PDA

View Full Version : Firewall outbound control tester


CloneRanger
May 24th, 2010, 02:20 PM
LeakOut - Firewall outbound control tester

Following on from blacknight's thread http://www.wilderssecurity.com/showthread.php?t=272900 i thought it might be enlightening to test/retest some other Leakers. There are several listed on the www, and the only one i havn't used before is this one.

-{ Quote: "LeakOut should be able to do this in these situations:

A properly configured firewall as above, but setup to 'Ask' every time even for the browser and authorization has been given to the browser at least once and the browser is still open. This should work if the browser is Firefox or Opera, for example, as they normally open a new URL in the same window & process that's already open. " }-

http://mark0.net/soft-leakout-e.html

218277

Tried it with FF v3 and IE6. Got prompted and denied = No go = expected. Got prompted and allowed = Go = expected.

218278

Wasn't too happy about them being able to see my Machine/User name though when i allowed out :(

sg09
May 24th, 2010, 04:06 PM
Oops...:o

Gullible Jones
May 24th, 2010, 04:12 PM
All the more reason to prevent malware from installing in the first place, then...

CloneRanger
May 25th, 2010, 09:43 AM
I don't use IE full time anymore, only for testing etc, so i'm not worried about the Machine/User name result. I just wondered what method they were using to grab the info ? Java/javascript/activex/cookies etc were all disabled.

The point of posting this was, for others to try it and see what results they got from both vectors ;)

blacknight
May 25th, 2010, 11:07 AM
I use Opera 10.53: Defense+ alerted me about LeakOut: if I deny, all right: LeakOut is blocked. If I allow, LeakOut can read Machine name and User.

Morro
May 25th, 2010, 11:26 AM
LoL PC Tools Firewall PLUS Hips function(If you can call it that) gave the choice...Allow/Block before LeakOut could do something, so i am not worried. ;D

Espresso
May 26th, 2010, 03:13 AM
-{ Quote: "I don't use IE full time anymore, only for testing etc, so i'm not worried about the Machine/User name result. I just wondered what method they were using to grab the info ? Java/javascript/activex/cookies etc were all disabled." }-

Doesn't matter what browser you use. The program gets the machine name/user and sends it out via the default browser. This is a very basic test and most firewalls/HIPS can handle it.

markcc
May 26th, 2010, 07:31 AM
No problem for Online Armor

CloneRanger
May 26th, 2010, 01:58 PM
Quote Espresso

-{ Quote: "Doesn't matter what browser you use. The program gets the machine name/user and sends it out via the default browser. " }-

Well that's just it, if this app can get our machine name/user, if we allow it, how many other apps/browsers etc that we allow every day can do the same, and upload the info to their www ? Not good :(

-{ Quote: "This is a very basic test and most firewalls/HIPS can handle it." }-

Sure blocking it from getting out seems easy for most, it's the machine name/user data that's more of a concern.