Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Standards in desktop firewall policies
Phil Kostenbader, CISSP, and Bob Donnelly, CISM, CISSP

Comments Mode:
Standards in desktop firewall policies 2006-06-12
Todd Knarr (1 replies)
Standards in desktop firewall policies 2006-07-03
Anonymous
Picky I know, but "Microsoft Windows doesn't support passive mode" is wrong. To the best of my knowledge it has always supported passive mode when browsing to an FTP url and XP, at least, supports the "quote PASV" command in the DOS FTP client.

Also in your example at the end of Page 1, you state that the firewall does NOT handle outbound UDP properly but your rules prevent inbound UDP packets, so DNS lookups (and any other 2-way UDP application) would fail.

Otherwise a good and useful article, thanks.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1867/601#601







 

Privacy Statement
Copyright 2008, SecurityFocus