Wilders Security Forums  

Go Back   Wilders Security Forums > Official LooknStop Firewall Forum > LnS English Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 6th, 2009, 10:45 AM
mattad mattad is offline
Regular Poster
 
Join Date: Mar 2006
Posts: 59
Default How to allow "local" Internet access but deny "real" Internet access?

At first I installed the well-known, free Oracle SQL Developer tool which allows the user to peek into and manage a Oracle database.
In my case the Oracle database is a locally (on my computer) installed free (=Express) version of Oracle.

When I start now SQL Developer tool LnS (v2.06) pops up a prompt:

SQLDEVELOPER.EXE
This software would like to connect to Internet.
Do you authorize it to connect?

Automatically I deny all outgoing traffic because I thought that SQL Developer want to transfer some user installation information to Oracles home server.

But much to my surprise this was not the case.
After detecting that SQL Developer does NOT work after denial I investigated the situation and found out that SQL Dev just wanted to access the Oracle Database listener on local port 1521.

The prompt is very misleading. If I remember it well the "Internet connection" alarms just local network adapter access appear from time for other programs as well.

How can I allow all already existing programs and all programs which I will install in future to connect all local "Internet" ressources but deny all "real"
connection which are located outside of my computer?

Matt
  #2  
Old October 6th, 2009, 02:06 PM
Frederic Frederic is offline
LnS Moderator
 
Join Date: Jan 2003
Location: France
Posts: 4,354
Default Re: How to allow "local" Internet access but deny "real" Internet access?

Quote:
Originally Posted by mattad
[...]
The prompt is very misleading. If I remember it well the "Internet connection" alarms just local network adapter access appear from time for other programs as well.
Yes, this is because Look 'n' Stop alerts as soon as a connection is detected without knowing yet if it will be used locally, or really for internet.
Quote:
How can I allow all already existing programs and all programs which I will install in future to connect all local "Internet" ressources but deny all "real"
connection which are located outside of my computer?
You can't do it when the prompt appears. You can do it after the application is added to the list of applications. Double-click on the application in the list (or use the Edit button), and enter 127.0.0.1 for the IP address the application can connect to (for UDP and TCP). This feature is available only when the Advanced mode is selected (in the advanced options).

Regards,

Frederic
  #3  
Old October 11th, 2009, 02:45 AM
mattad mattad is offline
Regular Poster
 
Join Date: Mar 2006
Posts: 59
Default Re: How to allow "local" Internet access but deny "real" Internet access?

Quote:
Originally Posted by Frederic
You can't do it when the prompt appears. You can do it after the application is added to the list of applications. Double-click on the application in the list (or use the Edit button), and enter 127.0.0.1 for the IP address the application can connect to (for UDP and TCP). This feature is available only when the Advanced mode is selected (in the advanced options).

Hmm, this is bad.

When the prompt appears what should I do?
Allow -> Program can connect to its home server (at least once)
Deny -> Installation is not possible

Is it possible to setup a general rule? Something like:
"Allow all programs to access 127.0.0.1 (or 192.168.*.*) regardless wether another rule exists which deny internet access."

If not: This is a real problem. You should find a solution for the next release.

Matt
  #4  
Old October 11th, 2009, 12:27 PM
Phant0m's Avatar
Phant0m Phant0m is offline
Massive Poster
 
Join Date: Jun 2003
Location: Canada
Posts: 3,328
Default Re: How to allow "local" Internet access but deny "real" Internet access?

If you enabled 'Advanced Mode' listed in 'Advanced Options' (Look 'n' Stop 'Options' Tab/screen, 'Advanced Options' button). This will allow you to control Applications IP and Ports through 'Application Filtering' Tab/Screen when double-clicking on an added application entry in the list of applications. It doesn't matter if you Authorized the application or denied the application first.


Regards,
Phant0m``
__________________
"Success is almost totally dependent upon drive and persistence. The extra energy required to make another effort or try another approach is the secret of winning.” --Dennis Waitley
 

Wilders Security Forums > Official LooknStop Firewall Forum > LnS English Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:40 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums