Username: Password:
Join  |  Login

Microsoft's OneCare Firewall Draws Fire
Posted by Anonymous 1435 Day ago, There are 11 comments, 9563 views
The firewall component in Microsoft's Windows OneCare security bundle has holes, experts have warned.The security software, available in a public beta version, by default allows applications that use the Java Virtual Machine or have a digital signature to connect to the Internet. Like any blanket security-bypass rule, these default settings are a bad idea, said Mark Curphey, vice president at vulnerability management specialist Foundstone, a part of McAfee.

"Any firewall, any security device should have a default deny," Curphey said in an interview Tuesday. "Any door should always be closed." Curphey discovered the issue when running software on his wife's computer, on which he had installed OneCare. He informed Foundstone security consultant Roger Grimes, who subsequently blogged about it on the InfoWorld Web site. Grimes also blasted the default bypass settings.

News source: ZDNet
Like this story?Spread the news by clicking below:
Add to: Score: (7 ratings) Rating it:

There are 11 additional comments
i dont trust any microsoft security apps/patches. use third party firewall. all doors should be locked... looknstop is the best firewall ;-)
Re: Microsoft's OneCare Firewall Draws Fire by Yabolt on 2006-02-03 00:10:26
Anyone know a patch or update for this integrated firewall?(1 or 2?, compare it with the rest of the firewalls in the market, good marketing and appearance for Microsoft, ehm?)... Ow! Microsoft not make a patch if it no is needed... good appearance... the same appearance of Blaster and the same stupid marketing of good appearance...

Single a gang of useless people who know to sell toys to the children.

RE : by Wanker on 2006-02-03 02:29:42
umm.. what?? please use better english if youre going to try and say.. ANYTHING!
Re: Microsoft's OneCare Firewall Draws Fire by Yabolt on 2006-02-03 06:31:48
Que se resume en comemela con patatas puto guiri hijo de puta. Que vivan los chinos y muerte al puto monopolista lleno de inutiles trabajadores(Microsoft) que lo unico que saben hacer bien es vender programitas con dibujitos a niñatos hijos de puta como tu.

Learn to read, y comemela de paso puto guiri. The color is red, red of chinese communist F U C K E D and perfectly english speaker.
Re: Microsoft's OneCare Firewall Draws Fire by matrix2645 on 2006-02-03 16:33:47
Microsoft runs stronger patches closing loop holes. Using the XP firewall you can set Ports 445, 137-139, 135 etc to use your computers subnet only. When you do this ICMP (Echo 8) will be on by default, but only for your subnet. The XP firewall works well - Use it in conjunction with another firewall if you want, but I use a linkSYS router with built in hardware firewall. Only virus I see is the one from eDonkey or eMule which modifies LSASS and post's it in the run section of your registry. Then ESET NOD32 discover's this and cleans the virus. BTW Chinese people all take english first names, I know many who are very kind and they are our friends and brothers. They run this site which is one of the best,
Anybody want to flame me on this, then confront me face to face and I will kick your ass.......Matrix
Re: Microsoft's OneCare Firewall Draws Fire by victory1908 on 2006-02-13 11:50:18
 This is the first time i post comment in this page
 I'm trying to find the proper firewall and virus scan for my computer
 there are some of my opinion
_ first i tried Mcafee 2006, but then i found they're too slow any require a lot of ram to run (in the process, I see at least 8 mcafee running stimutaneously).
_ second, i tried zonealarm security suit 6, but they doesn't make any effect, they provide too may thing at the same time which make computer run slower, and some of applicants you don't need. but none of them provide absolute protection.
_ Third, i tried norton 2006, but the same problem as mcafee and they occupied many spaces in hard drive.

    I think we only need one good fire wall (include spyware protection), one good virus scan which run at blackground. And we aslo need one spyware program (ex: spyware doctor) to check our computer prediodically and use when the computer is infected.
 
   That my idea and I'm trying to find the solution, can anybody help me?
No Comments Allowed for Anonymous, please login or register
Navigation
RegistryBooster 2009
SPONSORED
Subscribe
Special Topic
Stories Archive