View Full Version : Shields UP! Reports perfect stealth without firewall, HOW?
truthseeker
January 27th, 2008, 08:40 AM
I am running Vista.
I have Vista Firewall turned OFF!
Then I tested my PC. And Shields Up! And other websites reports PERFECT STEALTH, even though I have NO FIREWALL RUNNING!
And; http://probe.hackerwatch.org/probe/probe.asp REPORTS ALL PORTS ARE NOT VISIBLE TO ANYONE!
How is that possible? Any ideas anyone?
So I dont need a Firewall program?
solcroft
January 27th, 2008, 08:42 AM
Router/Internet Connection Sharing.
truthseeker
January 27th, 2008, 08:42 AM
Whats that mean?
Coolio10
January 27th, 2008, 08:44 AM
-{ Quote: "Whats that mean?" }-
It means you have a router or your using internet connection sharing (ICS).
Do you have 2 boxes near each other?
truthseeker
January 27th, 2008, 08:51 AM
I dont have any 2 boxes near each other, whatever that means.
I am only using a Siemens 4200 DSL modem.
So I dont need to use a Firewall at all in Vista?
And I checked the config in modem. The firewall in modem is turned OFF!
So what is going on? LOL. I have perfect stealth reports, yet firewall in Vista and Modem is turned OFF!
Anyone have a good explanation?
Mrkvonic
January 27th, 2008, 10:23 AM
Hello,
Proxy? Did you scan your own machine?
Mrk
Dieselman
January 27th, 2008, 10:27 AM
A hardware firewall stops in bounds. A software firewall stops out bounds. So yes you still need a software firewall.
http://www.matousec.com/projects/windows-personal-firewall-analysis/personal-firewall.php#purpose-of-personal-firewall
-{ Quote: "Purpose of personal firewall
In general the main purpose of personal firewall is to tighten the computer security, to set up restrictions to limit possible malicious activity but not to limit the user. Imagine common home workstation. There are many applications like text editor, Internet browser, file manager, computer games, media player etc. By default, without personal firewall installed, all these applications can do everything as the user who runs them. But why should be the text editor allowed to access the Internet? Why should be the Internet browser allowed to change system files? Is it not a possible danger to allow games to delete documents or control system services? Why should be the media player allowed to install kernel drivers? No, there is no need to allow such actions.
The purpose of a personal firewall is to set up rules that limit applications to perform actions they should not be able to do and to allow actions that are expected from them. This is something what antivirus or antispyware do not. However, it is the fashion nowadays that antivirus products include also the antispyware features as well as personal firewall features. Such a product is usually called security suite rather than antivirus." }-
wat0114
January 27th, 2008, 10:51 AM
-{ Quote: "And I checked the config in modem. The firewall in modem is turned OFF!
" }-
It doesn't matter. The scan is likely hitting and "seeing" your modem's WAN port. If you note the ip address that Shields Up is scanning you will probably find it's different than that of you pc's ip address under Network Connections.
Jon_T
January 27th, 2008, 01:13 PM
-{ Quote: "...And I checked the config in modem. The firewall in modem is turned OFF!
So what is going on? LOL. I have perfect stealth reports, yet firewall in Vista and Modem is turned OFF!
Anyone have a good explanation?" }-
In addition to wat01114's post.
The AT&T - High Speed DSL Modem (http://www.bestbuy.com/site/olspage.jsp?skuId=7331452&productCategoryId=abcat0503013&type=product&tab=1&id=1126591859340#productdetail) is the Siemens 4100 DSL modem which has both:
Concurrent NAT and NAPT; and
Configurable ICSA-compliant Stateful Inspection Firewall with Denial of Service (DOS) protection for secure communication and Internet access.
For additional info (explanation) see NAT Routers (http://www.dslreports.com/faq/security/3._NAT_Routers).
truthseeker
January 27th, 2008, 06:32 PM
-{ Quote: "It doesn't matter. The scan is likely hitting and "seeing" your modem's WAN port. If you note the ip address that Shields Up is scanning you will probably find it's different than that of you pc's ip address under Network Connections." }-
I looked under Network Connections, but cant see any PC IP there.
