Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 30th, 2004, 02:19 AM
Devinco's Avatar
Devinco Devinco is offline
Very Frequent Poster
 
Join Date: Jul 2004
Posts: 2,524
Question Are cable modem XP Pro computers vulnerable during boot up and shut down?

Hi Everyone,

I just read an excellent post on layered security etc. at DSLReports and found this part very interesting:

Modem Stand-by - If your Broadband modem has a "Standby" switch, consider using it to keep your machine disconnected from the Internet:
1) During Start-up, at least until your SWF and AV are fully loaded and running.
2) When you are not actively using the connection, especially if unattended.
3) During Shut-down.

So let's say the external cable modem (with no standby switch) is directly connected to the network card (no router or hardware firewall) and the user has a software firewall and AV installed.
1. Is the computer vulnerable to outside internet attack (let's say the ip is known) during the power on, POST, or during the entire Windows XP boot process prior to the software firewall and AV loading?
2. Is the computer vulnerable to outside internet attack during the shut down or restart process?
3. If the computer is vulnerable, what is the nature of the vulnerability?
  #2  
Old July 30th, 2004, 04:18 AM
Snook's Avatar
Snook Snook is offline
Regular Poster
 
Join Date: Jun 2003
Posts: 182
Default Re: Are cable modem XP Pro computers vulnerable during boot up and shut down?

I know with Sygate Pro you are not vulnerable if you configure it to not allow any traffic while Sygate's service is not loaded. As you mentioned in your post, a hardware firewall would also protect you during reboots, shutdowns and startups.
__________________
"Oh! do not attack me with your watch. A watch is always too fast or too slow. I cannot be dictated to by a watch."
  #3  
Old July 30th, 2004, 02:03 PM
dvk01's Avatar
dvk01 dvk01 is offline
Global Moderator
 
Join Date: Oct 2003
Location: Loughton, Essex. UK
Posts: 3,129
Default Re: Are cable modem XP Pro computers vulnerable during boot up and shut down?

Quote:
Originally Posted by Devinco
.
1. Is the computer vulnerable to outside internet attack (let's say the ip is known) during the power on, POST, or during the entire Windows XP boot process prior to the software firewall and AV loading?
2. Is the computer vulnerable to outside internet attack during the shut down or restart process?
3. If the computer is vulnerable, what is the nature of the vulnerability?


In theory yes there is a very slight possibility of being infected by a trojan/worm etc in the microseconds between windows starting and connecting to the network and the firewall/antivirus becoming enabled.

In practice it won't happen as almost all firewalls/antiviruses start as services, especially with XP/W2K/2003 and those services are enabled before the networking part of windows is enabled & the same happens in reverse, windows networking shuts down before the FW/AV services do

No baddie will be able to be downloaded to the computer until windows has been fully booted
  #4  
Old July 30th, 2004, 02:29 PM
Devinco's Avatar
Devinco Devinco is offline
Very Frequent Poster
 
Join Date: Jul 2004
Posts: 2,524
Smile Re: Are cable modem XP Pro computers vulnerable during boot up and shut down?

Hi Snook,

Thanks for your reply.
ZA Pro appears to have something similar with its vsmon.exe (True Vector service).
  #5  
Old July 30th, 2004, 02:34 PM
Devinco's Avatar
Devinco Devinco is offline
Very Frequent Poster
 
Join Date: Jul 2004
Posts: 2,524
Smile Re: Are cable modem XP Pro computers vulnerable during boot up and shut down?

Quote:
Originally Posted by dvk01
In theory yes there is a very slight possibility of being infected by a trojan/worm etc in the microseconds between windows starting and connecting to the network and the firewall/antivirus becoming enabled.

In practice it won't happen as almost all firewalls/antiviruses start as services, especially with XP/W2K/2003 and those services are enabled before the networking part of windows is enabled & the same happens in reverse, windows networking shuts down before the FW/AV services do

No baddie will be able to be downloaded to the computer until windows has been fully booted
Hi dvk01,

Thank you for your clear and definitive answer, it makes a lot of sense.
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:45 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums