Recommended Posts

I have windows firewall enabled but that doesn't allow you to block applications from calling home (as far as i'm aware)

Windows 7/Vista firewall have this functionality. Just type Windows Firewall with Advanced Security in the start menu. From this page make a new outbound rule (Right Pane) and simply choose to block the executable of your choice.

Hello,

A software-based application firewall can be useful for screening a notebook computer from attacks when it is connected to an untrusted network, such as a public Wi-Fi hotspot. Same with on a shared private network (dorm, home, etc.).

Regards,

Aryeh Goretsky

I saw Hawk say the same thing but I think it's one of his famous "Java is good" kinda joke again. :rolleyes:

Java is good ZA is not, never was. But then I stopped taking you serious about anything that has to do with code and such anyway since you obviously don't know what you're talking about. and still don't have any arguments beyond "it's bad".

Even back when XP didn't have a decent firewall, there was far better free alternatives, like Tiny.

Zonealarm tried to get extra market share by making several versions of the firewall with differnt added features like anti virus but lost their way in the process.Many years ago it was in my opinion one of the better free products but its just lost so much ground against the competition.

I don't understand why a lot of the so called 'experts' on Neowin seem to be fixated on advising people on using the half baked Windows 7 firewall or not having a firewall at all. By default, the WIndows 7 firewall allows all outbound traffic. You can set it to block outbound traffic but then you will have to manually create a rule for each and every application which you wish to allow access to the internet (talk about tedious). Most annoying of all is that it will not prompt you when a new program wants to establish an outgoing connection.

'Experts' of Neowin, please explain to me how your NAT gateway, your beloved MSE and half baked Windows 7 firewall at default settings will protect against unknown 0-day threats or driveby's from sending out your keystrokes or personal files to the attacker?

Hello,

A software-based application firewall can be useful for screening a notebook computer from attacks when it is connected to an untrusted network, such as a public Wi-Fi hotspot. Same with on a shared private network (dorm, home, etc.).

Regards,

Aryeh Goretsky

Wouldn't Windows' built-in firewall on an up-to-date installation do the job just fine in those situations? At our school and dorm network for example all clients are isolated and can't communicate with each other.

Perhaps someone didn't noticed that the latest version of ZA offers Kaspersky Antivirus for free?

Kaspersky has turned into trash itself. I used to buy a license for it, but quit using it about 3yrs ago. I use MSE and it has only failed me once. But that was my fault, I was beta testing release 2, instead of staying on the stable version.

'Experts' of Neowin, please explain to me how your NAT gateway, your beloved MSE and half baked Windows 7 firewall at default settings will protect against unknown 0-day threats or driveby's from sending out your keystrokes or personal files to the attacker?

That's the job of your AV and heuristics. firewalls are to protect from targeted attacks or remote attacks. at the point when outbund traffic matters, it's to late and the virus will, if it's a decent one, have disabled your FW anyway.

a FW has a purpose, it's not what you think it is.

  • Like 2

I don't understand why a lot of the so called 'experts' on Neowin seem to be fixated on advising people on using the half baked Windows 7 firewall or not having a firewall at all. By default, the WIndows 7 firewall allows all outbound traffic. You can set it to block outbound traffic but then you will have to manually create a rule for each and every application which you wish to allow access to the internet (talk about tedious). Most annoying of all is that it will not prompt you when a new program wants to establish an outgoing connection.

'Experts' of Neowin, please explain to me how your NAT gateway, your beloved MSE and half baked Windows 7 firewall at default settings will protect against unknown 0-day threats or driveby's from sending out your keystrokes or personal files to the attacker?

Where do I even begin to rebuttel this? Let me start with understanding nat and you do not. If you did you wouldn't have this argument.

Nat by default stops incoming attacks against your internal network. All routers do nat. Also many routers support other firewall attributes. Even corp firewalls do not get updates and what have you as often that these pos near useless "firewalls" do.

Your internal network is controlled by you and you allow what attaches to your network so therefore is secure against your neighbors for the most part anyway. I would be more concerned with someone breaking your wireless than someone getting into your network from the Internet.

Also, in case you didn't know, your pos router, that you have no faith in what so ever, has gotten attacked about 5000 times in the time it takes you to read this post. So even though you have absolutely no faith in it, it has done its job in protecting you better than you could have even imagined.

