ABoyCalledSilly
Guest
Posts: n/a
 
Re: Vista firewall not blocking outbound traffic despite explicit rules to do so
Posted: 02-12-2007, 07:19 PM

Roof Fiddler;180830 Wrote:
> "Rock" <rock@nospam.net> wrote in messag
> news:%23vv91lVTHHA.1228@TK2MSFTNGP06.phx.gbl..
> > "sd321" <sd321@discussions.microsoft.com> wrot
>
> >> In the followin directory is a AdobeDownloadManager
> >
> >> \Program Files\Common Files\Adobe\ESD
> >
> >> Maybe it is doing the update downloading
>
> > On this installation it's in \Program Files\Commo
> Files\Adobe\Udater
> > AdobeUpdater.exe is the file
>
> That was it! Thanks an bunch
> Now I have another question. If this is how Vista works, then doesn'
> i
> mean that outbound rules are useless as a security measure on a syste
> wher
> outbound connections are allowed by default? If a program finds that i
> can't get a connection, all it has to do is create a new .exe file an
> the
> run it, and the new .exe can get to the network. That means on Vista
> i
> order to have outbound security, you have to disallow outboun
> connection
> by default and add rules to allow connections for particular truste
> programs
>
> Wouldn't it make more sense for an outbound rule for a program to appl
> no
> to the program, but to all _processes_ started from that program? (An
> o
> course to children of that process too.) That would solve the problem
> an
> allow outbound connections to be allowed by default without allowin
> blocke
> programs to get around the rules this way
--------------

"Wouldn't it make more sense for an outbound rule for a program t
apply no
to the program, but to all _processes_ started from that program?

Wouldn't it be sweet being able to block a whole directory. ea
"\Program Files\Common Files\Adobe\*.*

And there is an option to block services. Create a new Outbound rule
make it a 'custom' on select services. You either select predefine
ones, or enter your own (use short names). In addition, you could als
specify an IP(range) + Port(range) to shut it down completely..

--
ABoyCalledSill

- windows vista ultimate 64-bit en
---------------------------------------
- cooler master stacker 830
- asus p5b deluxe
- conroe e6600
- 2x corsair memory (twin2x2048-8500c5)
- 3x seagate barracuda 7200.10, 320gb (sata ii, 16mb)
- ati sapphire x1950 pro
- creative x-fi xtreme game
-----------------------------------------------------------------------
ABoyCalledSilly's Profile: http://www.vista64.net/forums/member.php?userid=137
View this thread: http://www.vista64.net/forums/showthread.php?t=3564

Reply With Quote
Rock
Guest
Posts: n/a
 
Re: Vista firewall not blocking outbound traffic despite explicit
Posted: 02-12-2007, 08:08 PM
You're welcome.

"Roof Fiddler" <fiddler@roof.com> wrote
> "Rock" <rock@nospam.net> wrote
>> "sd321" <sd321@discussions.microsoft.com> wrote
>>
>>> In the followin directory is a AdobeDownloadManager :
>>>
>>> \Program Files\Common Files\Adobe\ESD\
>>>
>>> Maybe it is doing the update downloading?
>>
>> On this installation it's in \Program Files\Common Files\Adobe\Udater5
>> AdobeUpdater.exe is the file.
>
> That was it! Thanks an bunch.
> Now I have another question. If this is how Vista works, then doesn't it
> mean that outbound rules are useless as a security measure on a system
> where outbound connections are allowed by default? If a program finds that
> it can't get a connection, all it has to do is create a new .exe file and
> then run it, and the new .exe can get to the network. That means on Vista,
> in order to have outbound security, you have to disallow outbound
> connections by default and add rules to allow connections for particular
> trusted programs.
> Wouldn't it make more sense for an outbound rule for a program to apply
> not to the program, but to all _processes_ started from that program? (And
> of course to children of that process too.) That would solve the problem,
> and allow outbound connections to be allowed by default without allowing
> blocked programs to get around the rules this way.
--
Rock [MS-MVP User/Shell]

Reply With Quote
 
LinkBack Thread Tools Display Modes
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Firewall rules: how to get list of allow program through firewall? Manoj Chanchawat, Symantec Corporation. Windows Vista Security 1 10-18-2006 08:55 PM
Windows Live Messenger - Firewall rules Venkatarangan TNC Windows Vista Networking & Sharing 0 10-12-2006 06:34 PM
Outbound Firewall Rules David Sherman Windows Vista 2 05-12-2006 06:18 PM
PICS Rules/Porno Sites Blocking Waverly Windows XP Security & Administration 0 07-15-2003 10:32 AM
Firewall blocking secure sites? michael keith Windows XP Security & Administration 0 07-09-2003 12:43 AM


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90