 ccseifert
join:2001-06-25 Syracuse, NY | Sweet.
Is there anything more ironic than a firewall with a system-takeover vulnerability? |
|
  Mellow Premium join:2001-11-16 Salisbury, MD | Hardware Firewall
Once again, all the more reason to get a hardware firewall. If you want something done right get a good HARDWARE firewall. |
|
  errantmind
@mc.videot | oh well...
Sygate is better anyway  |
|
  GNXPower Got Boost? Premium join:2003-12-18 Huntington Beach, CA | What's the point without specifics...
There is little to discuss or do about this without them. |
|
  Steve I'm a PC, so shut up Consultant join:2001-03-10 Yorba Linda, CA
| said by GNXPower : There is little to discuss or do about this without them.
Sure there is: the vendors have been notified: Pressure them. -- Stephen J. Friedl * Security Consultant * Tustin, California USA * my web site |
|
  Corvus Flaming Tards Since 2003 Premium,VIP join:2003-11-26 | reply to Mellow Re: Hardware Firewall
And good hardware firewall doesn't mean a 50$ router  |
|
 Kip patterson Premium join:2000-10-23 Columbus, OH | Keep in mind the source
These vulnerabilities have been reported by a firm in the business, a competitior of sorts.
They should be confirmed before anyone gets too concerned. |
|
 vic102482 Premium join:2002-04-30 Upper Marlboro, MD | This has been an issue for years
Software firewalls can be at the mercy of the OS. Hacks have been out for years on software firewalls. -- I tie a rope around my penis and jump from a tree, don't you wanna grow up to be just like me!!!! |
|
  KaziSmith Premium join:2001-06-29 Dallas, TX
| whoa FLASHBACK
Wasn't this an issue not more then what, 2 years ago with ZoneAlarm with a master key or something?
Well, at any rate, im glad I run Kerio (It could have a vulnerability too... who knows O.o) |
|
  Soapm
join:2001-07-15 Aurora, CO | Rebrand?
I guess they will just rebrand the firewalls as VPN application's? |
|
 averagedude
join:2002-01-30 Mesa, AZ | reply to Mellow Re: Hardware Firewall
I hear this talked about allot, and I am confused as to what makes a "true" hardware firewall. Could you give a make and model number of an "affordable" unit? |
|
  qdemn7 Smurf in My Loop Premium join:2003-09-16 Fort Worth, TX
| reply to Corvus said by Corvus : And good hardware firewall doesn't mean a 50$ router 
So what would you (and Mellow) reccommend as a "good" hardware firewall? |
|
  coxta Ultramundane Premium join:2000-07-15 LALALALALALA
·Pacific Bell - SBC
| reply to Soapm Re: Rebrand?
A hardware firewall? That's just a box with a stripped down OS. It still uses the same firewall software.
ZA is now owned by Checkpoint. They have the best firewall on the market hands down. I'm sure that if they want to they can put the resources towards resolving this issue. -- If true happiness can only be achieved through a state of nothingness, you're going down the right path. |
|
  koitsu Premium join:2002-07-16 Mountain View, CA | reply to qdemn7 Re: Hardware Firewall
A pair of scissors. |
|
 Tommyastro
join:2004-01-18 Poughkeepsie, NY | reply to Corvus There is NOTHING wrong with a $50 router. I have one and it works just great. Big bucks don't always mean the best.
Try again. |
|
  Da22in Buck Fush
join:2002-06-10 Charlotte, NC clubs: 
| reply to Kip patterson Re: Keep in mind the source
Exactly! Some theoretical vulnerabilities claimed by a competitor. I'm not worried though, seems to be a fad - spout off some fantasy exploit that has never been actually acheived or proven, ITW or otherwise.
This company needs to put up or stfu.  |
|
  Mellow Premium join:2001-11-16 Salisbury, MD
·HostGator
·Cavalier Telephone
| reply to qdemn7 Re: Hardware Firewall
For the best I would go for a PIX. But your everyday consumer cant afford or configure that kind of setup. I recommend something that has SPI and has rule sets. An easy user gui doesnt hurt either. If you want cheap you can find the Netgear FVS318 at staples for $150. I have this installed at a remote office handling VPN with no problems. If you want to go cheaper and have a spare box you can do a smoothwall/ipcop/etc.. linux software firewall. I use ipcop at home and love it, it runs fine on an old cyrix 586 with 64megs in it. Just chunked in 3 nics and configured it, so now I got wan,lan,dmz. You cant beat that price $0. |
|
  XBL2009 ------
join:2001-01-03 Chicago, IL
·AT&T Midwest
1 edit | Horsecrap !
I hate these Doom and Gloom stories that there is a huge hole in the firewall. Most of the time it's just dumb noobs that don't do what there suppose to do like set a password for ZAP or set there folder permissions.
Some basic tips:
1. Use router 2. Use ZAP or other firewall 3. PGP disk containers for important files 4. Surf Encryption and anonymous is available for a cost ! 5. unplug the net when your away from the puter |
|
  MarkAW Barry White or lil bratt Premium join:2001-08-27 Canada
·Bell Sympatico
·Cogeco Cable
| reply to ccseifert Re: sweet
ISS advisory about Checkpoint termed 'inacurate'
"An advisory about vulnerabilities in the popular Checkpoint firewall, put out by Internet Security Systems last week, was inaccurate, a senior Checkpoint official says.
Scott Ferguson, Checkpoint regional director for Australia, New Zealand and the South Pacific, said the advice provided by ISS in its advisory was "not entirely accurate."
"One alleged flaw referred to a key exchange over private networks - this is referring to a three-year-old issue and the installed base has been upgraded a long time ago," Ferguson said." »www.smh.com.au/articles/2004/02/···498.html |
|
  qdemn7 Smurf in My Loop Premium join:2003-09-16 Fort Worth, TX
| reply to Mellow Re: Hardware Firewall
said by Mellow : For the best I would go for a PIX. But your everyday consumer cant afford or configure that kind of setup. I recommend something that has SPI and has rule sets. An easy user gui doesnt hurt either. If you want cheap you can find the Netgear FVS318 at staples for $150. I have this installed at a remote office handling VPN with no problems. If you want to go cheaper and have a spare box you can do a smoothwall/ipcop/etc.. linux software firewall. I use ipcop at home and love it, it runs fine on an old cyrix 586 with 64megs in it. Just chunked in 3 nics and configured it, so now I got wan,lan,dmz. You cant beat that price $0.
Tanks for the info. That Netgear looks like a good deal for $120 @ Newegg. Actually I was thinking of upgrading to Zywall 10W. I've been very happy with my $30 DLink DI604, but I'm always thinking about what's next. -- "It's the squares who know how to fly the fighter planes and operate the missiles and the bombs and work the M-16s. Liberals would still be fumbling with the federally mandated trigger locks." -- P.J. O'Rourke |
|