Windows firewall, why does it suck, exactly?

Our very own fight club!
Post Reply
User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Windows firewall, why does it suck, exactly?

Post by ayu »

Ok, on my Windows computer I use the Windows firewall, just because I only use Windows to play some games once in a while, so don't see a need for anything else.

Thing is, that every time I mention that I use it, someone always says something along the lines of "awwww man windows firewall SUCKS!! so buggy and full of holes!"

So....why does it really suck? The only reason that I think it's bad is because it can create trouble sometimes when allowing applications to pass it. But nothing more then that. So, is it really that bad? can it really be bypassed as easy as people say?

And are there any other reasons to why people hate it so much?
"The best place to hide a tree, is in a forest"

User avatar
DNR
Digital Mercenary
Digital Mercenary
Posts: 6114
Joined: 24 Feb 2006, 17:00
18
Location: Michigan USA
Contact:

Post by DNR »

I just rather not use the firewall that came with the OS, I just trust another third party to monitor the OS. When I did use it, I thought it was too easy - it doing all the work for me, and yet not explaining what it did.
I like comodo.com.

DNR
-
He gives wisdom to the wise and knowledge to the discerning. He reveals deep and hidden things; he knows what lies in Darkness, and Light dwells with him.

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

well, the earlier versions (before SP2) REALLY sucked because there were loads of bugs, so it couldn't even be called a real firewall.
ok, the later versions seem to be better, but still outgoing connections can not be processed (what a surprise, users might block traffic to MS).
also the possibilities in packet processing are very limited compared to iptables....packet size, flags set, etc,...all this can't be utilized for rules in the MS firewall.
the maybe biggest problem is the fact that TCP/IP is still nothing but an application in MS and not implemented in the kernel like on *nix, and because of this the risk of potential flaws is much bigger.
there must not be even a flaw in the firewall app itself, a flaw in the underlying applications could make the whole firewall useless, on a *nix system there must be a kernel bug to make the firewall exploitable.....which is much more unlikely than a bug in an application, and such bugs are usually also much harder to exploit (at least it's nothing the average skiddy can do).

User avatar
F4LSE
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 236
Joined: 02 Jul 2007, 16:00
16
Location: My Lab
Contact:

Post by F4LSE »

its made by windows... thus... sucky :)

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

Diagnol wrote:its made by windows... thus... sucky :)

Thought you said you used Vista :roll: the king of suck ^^
"The best place to hide a tree, is in a forest"

User avatar
Lyecdevf
cyber Idi Amin
cyber Idi Amin
Posts: 1222
Joined: 16 Mar 2006, 17:00
18
Location: In between life and death.
Contact:

Post by Lyecdevf »

I like to have a look at the logs from my firewall. In windows as far as I know that is not possible. It just sits there doing its job but I need more than that. Especially if I want to experiment with stuff. For instance I once put a windows box with ZoneAlarm on my LAN and port scanned from my linux box also on the LAN just for fun. ZoneAlarm of course showed me the logs of the event. No such thing is going to happen with the windows firewall. So I guess for experimental purposes the windows firewall is useless.
We will either find a way, or make one.
- Hannibal

User avatar
Stavros
ΜΟΛΩΝ ΛΑΒΕ
ΜΟΛΩΝ ΛΑΒΕ
Posts: 1098
Joined: 02 Jan 2006, 17:00
18
Location: Mississippi, U.S.A.

Post by Stavros »

Under Control Panel > Windows Firewall > Advanced tab the windows firewall is located at C:\WINDOWS\pfirewall.log. Of course you can change this to you're liking. All you'll need is something like Notepad or Wordpad to view the log file. That's simply for windows XP. I wouldn't know how to do it for Vista.

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

Stavros wrote:I wouldn't know how to do it for Vista.
Oh that's easy, just break into Microsoft's mother computer, and look for a file called "Big Brother Project 666", you'll find all your logs there I assure you.
"The best place to hide a tree, is in a forest"

User avatar
F4LSE
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 236
Joined: 02 Jul 2007, 16:00
16
Location: My Lab
Contact:

Post by F4LSE »

cats wrote:
Diagnol wrote:its made by windows... thus... sucky :)

Thought you said you used Vista :roll: the king of suck ^^
ouch, caught me red-handed. :p

There should be a vista support group.

Hi my name is Diagnol and im a vista user... :oops:

User avatar
Lyecdevf
cyber Idi Amin
cyber Idi Amin
Posts: 1222
Joined: 16 Mar 2006, 17:00
18
Location: In between life and death.
Contact:

Post by Lyecdevf »

Diagnol wrote:Hi my name is Diagnol and im a vista user... :oops:
8O

Well to keep the discussion on the firewall, I have heard that Vista has a pretty good firewall. They put a lot of thought into security but forgot about the rest! :(
We will either find a way, or make one.
- Hannibal

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

Lyecdevf wrote: They put a lot of thought into security but forgot about the rest! :(

Actually I think that if you call Microsoft and ask them about the security in Vista, they'll answer ".....what?"

Anyway....


So, before SP2, was there any known exploits in the Windows firewall? and are there any now?
"The best place to hide a tree, is in a forest"

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

one or two can be found here.
^^

User avatar
ayu
Staff
Staff
Posts: 8109
Joined: 27 Aug 2005, 16:00
18
Contact:

Post by ayu »

bad_brain wrote:one or two can be found here.
^^

wow, damn xD

Well, I most likely wont have to use the Windows firewall anymore soon anyway, since my Linux gaming tests are going excellent at the moment ^^ (check Linux board).

But, those vulnerabilities, would those pose a threat today? (not that I have an updated box, so I'm most likely in the danger zone, but I don't usually boot into Windows if it's not for Photoshop or gaming business)
"The best place to hide a tree, is in a forest"

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

hm, the last vulnerabilities are from february 2008, but I haven't checked how serious they are.....I would say better the windows firewall than none at all. in most cases flaws in the firewall are used for DoS or to evade the firewall for following attacks against an underlying service.
the main problem is all that phone-home stuff which can't be blocked, so I don't recommend to use free *cough* software, at least not when being online.... :wink:

Post Reply