Re: Apple¹s Mac OS X Leopard firewallfails every test




"Steve de Mena" <steven@xxxxxxxxxxxxxxx> wrote in message news:4728cfd7$0$11519$4c368faf@xxxxxxxxxxxxxxxxx
Jim wrote:
In article <47281c1b$0$20605$4c368faf@xxxxxxxxxxxxxx>,
Steve de Mena <steven@xxxxxxxxxxxxxxx> wrote:

Heise Security: Apple¹s Mac OS X Leopard firewall fails every test

Tuesday, October 30, 2007 - 06:02 PM EDT

"The Mac OS X Leopard firewall failed every test. It is not activated by default and, even when activated, it does not behave as expected. Network connections to non-authorised services can still be established and even under the most restrictive setting, "Block all incoming connections," it allows access to system services from the internet. Although the problems and peculiarities described here are not security vulnerabilities in the sense that they can be exploited to break into a Mac, Apple would be well advised to sort them out pronto," Jürgen Schmidt reports for Heise Security

"Apple is showing here a casual attitude with regard to security questions which strongly recalls that of Microsoft four years ago. Back then Microsoft was supplying Windows XP with a firewall, which was, however, deactivated by default and was sometimes again deactivated when updates were installed. It was also the case that system services representing potential access points for malware were accessible via the internet interface by default. Despite years of warnings from security experts, the predominant attitude was that security must not get in the way of the great new networking functions," Schmidt reports.

"Then along came worms such as Lovsan/Blaster and Sasser, which rapidly infected millions of Windows computers via security vulnerabilities in system services, causing millions worth of damage. Even today, an unpatched Windows system with no active firewall will be infected within a matter of minutes. However, Microsoft has since learnt its lesson -- a serviceable firewall, activated by default, has been included since Service Pack 2. With the standard configuration, no services are accessible from the internet on a Windows system," Schmidt reports.

Full article here:

http://www.heise-security.co.uk/articles/98120

So? Most Wireless access points which are routers have hardware firewalls which are much better anyway.


That is very true. Never heard you mention that when the subject was Windows' firewall or the myriad of exploits which weren't applicable if you were behind a router.

Steve

Of course he wouldn't mention that. He's a dishonest alcoholic. His Lord and Savior Steve Jobs doesn't look good if he says that. It's all about the Apple worship.

.



Relevant Pages

  • Re: Guide to secure installtion of IIS 5
    ... don't forget a well-configured firewall. ... Do not put the computer onto the network or the Internet until after the ... Follow the instructions for hardening Windows and IIS at ... Install all service packs and security fixes from Microsoft and otherwise ...
    (microsoft.public.inetserver.iis.security)
  • Re: 2 questions to Sygate firewall users
    ... >>> Sygate offers strong security as a firewall for most users. ... >> Sygate does install system services which open Windows. ...
    (comp.security.firewalls)
  • Re: The Myth of the secure Mac
    ... You are screwed only if you use Outlook. ... >> 1) You fail to apply necessary recommended security patches after ... >> 3) In the case of a firewall, ... >> attached as common Windows files) Make sure this Junk Mail is moved to ...
    (comp.sys.mac.advocacy)
  • Re: Antivirus Programs
    ... Shenan-you wrote an excellent security book. ... >> May I install Norton AntiVirus and McAfee Security on my ... > Windows is not the only product you likely have on your PC. ... You should at least turn on the built in firewall. ...
    (microsoft.public.windowsxp.newusers)
  • Re: Microsoft Windows Network & Web Client Network - somebody connected to my computer?
    ... I use Windows XP. ... Doing the best I can at absorbing the necessary information about security. ... > UPDATES and PATCHES ... You should at least turn on the built in firewall. ...
    (microsoft.public.windowsxp.security_admin)