Showing posts with label firewall. Show all posts
Showing posts with label firewall. Show all posts

Wednesday, 31 October 2012

Free Personal Firewall: The Door To Your Computer

What is Firewall

Firewall is either a software or hardware gate to the computer or computer network. So it is very easy to compare the Firewall to the gate that limits access to the personal property in terms of estate: house, garage and any other building within the area that is your personal property. To be more precise, the Firewall is like a gate and its guard in one: it restricts the access to the computer or computer network by examining the incoming and outgoing data traffic from other network which, on most cases, is the Internet. In order to be capable of doing what it is supposed to do, Firewall needs to have rules set. For both, Windows and Linux Firewalls, you would have some basic rules set by default.
Now, on the network there may be peripheral devices that can be accessed from trusted computers on the network, and this is where we are figuratively talking a property that consists of few different buildings. The topic of this post however is not the Network Firewall where it usually works together with Network Intrusion Detection and Prevention System to keep the network of computers as safe and protected as possible. Such a topic doesn't apply to basic Computer Security essentials, and is a discipline of IT Professionals. We will take a look at free Personal Firewall, and some tests that can be run to ensure that your personal computer meets good security standards.


How Does Firewall Work?

Digital Communication

Every Computer Network, including the biggest one in The World, The mighty Internet, is essentially a network of communications. Nothing more than that... and nothing less. Computers communicate with each other by sending and receiving data packets. That is their way of communicating. Today's world basically has a parallel, digital dimension that consists of the traffic of millions of data packets. In order for computers to understand each other, there are various Communication protocols in place. This is the reason why you would need, for example, a Skype application instead of MSN Messenger installed and running on a Windows machine in order to communicate with someone who is using Skype on their computer. So where does Firewall come into play?

Data Packet

In this post I refer to the unit that is sent from one computer to another as the 'data packet'. It contains essential communication information such as destination IP address, communication protocol in use and few other things. One of the main Firewall's tasks is to analyze contents of these data packets: whether the right protocol is being used for a specific communication port, whether the IP address, the packet is supposed to be received by, has actually anything to share with the sender of that packet, and what type of software application is involved in exchange of these data packets. For years this has been a point where basically the common things between Firewall software of Windows OS and that of Linux OS's end. While Linux has got Firewalls based on IP Table filtering, Windows OS has had different requirements regarding its security because of the differences in how each of these Operating Systems have been designed and developed.


Further in this post we will deal exclusively with Windows Security by taking a look at typical Firewall features on Windows machine. The product I have chosen as an example is Online Armor by Emsisoft. Not only it's an outstanding paid solution for those who would like to take full advantage of its additional security features, it's also one of the best free Win Firewalls out there.

Online Armor: Free Cutting Edge Firewall

This Firewall software does not lack a single thing any other free Firewall worth its name would be able to provide. Besides, Emsisoft have been working hard for years to provide Windows computer users and administrators with additional free and effective computer security tools, and the fact that one of them, Anti-Malware, the name that speaks for itself, is among the means of keeping your Windows machine protected, adds to the strength of Online Armor's effectiveness.



Firewall. The section where you manage communication ports on your Win computer, and networks your computer gets connected to. You can easily allow or block access rights for programs to access the Internet here. You can see all the associated program files that have the right for Internet access: protocols and ports they use.
Domains. This section is very much like a Windows Hosts file that allows you to list domains that you'd rather not want to be connected to. Editing the actual Hosts file is not a recommended practice for someone who's not an advanced computer user therefore the opportunity to simply save an unwanted domain name here makes things very convenient and simple.
Programs. Allow, Block or Run Safer any installed program on your computer. The Firewall is also able to detect Hidden running processes on your computer. For a full list of Program Options please see the Screenshot:


Autoruns. The list of all the System and Program Files that are allowed to start automatically (like scheduled Java Update, for instance). Block or Delete them easily here.
Anti-Keylogger. Online Armor automatically detects files and programs that might have keystroke recording capability (your usernames, password, web addresses, email addresses, phone numbers given to others, bank security details?). Those programs and files, if any, will be listed here.
Hosts File. Monitors and keeps a record of the changes made to the Windows Hosts File, if any.
History. List of alerts made by Online Armor, and the response action taken by you.
Options. Firewall Software general configuration settings.


