October 31, 2006 @ 16:24
Firewalls Vulnerable To Attack… From Within.
When I first read this…
Hackers have published code that could let an attacker disable the Windows Firewall on certain Windows XP machines.
The code, which was posted on the Internet early Sunday morning, could be used to disable the Windows Firewall on a fully patched Windows XP PC that was running Windows' Internet Connection Service (ICS). This service allows Windows users to essentially turn their PC into a router and share their Internet connection with other computers on the local area network (LAN.) It is typically used by home and small-business users.
I thought, "Wow, this could be a big deal…" Then, as I kept reading…
By knocking off the Windows Firewall, a criminal could open the door to new types of attacks, but there are a number of factors that make such an attack scenario unlikely, Reguly said.
For example, the attacker would have to be within the LAN in order to make the attack work, and, of course, it would only work on systems using ICS, which is disabled by default. Furthermore, the attack would have no effect on any third-party firewall being used by the PC, Reguly said.
I thought, "Wow, big deal…"
The attacker has to be INSIDE the LAN, the victim must be using ICS, and third-party firewalls are not affected.
So, in reality, this applies to how many people?
Interesting…
Filed under Randomized Permalink · Comments Off