A software firewall is good for protecting you on unsecure networks like hotels, public hot spots, library networks, etc. But on secure networks they are nothing more than unnecessary overhead.

  • Like 3

That's the job of your AV and heuristics. firewalls are to protect from targeted attacks or remote attacks. at the point when outbund traffic matters, it's to late and the virus will, if it's a decent one, have disabled your FW anyway.

a FW has a purpose, it's not what you think it is.

Nothing is flawless including AV heuristics or software firewalls. The first thing a 0-day exploit will do is try to disable any security software on a target machine. If your AV and its self defence succumbs, at least firewall will block all outbound connections if **** hits the fan.

Yes, a software firewall has a purpose. I'd suggest you read up on them instead of making blanket statements

http://en.wikipedia.org/wiki/Personal_firewall

ZA was pretty good back in the day. I would always recommend it along with Sygate and Comodo. But since ZA got brought out, it turned to ****. I think Sygate got brought out earlier too.

Only one that remains today is Comodo, but since the Windows 7 firewall is perfect. Kinda makes Comodo redundant.

ZA was pretty good back in the day. I would always recommend it along with Sygate and Comodo. But since ZA got brought out, it turned to ****. I think Sygate got brought out earlier too.

Only one that remains today is Comodo, but since the Windows 7 firewall is perfect. Kinda makes Comodo redundant.

Sygate was amazing. It's still a shame Symantec bought it and discontinued the free version completely.

Nothing is flawless including AV heuristics or software firewalls. The first thing a 0-day exploit will do is try to disable any security software on a target machine. If your AV and its self defence succumbs, at least firewall will block all outbound connections if **** hits the fan.

Yes, a software firewall has a purpose. I'd suggest you read up on them instead of making blanket statements

http://en.wikipedia....rsonal_firewall

:facepalm:

didn't read m post at all did you ?

Where do I even begin to rebuttel this? Let me start with understanding nat and you do not. If you did you wouldn't have this argument.

Nat by default stops incoming attacks against your internal network. All routers do nat. Also many routers support other firewall attributes. Even corp firewalls do not get updates and what have you as often that these pos near useless "firewalls" do.

Your internal network is controlled by you and you allow what attaches to your network so therefore is secure against your neighbors for the most part anyway. I would be more concerned with someone breaking your wireless than someone getting into your network from the Internet.

Also, in case you didn't know, your pos router, that you have no faith in what so ever, has gotten attacked about 5000 times in the time it takes you to read this post. So even though you have absolutely no faith in it, it has done its job in protecting you better than you could have even imagined.

A software firewall is good for protecting you on unsecure networks like hotels, public hot spots, library networks, etc. But on secure networks they are nothing more than unnecessary overhead.

NAT gateways stop incoming attacks, I think that's something we can agree on. A user instigates what comes in and goes out on a network, yes, but how will NAT help in a driveby malware attack where it goes under the radar of an AV's heuristics? Just so you know, malware does tend to call home.

As for firewalls being good for untrusted wireless networks, the average Neowinian with little knowledge in networking would assume simply running a firewall would protect them which is far from the truth. A software firewall is useless on untrusted networks unless you set it up to block all traffic apart from the port you are tunnelling on. Better advice would be to use a VPN instead.

Why can't you be content what you "think" and help the OP instead.

Has anyone ever thought for a second that if your computer is compromised wouldn't the software that is running in the os be compromised as well?

The way I look at it, if your computer is compromised it is already too late. Just because you get a warm and fuzzy that your software firewall is blocking all outbound communication don't believe it is. If anything that the earlier revisions of za taught me is don't believe it is disabled (because it isn't) and don't believe it is blocking things from communicating (because it isn't).

The only way to be sure is to block it on the hardware level. This has not gotten cheap enough, IMO, for the home network. You want to block outbound and know for sure what your network is doing get a firewall distro like pfsense, monowall, or smoothwall... Once your computer is compromised it is hard to know for sure that the software on it is 100% in tact.

Why don't you install Threat Management Gateway on each computer

I don't understand why a lot of the so called 'experts' on Neowin seem to be fixated on advising people on using the half baked Windows 7 firewall or not having a firewall at all. By default, the WIndows 7 firewall allows all outbound traffic. You can set it to block outbound traffic but then you will have to manually create a rule for each and every application which you wish to allow access to the internet (talk about tedious). Most annoying of all is that it will not prompt you when a new program wants to establish an outgoing connection.

