![]() |
|
#26
|
|||
|
|||
|
There are major differences between WFC and WFN.
WFN uses the WIN 7 Firewall API. As such, the rules created by WFN are actual WIN 7 outbound firewall rules accessable via the WIN 7 firewall GUI. WFN made a valiant attempt and creates firewall rules by service but could not catch them all. Hence, most users end up with the total insecure rule of allowing all outbound access to svchost.exe TCP port 80 and/or 443. WFC is an entire front-end to the WIN 7 firewall. Rules created by WFC are WFC rules only. I believe WFC also has the same problem with outbound svchost.exe and creates a global rule to allow outbound TCP port 80, 443. I know this is true for the free version. WFN is still buggy due to the fact it was developed is maintained by a single French developer. Guy works at his day job and works on WFN as time permits. |
|
#27
|
||||
|
||||
|
ive tried windows firewall control but the resource usage is astronomical for such a "small" app.plus there were freezing issues.
![]()
__________________
Avira Free Antivirus.||Comodo Firewall 5.12.||Sandboxie.||MBAM free version.|| For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world... |
|
#28
|
||||
|
||||
|
Quote:
__________________
You can visit us at http://binisoft.org |
|
#29
|
|||
|
|||
|
Quote:
Alexandrud, is this true, that WFC allows all Outbound traffic for svchost.exe? And only for free version or for registered version too? Werderforever |
|
#30
|
||||
|
||||
|
Quote:
Fiuuuuu, need an eternity to understand. ![]()
__________________
We secure the world ;-) |
|
#31
|
||||
|
||||
|
Quote:
There is one product named WFC (Windows Firewall Control) which is developed by me and published on binisoft.org. WFC does not allow svchost.exe at all. It is blocked. All programs are blocked, including system ones. There is a second product which is called W7FC (Windows 7 Firewall Control) which is developed by Sphinx software. This one, indeed allows svchost.exe in the free version. Also other system applications. Quote:
__________________
You can visit us at http://binisoft.org |
|
#32
|
|||
|
|||
|
Quote:
To many Windows Firewall front-ends to keep track of I do have a question about WFC. Does it maintain WSH integrity? |
|
#33
|
||||
|
||||
|
It's threads like this that leave me in no hurry whatsoever to "upgrade" to Win7. Good grief... the outbound control on this native FW sounds like an absolute nightmare.
I'd hate having to use 3'rd party software when there's an integrated (and feather light) solution there. But I hate headaches as well. I may just have to hang on to Comodo FW when I make this switch. I know I can depend on it, worry/headache free, for easy, granular rule setting.
__________________
XP Pro SP3: Comodo FW/D+ 5.10 ▪ Sandboxie ▪ VT Hash Check ▪ OpenVPN ▪ VirtualBox |
|
#34
|
||||
|
||||
|
Quote:
Here on my XP Pro box svchost.exe doesn't require any internet access for my setup to function properly. Is this not the case on Win7? If so, what exactly is the access required for? Some service(s)? For all the claims of this OS being "more secure", based on actual real world observations I see quite to the contrary. Out of the box, sure. But when you harden XP Pro, compliment it with the right software, and exercise safe habits, I think you can make it safer than you could possibly get Vista or 7. Because you don't have dozens of services/processes that need to be running and granted internet access for it to function. I have 11 processes running and 9 services "started" at boot up. Only 2 instances of svchost, neither requiring internet access. From what I gather there are like a dozen instances of svchost alone on 7. I think I'll stick with XP Pro until EOL do us part...
__________________
XP Pro SP3: Comodo FW/D+ 5.10 ▪ Sandboxie ▪ VT Hash Check ▪ OpenVPN ▪ VirtualBox |
|
#35
|
||||
|
||||
|
Quote:
Actually, it's 100% logical once you get the gist of it.
__________________
Win 7x64 Ultimate SUA | UAC @ Max | AppLocker w/DLL enforcement | Win fw w/advanced security| EMET 3.5 | Firefox w/NS +AdBlock+ plugins | GPO restrictions | Bitlocker and Truecrypt | ShadowProtect images | IFW data backups + dual boot to XP Pro: GPO, SRP, Jetico firewall w/Process Attack filter |
|
#36
|
|||
|
|||
|
I used Stems thread on here and it was about a 30-40 minute process whitelisting my outbound apps and turning outbound protection to blocked. Takes about 1 minute to add a new app if I install something new. Pretty easy, if I used a 3rd party firewall it would be for the HIPS not the firewall. Overall I like the built in one but would like pop ups on what is blocked without installing something else or having to view logs. I can live without that though.
|
|
#37
|
||||
|
||||
|
Blocking svchost.exe?
..is that advisable seeing as its a windows service.Sorry im useless with firewall logic.lol. ![]()
__________________
Avira Free Antivirus.||Comodo Firewall 5.12.||Sandboxie.||MBAM free version.|| For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world... |
|
#38
|
||||
|
||||
|
Quote:
No need to block it. Rather, control it: Code:
This an older rule controling it for Windows update servers (more remote ip addresses are required). Note the service "wuauserv.exe" tied to svchost.
