Author Topic: Block  (Read 8455 times)

0 Members and 1 Guest are viewing this topic.

longhorn

  • Guest
Block
« on: September 30, 2012, 12:26:09 AM »
I made a security check at https://www.grc.com SHIELDSUP and my computer failed in the following point:
Ping Reply: RECEIVED (FAILED) — Your system REPLIED to our Ping (ICMP Echo) requests, making it visible on the Internet. Most personal firewalls can be configured to block, drop, and ignore such ping requests in order to better hide systems from hackers. This is highly recommended since “Ping” is among the oldest and most common methods used to locate systems prior to further exploitation.
How I can close/block my ping response? I have avast free antivirus, program version 7.0.1466 and virus def. is up to date.
I’m running windows xp pro sp3
 :)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37542
  • Not a avast user
Re: Block
« Reply #1 on: September 30, 2012, 12:29:41 AM »
« Last Edit: September 30, 2012, 12:44:47 AM by Pondus »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89104
  • No support PMs thanks
Re: Block
« Reply #2 on: September 30, 2012, 12:51:48 AM »
@ longhorn
The avast free antivirus is not a firewall and the firewall is the area of stealthing for your system. This stealth is achieved by your firewall not responding to unsolicited connections (external port scans, etc.) to your system.

So the real question is what is your firewall ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

longhorn

  • Guest
Re: Block
« Reply #3 on: September 30, 2012, 01:03:33 AM »
My firewall is windows firewall and I'm behind a netgera gateway, I did go into control panel/security center/windows firewall/ICMP settings and unchecked ererything but I'm still getting failed at www.grc.com common ports?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89104
  • No support PMs thanks
Re: Block
« Reply #4 on: September 30, 2012, 01:19:35 AM »
Which ever is getting in first, either your netgear gateway (if it has a firewall) or the XP firewall ideally should ignore unsolicited inbound connection attempts, e.g. those not responding to an outbound request from the system. The XP firewall although basic (doesn't have outbound protection) is usually good at stealthing your system.

Not if you go specifically blocking a port, that is considered as bad a getting a response from your system on an unsolicited connection attempt as it signals that there is a system on the end of that IP address and port. If you did actually manage to block/close the ping port, ShieldsUp would still indicate a failure in stealthing as the blocked port is in effect a response.

In all honesty the windows XP firewall is damn old and pretty basic, you should consider getting a 3rd party firewall that provides outbound protection.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7168
  • When you think you know, Think Again
Re: Block
« Reply #5 on: September 30, 2012, 01:31:02 AM »
3RD. Party Firewalls could include: OutPost FW
                                                 Online Armour FW
                                                 Private FW
I have tested These 3 (and others) over the years and have found them very effective, and aggressive Firewalls in both the FREE versions and PRO versions.  :)

longhorn

  • Guest
Re: Block
« Reply #6 on: September 30, 2012, 01:38:41 AM »
ok that sounds good, I'll check them out pick one try sheildsup again and let you know the results.
thanks.  :)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37542
  • Not a avast user
Re: Block
« Reply #7 on: September 30, 2012, 01:43:44 AM »
if you checked the links i gave you above....you will see that if you are behind a isp box or router with a firewall, then it is the first firewall you are testing.....the test is not reaching your software firewall
« Last Edit: September 30, 2012, 01:46:14 AM by Pondus »

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7168
  • When you think you know, Think Again
Re: Block
« Reply #8 on: September 30, 2012, 01:44:10 AM »
ok that sounds good, I'll check them out pick one try sheildsup again and let you know the results.
thanks.  :)

You are welcome.
On a side note, you may want to go into your profile/Account settings and UNCHECK " Allow users to Email me" as there are those spammers who will harvest Emails that are shown here in the Forum
Just saying. ;) :)

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7168
  • When you think you know, Think Again
Re: Block
« Reply #9 on: September 30, 2012, 01:45:52 AM »
if you checked the links i gave you above....you will see that if you are behind a isp box or router with a firewall, the it is the first firewall you are testing.....the test is not reaching you software firewall

Good Point, thanks Pondus.  ;)

Offline Para-Noid

  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 6700
  • Trust only what you test yourself!
Re: Block
« Reply #10 on: September 30, 2012, 02:55:18 AM »
For what it's worth. I tested, using http://www.grc.com/intro.htm (click "services"), both Online Armor Free and Private Firewall.
Private Firewall proved to be more stealthy.  :)
Dell Inspiron, Win10x64--HP Envy Win10x64--Both systems Avast Free v17.9.2322, Comodo Firewall v8.2 w/D+, MalwareBytes v3.0, OpenDNS, Super Anti-Spyware, Spyware Blaster, MCShield, Unchecky, Vivaldi Browser and, various browser security tools.

"Look before you leap!" Use online scanners before you click on any link.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89104
  • No support PMs thanks
Re: Block
« Reply #11 on: September 30, 2012, 03:14:47 AM »
As expected all ports stealthed.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline schmidthouse

  • VIRUS FREE A Long Time
  • Avast Evangelist
  • Starting Graphoman
  • ***
  • Posts: 7168
  • When you think you know, Think Again
Re: Block
« Reply #12 on: September 30, 2012, 03:37:14 AM »
As expected all ports stealthed.

Here also: ;) ; 8)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37542
  • Not a avast user
Re: Block
« Reply #13 on: September 30, 2012, 08:51:41 AM »
Firewall ON or OFF ....it does not matter what i do as it is the firewall in my ISP box that control this



I can't pass a firewall test, what should I do?

http://ask-leo.com/i_cant_pass_a_firewall_test_what_should_i_do.html
« Last Edit: September 30, 2012, 08:53:16 AM by Pondus »

longhorn

  • Guest
Re: Block
« Reply #14 on: October 02, 2012, 06:27:15 PM »
thnx schmidthouse for the info. on profile/Account settings and UNCHECK, done.
I did try both Online Armour FW an Private FW.
 
I liked Online Armour FW but just a little bulky for my Celeron CPU 2.40GHZ w/only 1GB of ram so I settled for Private FW and once I figure out all the right settings I shoul be fine.

As for the sheildsup test my results are the same with or without FW's installed.
Solicited TCP Packets: PASSED
Unsolicited Packets: PASSED
Ping Reply: RECEIVED (FAILED)

I had been stressing over it  ???..... you know how newbies are  ;D
but after I read Pondus post on: I can't pass a firewall test, what should I do?
http://ask-leo.com/i_cant_pass_a_firewall_test_what_should_i_do.html,
I can live with it, I feel my system is secure.

I also implemented more security and would like to throw it around and get some thoughts.