'Experts' of Neowin, please explain to me how your NAT gateway, your beloved MSE and half baked Windows 7 firewall at default settings will protect against unknown 0-day threats or driveby's from sending out your keystrokes or personal files to the attacker?

Why don't you install Forefront TMG 2010 on each client computer that'll keep those nasty outbound connections at bay./s

Overkill much ? centralize all this at the edge firewall.

Not used a software firewall since the basic one introduced with XP SP2, and never been remotely hacked. Almost every ISP will supply you with a router these days and I've always found that works just fine.

NAT gateways stop incoming attacks, I think that's something we can agree on. A user instigates what comes in and goes out on a network, yes, but how will NAT help in a driveby malware attack where it goes under the radar of an AV's heuristics? Just so you know, malware does tend to call home.

As for firewalls being good for untrusted wireless networks, the average Neowinian with little knowledge in networking would assume simply running a firewall would protect them which is far from the truth. A software firewall is useless on untrusted networks unless you set it up to block all traffic apart from the port you are tunnelling on. Better advice would be to use a VPN instead.

Why can't you be content what you "think" and help the OP instead.

I am fully aware that they call home and do not rely on a infected system to tell me that it is communicating out.

A software firewall useless on an untrusted network? Wow this is funny....you clearly have absolutely no clue about anything. This made me chuckle a bit. Please tell me more.....The software firewall bocks communication from anything outside of the computer by default. No other configuration needed. You need to create rules to allow communication with other network computers. Even the windows firewall wants to believe everything other than the host pc is hostile. I am not even touching the VPN comment, it doesn't belong in this convo.

I am fully aware that they call home and do not rely on a infected system to tell me that it is communicating out.

A software firewall useless on an untrusted network? Wow this is funny....you clearly have absolutely no clue about anything. This made me chuckle a bit. Please tell me more.....The software firewall bocks communication from anything outside of the computer by default. No other configuration needed. You need to create rules to allow communication with other network computers. Even the windows firewall wants to believe everything other than the host pc is hostile. I am not even touching the VPN comment, it doesn't belong in this convo.

The irony is that one of his replies(in fact the one to me where I brought up that exact issue) is that viruses will disable your security systems so you need your software firewall to protect you ... which isn't it's purpose in the first place, and somehow it magically didn't get deactivated, which is even more interesting since most software firewalls allows local software to self allow themselves without malicious intent, and as malicious software it would most certainly disable both AV and FW among other systems.

