PDA

View Full Version : Question about GMER & Samurai HIPS


Rasheed187
August 19th, 2007, 04:04 PM
Hi,

I have noticed that GMER has a feature named "Allow default IE connections only", what exactly is the purpose of this? And Samurai has a featured named "Block unsolicited inbound Internet traffic", what will this exactly do? Doesn´t a firewall perform the same function? More info:

{QUOTE-> This step blocks incoming Internet traffic by enabling the registry value “HKLM\System\CurrentControlSet\Services\TcpIp\Parameters\ EnableSecurityFilters”. This setting only affects inbound traffic. This setting will not become active until the machine is rebooted. <-QUOTE}

Rasheed187
August 21st, 2007, 12:31 PM
Where are the firewall/network experts? Anyone? :blink:

TopperID
August 21st, 2007, 01:47 PM
I've never used GMER, but go to IE/Tools/Internet Options/Connections, presumably it only permits the default connection here to foil malware which might set up some other direct connection.

As for the second part, I dunno except default is to have the setting disabled, however if you enable it you can customise the filtering in some way; apparently some malware does that, but I don't know to what end?

http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/regentry/33568.mspx?mfr=true

http://www.windowsitlibrary.com/Content/329/04/3.html

I don't understand the ramifications to give a simple answer, maybe someone else can?

Rasheed187
August 27th, 2007, 10:13 AM
Thanks for the feedback, so you think the setting in GMER protects against dialers? Never really thought of that, I will check it out. And I still wonder what the setting in Samurai is all about, I mean will it make an inbound firewall obsolete, without causing any problems? Perhaps a stupid question, but I´m not an expert when it comes to firewalls. :)

http://support.microsoft.com/kb/813878