CurlyWhirly Posted March 30, 2005 Report Share Posted March 30, 2005 I have run the Shields Up test at Click here, and according to the test all of the ports are in Stealth Mode (See screenshot) I know that there are 3 possible states for a port, on, off or stealth. I was always lead to believe that it is impossible to be invisible on the internet, as without displaying your IP address, no one would be able to communicate with you as this information is fundamental to the way the internet works, or have I missed something here? :unsure: Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 30, 2005 Report Share Posted March 30, 2005 Hi CurlyWhirley,Your assumption that your Internet IP can't be invisible is not necessarily correct. A properly configured firewall without any need for any static mappings (a DNS Server or E-mail Server, for example) can be made invisible to outside requests. That means unsolicited packets (pieces of Internet traffic) hitting your outside interface will not receive interaction of any kind from the firewall. They will all be silently dropped, which would mimic the results of a port scan to an IP with nothing attached to it.If your PC wants to go to the Internet, the return traffic from the server you're hitting is allowed back through the firewall because you requested it. It's kind of like a check valve, but it selectively lets some traffic (traffic you specifically requested) return.Hope that answers your question. Excellent results on ShieldsUp! :) Did you ask for All Service Ports or Common Ports? Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted March 30, 2005 Author Report Share Posted March 30, 2005 Hope that answers your question. Excellent results on ShieldsUp! :) Did you ask for All Service Ports or Common Ports?Thanks for replying homecomputeraid Yes your reply does indeed answer my query.By the way, I used the All Service Ports option :) Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted March 30, 2005 Author Report Share Posted March 30, 2005 Just another query :blush: These types of software firewalls are only designed to stop a casual hacker are they? It's just that I have read that a determined hacker can bypass any software firewall if he/she has the 'know how', is this true? It must be an awesome task to 'hack' a PC when it is 'virtually' invisible! :huh: Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 30, 2005 Report Share Posted March 30, 2005 I think the hacker would have to know what kind of firewall you're using, which may be difficult to determine. Some active port scanners try to guess about the operating system and/or firewall by the types of responses to certain queries. I'm more comfortable with a hardware firewall and a software firewall. The disadvantage of a software firewall is that your PC is exposed to the Internet, and if there's a weakness in either the OS or the software firewall, you can be vulnerable. Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted March 30, 2005 Author Report Share Posted March 30, 2005 I think the hacker would have to know what kind of firewall you're using, which may be difficult to determine. Some active port scanners try to guess about the operating system and/or firewall by the types of responses to certain queries. I'm more comfortable with a hardware firewall and a software firewall. The disadvantage of a software firewall is that your PC is exposed to the Internet, and if there's a weakness in either the OS or the software firewall, you can be vulnerable.I would like to buy a hardware firewall, as I am online on a broadband connection for long periods of time. If I was only on dial-up and online for short sessions then I wouldn't worry!Are they simple to setup as I am not really a computer savvy person, and also how come a software firewall doesn't conflict with a hardware firewall (as in your case)? Finally, if a hardware firewall is so good, then why do you feel the need to run a software firewall as well? :huh: Just curious :rolleyes: Quote Link to comment Share on other sites More sharing options...
Redhat Posted March 30, 2005 Report Share Posted March 30, 2005 I think the hacker would have to know what kind of firewall you're using, which may be difficult to determine. Some active port scanners try to guess about the operating system and/or firewall by the types of responses to certain queries. I'm more comfortable with a hardware firewall and a software firewall. The disadvantage of a software firewall is that your PC is exposed to the Internet, and if there's a weakness in either the OS or the software firewall, you can be vulnerable.I would like to buy a hardware firewall, as I am online on a broadband connection for long periods of time. If I was only on dial-up and online for short sessions then I wouldn't worry!Are they simple to setup as I am not really a computer savvy person, and also how come a software firewall doesn't conflict with a hardware firewall (as in your case)? Finally, if a hardware firewall is so good, then why do you feel the need to run a software firewall as well? :huh: Just curious :rolleyes:Just a NAT Router supporting SPI which would suffice, easy to set up only get a wireless version if you intend to use wireless, otherwise buy a wired router with NAT and SPI, bring it home, plug in power supply, plug in modem cable to router, plug in computer cable to router, and VOILA :D (God that was a long sentence!!!) And software firewall for outbound protection.To confuse you more, theres no actual such thing as a hardware firewall, just a dedicated firewall, because a "hardware firewall" is just hardware with firewall software on :lol: Quote Link to comment Share on other sites More sharing options...
