Author Topic: Firewall useless with sshdroid ?  (Read 3559 times)

0 Members and 1 Guest are viewing this topic.

adrien05

  • Guest
Firewall useless with sshdroid ?
« on: January 30, 2013, 09:28:50 PM »
Hi,

When using SSHDroid, I would have thought that it would not be possible for me to connect unless I authorize connection within the Avast Firewall...

Yet, it is supposed to be blocked (I'm in whitelist mode), and I still could connect to the SSH server on the phone from my PC.

Why is that ?
Any reason why the firewall configuration is bypassed ?

Thanks a lot !

svehlak

  • Guest
Re: Firewall useless with sshdroid ?
« Reply #1 on: January 30, 2013, 11:43:18 PM »
Could you please be more specific? Do you have port blocked too?

adrien05

  • Guest
Re: Firewall useless with sshdroid ?
« Reply #2 on: February 01, 2013, 11:47:36 AM »
Hi,

I have:
- White list mode set,
- Allow all apps unchecked,
- Some apps checked (those are confirmed to be able to go on the Web),
- Some other apps unchecked (those are confirmed not to be able to go on the Web),
- No custom rules created (this is what I would have liked to use regarding sshdroid)...

In particular, SSHDroid is unchecked => it should not be able to use the Network.

Yet, when activating the server, there is no problem for me to connect to it from my PC...

Is there anything else you need ?

Regards, Adrien

svehlak

  • Guest
Re: Firewall useless with sshdroid ?
« Reply #3 on: February 01, 2013, 04:49:47 PM »
Yes, thanks for the info. I just tried it and the block is done without any problem (using SSHDroid as a server and sftp for connecting. Could you please post informations about your device, like OS, ROM, build, kernel version and baseband? Are you able to call iptables from the shell?

Offline Ondra Cermak

  • AMS
  • Avast team
  • Full Member
  • *
  • Posts: 181
Re: Firewall useless with sshdroid ?
« Reply #4 on: February 04, 2013, 10:21:39 AM »
Hi,

if I understand it correctly, you are running an SSH server on the phone and connecting to it from your PC, right? Then my guess would be the firewall won't block it, because it works only for outgoing connections. I'll ask if we could do something about it, but I don't promise anything.

Ondra

Offline Ondra Cermak

  • AMS
  • Avast team
  • Full Member
  • *
  • Posts: 181
Re: Firewall useless with sshdroid ?
« Reply #5 on: February 04, 2013, 10:55:48 AM »
I just tried it and it is indeed not blocked, for the reason I wrote earlier. It might be possible to block incoming connections for the custom rules, but right now it's not implemented and unfortunately I can't give you any timeframe, sorry.

Anyway, our Firewall doesn't show you a notice when some app is trying to make a connection. It's rule based and those rules can't be changed "on the fly" as apps are making connections. You always have to go to the Firewall sections of AMS and set the rules there.

Ondra