Why Firewall is mandatory for every PC regardless of Operating System?

There is no Data and Computer Security expert who wouldn't advise on having a Firewall installed on your computer unless they would want you to see what happens in about week's time after you've been connecting to the Internet without a Firewall on your machine. The list of Online Armor features provided earlier basically contains answers to the question: why would I need a Firewall on my computer? After all, Firewall is just another software application using my computer's resources, and asks annoying and repetitive questions every time I install new software on my computer. Well, just as it is in the real world, there are people in the Digital one who wouldn't want to miss the opportunity to take advantage of someone else. For whatever reasons. And then there are people who just love challenges and games, and for them hacking techniques might be simply an interesting game. Regardless of anyone's personal motives, here are few ways modern Personal Firewall makes life more difficult for online criminals:
  • It reduces to a minimum the possibility for malicious software to be installed and run without your consent;
  • It doesn't allow scanning for available communication ports on your computer;
  • It reduces unwanted connections to a minimum.
So we can certainly say that Firewall is a tool that lets you be in control. However, it's not a guarantee for your machine to be invincible. Why? Read more in my other post about how computers get infected.

Test your computer's visibility from hacker's view online

There are quite a few excellent options for testing your computer's Firewall, visibility, state of your ISP's DNS and your computer's communication ports, all to be found at Gibson Research Corporation Website. Look for Services / Shields Up! if you want to see if matters related to your network connections are in Stealth Mode (i.e. in a good condition). Look for some other no less brilliant free things on their website including secure password generators and DNS spoofability Test.

Saturday, 31 March 2012

How Windows pc and Mac systems get infected

Why Windows malware is not posing a threat to Linux system

In this post I will make an attempt to create a synopsis of usual ways malware makes its way into Windows or Mac system. I am referring specifically to Win/Mac because the vast majority of viruses and other malware is created for these two aforementioned Operating Systems, MS Windows being particular favourite of malware writers due to its large share of OS market (that is, if we are not talking mobile phones at this point).
Malware that has been created for Windows pc, is designed for Registry based OS, and neither Linux or Unix is one, therefore, cannot become affected by it (that is one of the few reasons why I absolutely love Linux). Even though malware can affect only OS it has been designed for, there are couple of things often shared by all three most popular computer Operating Systems (as well as those found in majority of mobile smartphones): Adobe Flash and Sun Java. (In case of Linux the use of Adobe product is less common though.) Even though HTML5+DOM coding in website development is expected to eventually make the use of Flash obsolete, currently that is not the case.

Top weaknesses that can cause infection

1. Unpatched security holes.

Operating system, software and its components are always a subject to exploitation because nothing is ever 100% perfect. If latest updates are not installed, the coding and design vulnerabilities in software applications and operating system are posing a risk of being abused by malware writers. Internet browsers, Adobe products, Sun Java, Windows Media Player, Apple Quicktime all have to be updated on regular basis.
Adobe products. Adobe Reader is usually installed with Speed launcher. This feature is loaded during Windows start-up thus prolonging the OS loading and storing the associated .exe file in Applications' folder where it may simply be another useless file which may be exploited during malware attack on the system. By reading this short article you can decide whether you really need this feature. More on Adobe Acrobat Reader related security issues here.
Adobe Flash is another subject to exploitation if not kept updated. Hackers are known to exploit Flash vulnerabilities which can lead to malware infection. When visiting a website that hosts a HTML page which requires a Flash script, users may encounter a malicious Flash redirector, or malicious script written to exploit vulnerability in the Flash Interpreter which causes it to execute automatically in order to infect the computer. Flash vulnerabilities are directly related to Web application and casual online gaming security. More extensive overview on this subject can be found here.
Java, if not kept updated, is the most common way of infecting computer with trojans while browser is rendering a HTML code at some dodgy adult or software cracking tools' website. It must be noted that most exploited vulnerability on such an occasion is previous Java version that has not been uninstalled after the new, updated one has been downloaded and installed. You can check whether you have two Java versions in your Windows pc by going to Control Panel and opening Add/Remove Programs. If you do have two Java updates listed, it is recommended that you uninstall the older one. You can check your system's Java status here.

