Re: Is it recommended to allow all outgoing connections from your firewall??



--On May 10, 2006 6:22:11 PM -0700 Mark Jayson Alvarez <jay2xra@xxxxxxxxx> wrote:

I've seen most people allow all outgoing traffic
originating from the firewall itself... Is this really
recommended?? What if the machine have been
compromised and the intruder have installed a program
that let's him access the machine remotely by having
the program itself to initiate the outgoing connection
to him thus defying the incoming connection firewall
ruleset...

Because if the machine has been compromised, it doesn't *matter* what the outgoing ruleset is. Or what anything else is, for that matter.

If I hack your box, one of the first things I'm going to do is install a rootkit. Then I'm going to wipe the logs of any evidence of my entry (but leave them intact otherwise), clean my tracks from the shell history file and remove any other evidence of my presence. "Bypassing" your firewall rules is the least of my worries.

Paul Schmehl (pauls@xxxxxxxxxxxx)
Adjunct Information Security Officer
The University of Texas at Dallas
http://www.utdallas.edu/ir/security/


Relevant Pages

  • Re: Service Pack 1 & 2
    ... but enable to install because of service pack 2. ... >> I recently reinstalled Windows XP home on a new hard disk because the ... >> I tried to install service pack 1 but was rejected from doing so. ... > Why you should use a computer firewall.. ...
    (microsoft.public.windowsupdate)
  • Re: Feedback solicited - best way to harden a mail/web server?
    ... Was the system protected by a properly configured firewall? ... it's not a bad "starting point" and it can generate an IPtables rule ... > nor is there a web or ftp server; aside from that I haven't tried to secure ... Before I'll install some nifty application ...
    (comp.os.linux.security)
  • Re: I THINK I HAVE A VIRUS MY ANTIVIRUS SCAN WONT EVEN RUN
    ... install some thing ells like ez antivirus or antivier both ahve free triles ... > your computer online - meaning you likely have usernames and passwords ... > Why you should use a computer firewall.. ... > The system restore feature is a new one - first appearing in Windows ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Downloading updates in advance
    ... Did you enable the firewall in XP ... internet after a fresh install and then go to Windows Updates. ... The Microsoft Windows system contains invalid registry entries and your ...
    (microsoft.public.windowsxp.security_admin)
  • The Trackers First Review Response
    ... Here are the "Malicious Hackers Best ... > hidden firewall applicationto protect their Virtual Private ... > your system for a Backdoor, Trojan Horse, Virus, or Worm until your ... Typically once a system is compromised, there is little need to install ...
    (alt.computer.security)