heck even non call home malware and bad ware I clean from clients computers usually have any firewall completely disabled or usually broken. it's far more common for malware to break the firewall than the AV which is often just disabled.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Stellarium 26.2 by Razvan Serea Stellarium is a free open source planetarium for your computer. It shows a realistic sky in 3D, just like what you see with the naked eye, binoculars or a telescope. It is being used in planetarium projectors. Just set your coordinates and go. Stellarium key features: Realistic simulation of the sky, sunrise and sunset Default catalogue of over 600,000 stars Downloadable additional catalogues for up to 210 million stars Catalog data for all New General Catalogue (NGC) objects Images of almost all Messier objects and the Milky Way Artistic illustrations for all 88 modern constellations More than a dozen different cultures with their constellations Solar and lunar eclipse simulation Photorealistic landscapes (more are available on the website) Scripting support with ECMAScript (a few demo scripts are included) Extendable with plug-ins: 8 plug-ins installed by default, including: artificial satellites plug-in (updated from an on-line TLE database) ocular simulation plug-in (shows how objects look like in a given ocular) Solar System editor plug-in (imports comet and asteroid data from the MPC) telescope control plug-in (Meade LX200 and Celestron NexStar compatible) The major changes of this version: Added new sky culture Added new plugin: Planes Many improvements in plugins Many improvements in Core and GUI Many updates in sky cultures. [full release notes] Download: Stellarium 26.2 (64-bit) | 456.0 MB (Open Source) View: Stellarium Home Page | Other Operating Systems | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • NASA: This asteroid may not kill us but it probably won't be far off either by Sayan Sen Image by Zelch Csaba via Pexels New observations by NASA's James Webb Space Telescope have eliminated the last remaining impact threat posed by asteroid 2024 YR4, ruling out the possibility that the near-Earth object could strike the Moon in December 2032. NASA said observations collected by Webb on February 18 and 26, 2026, enabled scientists to refine the asteroid's orbit enough to "rule out a chance of lunar impact on Dec. 22, 2032." Instead, asteroid 2024 YR4 is now expected to pass the Moon at a distance of about 13,200 miles (21,200 km). The agency stressed that the update "reflects improved precision in our understanding of where the asteroid is expected to be in 2032 rather than a shift in its orbital path." The announcement closes a remarkable chapter in planetary defence that began in late 2024, when the approximately 60-metre-wide asteroid briefly became the most closely watched near-Earth object in the world. Discovered on December 27, 2024, by the ATLAS telescope in Chile, 2024 YR4 initially appeared to have a small chance of colliding with Earth on December 22, 2032. As astronomers gathered more observations, the impact probability briefly climbed to around 3%—the highest ever recorded for an asteroid of its size—before steadily falling as its orbit became better understood. By early 2025, international observations had ruled out any significant risk to Earth. However, astronomers were left with another possibility: a roughly 4% chance that the asteroid could instead strike the Moon. "The probability that asteroid 2024 YR4 will strike the Moon on 22 December 2032 is now approximately 4%," the European Space Agency (ESA) had said last year, noting that "there is a 96% chance that the asteroid will not impact the Moon." ESA said such an impact, while unlikely, would have presented an extraordinary scientific opportunity. "It is a very rare event for an asteroid this large to impact the Moon – and it is rarer still that we know about it in advance. The impact would likely be visible from Earth, and so scientists will be very excited by the prospect of observing and analysing it," said Richard Moissl, Head of ESA's Planetary Defence Office. "It would certainly leave a new crater on the surface. However, we wouldn't be able to accurately predict in advance how much material would be thrown into space, or whether any would reach Earth," he added. The asteroid also exposed an important blind spot in planetary defence. Because 2024 YR4 approached Earth from the direction of the Sun, it remained hidden from ground-based telescopes until after its closest approach. "We looked into how Neomir would have performed in this situation, and the simulations surprised even us," Moissl said. "Neomir would have detected asteroid 2024 YR4 about a month earlier than ground-based telescopes did. This would have given astronomers more time to study the asteroid's trajectory and allowed them to much sooner rule out any chance of Earth impact in 2032." He added, "As an infrared telescope, like Webb, Neomir would have also immediately given us a much better estimate for the asteroid's size, which is very important for assessing the significance of the hazard." The latest NASA observations underscore the value of space-based infrared telescopes in tracking faint asteroids. According to NASA, Webb made "among the faintest ever observations of an asteroid," extending the object's observational record by nearly eight months at a time when it had become too faint for other telescopes. That additional data allowed scientists to eliminate the remaining uncertainty surrounding its 2032 flyby. Although asteroid 2024 YR4 is now confirmed to pose no threat to either Earth or the Moon, scientists say its discovery remains one of the most significant real-world tests of the international planetary defence system, demonstrating how continued observations can rapidly transform an object once considered hazardous into one whose future path is known with high confidence. Source: NASA, ESA This article was generated with some help from AI and reviewed by an editor. Under Section 107 of the Copyright Act 1976, this material is used for the purpose of news reporting. Fair use is a use permitted by copyright statute that might otherwise be infringing.
    • Yup. Google is just scraping the entire internet for their own ad profits without sharing revenue with the sources. It's obviously stealing, but since these sites depend upon Google's search scraps to survive... As for me, I just stopped using Google for anything except Reddit searches. If Reddit's own search wasn't complete crapola, I'd never use Google search again.
  • Recent Achievements

    • Conversation Starter
      Admir earned a badge
      Conversation Starter
    • First Post
      The_Focal_Point earned a badge
      First Post
    • Apprentice
      daryld went up a rank
      Apprentice
    • Contributor
      Carltonbar went up a rank
      Contributor
    • One Month Later
      The_Focal_Point earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      418
    2. 2
      +Edouard
      170
    3. 3
      PsYcHoKiLLa
      130
    4. 4
      Xenon
      69
    5. 5
      neufuse
      69
  • Tell a friend

    Love Neowin? Tell a friend!