2. Javascript enabled for all sites.

Regardless of the Web browser you are using, a Javascript can make your system less secure if enabled to run on all sites. The safe way of using Javascript is to enable it exclusively for trusted sites. Javascript is often the cause of malicious redirects to a site with either a malicious content or an intent to boost the incoming traffic.

3. Online game servers.

Because of the design of the online game architecture, firewalls and anti-malware software sometimes can't detect intrusions. That provides an opportunity for hackers to abuse the victim's machine by using online bots and rootkit-like techniques. More info on data and computer security threats related to online gaming can be found here.

4. Torrent, P2P (Peer-to-Peer) networks, File Sharing programs.

Connection to these networks is making the system susceptible to remote attacks and probability of downloading infected, malicious files. That in turn can lead to identity thefts. Malicious worms, backdoor Trojans, IRCBots and rootkits spread across P2P file sharing networks, gaming, dodgy adult and underground sites.

5. Infected files on USB and other storage media.

An Autorun.inf file can cause much trouble. More about this threat and how to avoid it you can read here.

6. Clicking unsolicited links in e-mail and Instant Messenger chats.

For more info as to why such links are being sent and what consequences such actions can have please see my previous posts here and here.

7. Rogue antivirus / antimalware software.

This includes clicking on pop-ups or banners that claim your computer is infected. All about rogues you can read in one of my previous posts here.

8. Backing up infected files.

A logical cause of re-infection.

9. Assuming that antivirus and/or firewall are not needed, or that they are providing 100% protection.

Two extreme assumptions that both can result in computer not being protected against cyber threats. On the first occasion, it is most likely that such a computer's owner won't even get that far as to visit this website to read this article, therefore, I am going to address the second assumption by saying that even protected machines get infected. Otherwise malware writers wouldn't waste their time on doing what they do. Here is an excerpt from Ivizsecurity.com blog:
Security products like anti-virus, firewalls, IDS/IPS and VPN have become of paramount importance to provide highest degree of confidentiality, availability and Integrity (CIA) to individuals and organizations. However, it is foolish to assume that security products are free from any vulnerability (security flaws). Security Products can also be of target of attacks from the attackers.
  By assuming that Anti-virus and Firewall will do the trick of fully protecting the machine, we risk to return to the beginning of this list, e.g. unpatched security holes.

Download and test these products for free for 30 days:
Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall

Tuesday, 28 February 2012

Anti Malware for Windows Server 2003 and 2008


This product from Emsisoft can be a real treat for IT administrators and a solution, worth considering in business environment. Particularly at large organizations that depend on multiple interconnected computer networks that have to be secured for safe and optimal functioning. As is the case with all the Emsisoft products, this one too comes with 30 day money back guarantee and can be obtained with considerable discounts ranging from 25 to 75 percent, depending on the number of machines it is obtained for. There is also a free trial version of the software available for download so that you can test the product before deciding on purchase.
Anti Malware for Server comes with:
  • dual scan engine consisting of: E1/A2 Emsisoft Anti-Malware engine, and E2/IK Ikarus Anti-Virus engine: a combination that works as 2 in 1;
  • File Guard that works as a real-time shield and compares every file downloaded to known malware patterns. As soon as infected file is detected and quarantined/deleted, a notification email is sent to administrator;
  • HiJack Free, an integrated software designed for professionals to monitor autorun and running processes, services, port configuration, installed ActiveX objects (can be submitted for online analysis), LSP Protocols;
  • Command-line scanner which is the same anti malware scanner without GUI.
This product can be run alongside other Anti Virus software and Firewall causing no conflicts or system failures. In case a technical problem arises the publisher's support team is always available to assist in solving it quickly and professionally.

To download the trial version click here. If you'd like to order the product electronically or by postal mail click here.

You might also want to consider these products:
Internet Security Pack: AntiVirus+Firewall
Online Armor Premium Firewall