__________________
Win 7x64 Ultimate SUA | UAC @ Max | AppLocker w/DLL enforcement | Win fw w/advanced security| EMET 3.5 | Firefox w/NS +AdBlock+ plugins | GPO restrictions | Bitlocker and Truecrypt | ShadowProtect images | IFW data backups + dual boot to XP Pro: GPO, SRP, Jetico firewall w/Process Attack filter |
|
#39
|
|||
|
|||
|
Quote:
C:\program files\avast software\avast\setup\avast.setup C:\program files\avast software\avast\avastui.exe C:\program files\avast software\avast\avastsvc.exe |
|
#40
|
||||
|
||||
|
Quote:
Do those rules work when you select block all outgoing that do match a rule? I tried that. Did not work. But this did. http://www.wilderssecurity.com/showp...&postcount=570
__________________
"Don't Fear Malware......Be Prepared for it!" Last edited by Aventador : September 19th, 2012 at 01:47 AM. |
|
#41
|
|||
|
|||
|
Quote:
I don't use the Avast Web Shield. It enables all traffic sent via proxy. Although it may not make a difference in your case, try turning off the Avast Web Shield and see if that changes anything. I haven't used Tiny Wall. You may want to try disabling it too and just using the Win7 firewall while you troubleshoot it. |
|
#42
|
||||
|
||||
|
Quote:
If someone is able to write two lines of code (GUI-with exaggerated memory usage) does not mean to understand firewall logic. To open the discussion both sides should understand the minimum of the argument of which discussion proceeds. I try and then decide if it is worth continuing. To verify the minimum logic, I have the first question ? Quote:
If you believe in what you write, and written are right? because WFC with the first installation suggests "Create system rules (recommended)" and creates different Block.. svchost.exe rules like (Outbound rule to block WFC - Akamai Technologies) ?
__________________
We secure the world ;-) |
|
#43
|
||||
|
||||
|
Quote:
I don't grant anything access unless it's either necessary, or useful. svchost.exe is only needed for me once a month when I update Windows. So I don't actually have it blocked. I have no rule set for it. Then that once a month when I update Windows I grant it access on that per case basis, then don't hear from it again for 30 days. Perhaps it is needed for more functionality in Windows 7? Essential even for a stable system? That's not the case in XP.
__________________
XP Pro SP3: Comodo FW/D+ 5.10 ▪ Sandboxie ▪ VT Hash Check ▪ OpenVPN ▪ VirtualBox |
|
#44
|
||||
|
||||
|
Quote:
it has to be allowed on Windows 7 to surf the Internet.
__________________
| Sphinx Firewall || NoScript || Image for Linux + BootIt Bare Metal | |
|
#45
|
||||
|
||||
|
Quote:
Quote:
For "Low Filtering" some of svchost.exe connections are blocked by these rules and the others are possible. These are the common locations where svchost.exe tries to connect. For "Medium Filtering" all svchost.exe connections are blocked, with the exception of Windows Update and Windows Time, which are allowed. But, any other connections for svchost.exe are blocked. The discussion was in the context where the W7FC from Sphinx allows all traffic for svchost.exe, rundll.exe, etc, in the free version. My program can block svchost.exe even if you are not a registered user. Ans, also you can define a rule to block all traffic for svchost.exe. This can't be achieved in the free version of W7FC from Sphinx.
__________________
You can visit us at http://binisoft.org |
|
#46
|
||||
|
||||
|
Quote:
Excuse me, with no intention to be rude, if GUI such as WFC is using memory as video editing software ? then yes I say it in a loud voice, it is a little crappy GUI. Quote:
This level there is no need (rename it, allow all), because confusing simple user, provides false sense of security with three block rules. Quote:
Exact, but with DNS services disabled learning mode not work and GUI return to allow all level, very useless. I see that you're not going to try to understand importance of controlling svchost.exe connection, and if this is not clear to yourself, learning further would be rather inefficient.
__________________
We secure the world ;-) |
|
#47
|
||||
|
||||
|
Quote:
Quote:
Quote:
The following Windows services are required to be enabled for the notifications to work: "DNS Client" and "TCP/IP NetBIOS Helper". If these two are stopped the notifications provided by Learning Mode does not provide the real remote IP address of the connection. It will show the IP of your local router. But even in this case, the filtering is done properly. I don't see where is the problem. If you are such a svchost guru, please enlighten us with how the svchost connections should be handled.
__________________
You can visit us at http://binisoft.org |
|
#48
|
|||
|
|||
|
Quote:
svchost.exe est le plus difficile à configurer, lui même ne se connecte pas (jamais vu en tant que processus "parent"), sauf dans le réseau local, ce sont ses processus "enfant" qui le font, Bitdefender pas moins de 10 à 15 règles dans le pare feu... Ring0 a raison de souligner cette difficulté. Svchost.exe is the most difficult to configure, even he does connect not (never seen as "parent" process), except in the local network, these are processes "child" that do, Bitdefender not less than 10 to 15 rules in the firewall... Ring0 was right to point out this problem. Last edited by Spiedbot : September 20th, 2012 at 05:08 AM. |
|
#49
|
||||
|
||||
|
Quote:
If you enable outbound filtering in Windows Firewall from cmd line, anyway you will not see any notification and svchost.exe will be entirely blocked. 1. Windows Firewall blocks connections. WFC does not block anything. 2. WFC can inform the user about these events by providing notifications. 3. Again, I don't see the problem here with WFC regarding svchost.exe.
__________________
You can visit us at http://binisoft.org |
|
#50
|
|||
|
|||
|
Quote:
Thanks for the remote IP. Do you have an updated remote IP addresses for windows update please? If not, do you encounter any problems (like failed updates) as Microsoft may have a complete set of different remote IPs for windows update? Do you bind all svchost.exe to remote IPs? The microsoft advise against defining the IP address for windows update. They state that their IPs constantly change for reasons of security. http://social.technet.microsoft.com/...9-dcfc5c5bf22d |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|