Where exactly do I find this IP you refer to in Vista?
truthseeker
January 27th, 2008, 06:36 PM
-{ Quote: "In addition to wat01114's post.
The AT&T - High Speed DSL Modem (http://www.bestbuy.com/site/olspage.jsp?skuId=7331452&productCategoryId=abcat0503013&type=product&tab=1&id=1126591859340#productdetail) is the Siemens 4100 DSL modem which has both:
Concurrent NAT and NAPT; and
Configurable ICSA-compliant Stateful Inspection Firewall with Denial of Service (DOS) protection for secure communication and Internet access.
For additional info (explanation) see NAT Routers (http://www.dslreports.com/faq/security/3._NAT_Routers)." }-
So I dont need a Firewall at all then do I, seeing I keep getting Perfect Stealth Reports without even having Firewall on in Modem and not having a Firewall on in Vista?
Or do those perfect stealth reports only mean that nobody can hack into my PC? And I also need a Vista Firewall to stop any spyware etc if I was to get any, sending data OUT?
Do I understand this correct?
Thank you for your patience and time.
wat0114
January 27th, 2008, 07:27 PM
-{ Quote: "
Where exactly do I find this IP you refer to in Vista?" }-
Try here:
find ip address in Vista (http://windowshelp.microsoft.com/Windows/en-US/Help/3726934c-1315-4c29-bd4d-e42c10225e5a1033.mspx)
-{ Quote: "So I dont need a Firewall at all then do I, seeing I keep getting Perfect Stealth Reports without even having Firewall on in Modem and not having a Firewall on in Vista?
Or do those perfect stealth reports only mean that nobody can hack into my PC? And I also need a Vista Firewall to stop any spyware etc if I was to get any, sending data OUT?
Do I understand this correct?
Thank you for your patience and time." }-
I would enable either Vista's built-in firewall or the firewall in your modem. The stealth result does not really mean your machine is being properly "firewall" protected. It is just your modem's WAN port - I believe - that is being scanned and since there are no programs holding any ports open, it comes up stealthed. However, there is likely no proper filtering such as even basic SPI (stateful packet inspection) or DPI (deep packet inspection) being done by the modem firewall, since it is disabled as you alluded to earlier. The feature is built into your modem, so it makes sense to take advantage of it, or leave it disabled and use Vista's firewall. If it were up to me, I would use the modem firewall because then it will shield your pc from all that Internet "noise".
If you have more questions, feel free to ask. There are many knowledgeable members in this forum happy to help. You could also try this Other Firewalls Sticky Posts (http://www.wilderssecurity.com/showthread.php?t=24415) if you are interested in knowing more about firewalls and related matter :)
truthseeker
January 27th, 2008, 07:48 PM
-{ Quote: "Try here:
find ip address in Vista (http://windowshelp.microsoft.com/Windows/en-US/Help/3726934c-1315-4c29-bd4d-e42c10225e5a1033.mspx)
I would enable either Vista's built-in firewall or the firewall in your modem. The stealth result does not really mean your machine is being properly "firewall" protected. It is just your modem's WAN port - I believe - that is being scanned and since there are no programs holding any ports open, it comes up stealthed. However, there is likely no proper filtering such as even basic SPI (stateful packet inspection) or DPI (deep packet inspection) being done by the modem firewall, since it is disabled as you alluded to earlier. The feature is built into your modem, so it makes sense to take advantage of it, or leave it disabled and use Vista's firewall. If it were up to me, I would use the modem firewall because then it will shield your pc from all that Internet "noise".
If you have more questions, feel free to ask. There are many knowledgeable members in this forum happy to help. You could also try this Other Firewalls Sticky Posts (http://www.wilderssecurity.com/showthread.php?t=24415) if you are interested in knowing more about firewalls and related matter :)" }-
Yeah my Vista IP address is different to the IP that SHields UP! says I have. Hence, reason for stealth, as you suggested.
So its good I get Stealth Protection. However, having said that, I have now installed COMODO Firewall. It looks good :)
wat0114
January 27th, 2008, 08:04 PM
-{ Quote: "So its good I get Stealth Protection. However, having said that, I have now installed COMODO Firewall. It looks good :)" }-
Hopefully it works well for you :)
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums