannot access this folder.make sure u have typed the file name correctly and u have the permission to access this folder
details: a connection with the server cannot be established
port 23 :connecting to 127.0.0.1....cud not open connection to the host,on port 23 connect failed.
ok so tell me
1.does it mean that my pc is safe ?
2.and if it so than why do symantec and shields up tell me that my pc is at
gr8 risk?
|
it means that these ports are already blocked on ur machine..
the reason why norton showing those ports open coz it was checking the IP address of your ISP not yours..
you must have having IP address with 172.16.xx or 10.x.xx.xx or 192.168.xx.xx
to cross check it
start - run - command - write ipconfig
it should show ur ip address
and then go to www.whatismyip.com
it should show the IP address of your ISP..if both are same then you have public IP and otherwise your IP address is private..
about ur 2nd question...
answer is in my above explanation...it's chekcing ur ISP's IP address..no need to worry..install firewall like Norton Internet Security or any other u prefer..shall solve your problem
Deep
__________________
- Deep Ganatra -
www.whoisdeep.com
www.twitter.com/DeepXP/
|
|
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|
|