Redhat Posted March 30, 2005 Report Share Posted March 30, 2005 To follow up, the reason for a "hardware firewall" is that if it's compromised, the router is compromised, not your system. Unless you are not running a software firewall on the workstation. Another reason to use both :) Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted March 30, 2005 Author Report Share Posted March 30, 2005 To confuse you more, theres no actual such thing as a hardware firewall, just a dedicated firewall, because a "hardware firewall" is just hardware with firewall software on :lol:Don't worry as it doesn't take a lot to confuse me! :lol: On a more serious note, thanks for the explanation RedhatI wonder whether I am worrying about nothing as Powerless doesn't use a Firewall :o well at least he never used to :unsure: Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 30, 2005 Report Share Posted March 30, 2005 Maybe Powerless will post his outside IP address and we can give him a reason to start using firewalls. Some ethical hacking? :) Just kidding Powerless! I hope you do use some kind of firewall though.Just splitting hairs here, but I'm going to disagree with Redhat about there being no such thing as hardware firewalls. By that definition, nothing would be "hardware" except my toaster... wait, is there a microchip in there? :)I define a hardware firewall as a device that's specifically made to be used as a firewall (well, for the most part routing and firewalling), with a hardened operating system designed to let the hardware do its job. I agree with Powerless that a router/firewall is a good step, but if it's compromised, a software firewall can be one more hurdle for the attacker to overcome. The software firewall should also warn you somehow when an unknown or disallowed program tries to access the Internet which gives you a heads up that you might have spyware or a virus. Hardware firewalls (my definition here :)) are very often set to allow anything out without logging. Quote Link to comment Share on other sites More sharing options...
Redhat Posted March 30, 2005 Report Share Posted March 30, 2005 Touché :D :lol: Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted March 30, 2005 Author Report Share Posted March 30, 2005 I agree with Powerless that a router/firewall is a good step, but if it's compromised, a software firewall can be one more hurdle for the attacker to overcome. The software firewall should also warn you somehow when an unknown or disallowed program tries to access the Internet which gives you a heads up that you might have spyware or a virus. Hardware firewalls (my definition here :)) are very often set to allow anything out without logging.So it does seem that two firewalls are better than one then! A software and a hardware one I mean, not 2 software firewalls as they would conflict with one another.Touché :D :lol::uhm: Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 30, 2005 Report Share Posted March 30, 2005 I think Redhat's touche refers to this:Just splitting hairs here, but I'm going to disagree with Redhat about there being no such thing as hardware firewalls. By that definition, nothing would be "hardware" except my toaster... wait, is there a microchip in there?Do you understand why the Hardware and Software Firewalls won't conflict? They're separate entities that won't even know of each other's existence. Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted March 30, 2005 Author Report Share Posted March 30, 2005 Thanks for explaining that to me homecomputeraid, I wouldn't have got the joke in a million years! :rolleyes: Quote Link to comment Share on other sites More sharing options...
Redhat Posted March 31, 2005 Report Share Posted March 31, 2005 Sorry for completely confusing this thread :blush: Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 31, 2005 Report Share Posted March 31, 2005 I think we both strayed into our own discussion, but CurlyWhirly probably learned a lot. :) Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted March 31, 2005 Author Report Share Posted March 31, 2005 Sorry for completely confusing this thread :blush:There's no need to apologise, as I am always going off topic myself :rolleyes: I think we both strayed into our own discussion, but CurlyWhirly probably learned a lot. :)Yes, I now know more about firewalls then I did before I asked the question ;) Do you understand why the Hardware and Software Firewalls won't conflict? They're separate entities that won't even know of each other's existence.Yes, I get it now. Thanks. :) Finally would you know of a site in the UK where I can buy a hardware firewall from? If so, would you know if it would be compatible with AOL?I know AOL has a bad reputation, but I am happy with their service as I have never had a major problem (yet anyway) :rolleyes: Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 31, 2005 Report Share Posted March 31, 2005 I don't know a UK site, but there should be people who can help with that. Make sure the router's capable of PPPoE, and you may need some assistance setting that up for use on AOL Broadband. Here's a link to a Linksys Router/Firewall. Maybe you can find that model on a good UK site?http://www.linksys.com/products/product.asp?prid=433&scid=29 Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted March 31, 2005 Author Report Share Posted March 31, 2005 I have just realised that I am running on a proxy server as explained in another thread Click here I did a Google and up came a definition of a proxy server:Proxy servers have two main purposes: improve performance and filter requests.It also acts as a firewall, mediating traffic between a protected network and the internet. As mention of the proxy server also acting as a firewall, would someone suggest that a software firewall is all I really need, as I don't want to spend money on a hardware firewall if it's not really necessary? :rolleyes: Quote Link to comment Share on other sites More sharing options...
homecomputeraid Posted March 31, 2005 Report Share Posted March 31, 2005 Proxy servers can provide security. That doesn't mean they necessarily do. Does your ISP own the proxy server? If so, it's very unlikely that it provides much security. If you don't want to buy a firewall, just make sure you have software firewalls on all PC's that connect to the Internet. Quote Link to comment Share on other sites More sharing options...
CurlyWhirly Posted March 31, 2005 Author Report Share Posted March 31, 2005 Proxy servers can provide security. That doesn't mean they necessarily do. Does your ISP own the proxy server? If so, it's very unlikely that it provides much security. If you don't want to buy a firewall, just make sure you have software firewalls on all PC's that connect to the Internet.I don't know whether AOL actually own the proxy server :unsure: I only have the one PC and I always keep my anti-virus definitions up to date, as it is configured to run automatically. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.