Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » The Site » Old Forums » Kerio - Tiny Support » [Kerio 2.x] My Kerio 2.1.5 rules based on BZ's please critique
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
[Kerio 2.x] Rule 'Packet to unopened port received': Permitted »
« [Kerio 4.x] How to make Kerio old approve internet related pro  
AuthorAll Replies

ghost16825
Use security metrics
Premium
join:2003-08-26


1 edit
reply to Lilla1
Re: [Kerio 2.x] My Kerio 2.1.5 rules based on BZ's

I have to say this is one of the better rulesets I have seen. There's not very much to criticise in it. Regardless, now that you seem pretty happy with it, it's important to see where the weakest parts are even if there's nothing you can do to restrict the rule further.

Here's my suggestions:

1. Being on a dialup it is highly unlikely you need DHCP through svchost for the connection to work properly. (Perhaps only if you have a local are network). This isn't a security risk but there's no point having it there if it's not needed. Disable DHCP Client through Services and specify primary and alternate addresses in your connection instead of selecting "Get DNS addresses automatically" in your connection properties. (This causes DHCP Client to start Automatically)

2. Some people end their local port range at 4999 instead of 5000. (1024-4999) because of SSDP Discovery Service. (Incoming->5000). Do so if it makes you feel any safer.

3. See if you can come up with a list of IP addresses for Spybot.

4. Just a preference of mine:
For your browser rules I would create a rule which includes remote ports which you encounter all the time without fail:

Browser Allow TCP Out 1024-5000 Any address 80,21,443 (Perhaps 8080 and 81 as well if you encounter these on a daily basis)

And then a logged rule underneath:
Outside of Browser rules TCP Out 1024-5000 Any address 81-65535 or the much safer suggested 5001-65535 allow log

OR Two rules:

Outside of Browser rules common TCP Out any address 81,8080 log

Outside of Browser rules TCP Out any address 5000-65535 alert and log

To get SYSTEM rules take off come of your Windows specific rules, (local port 135,1025-1026,5000) and visit grc.com and do the shields up test. You should get a SYSTEM alert in their somewhere. If this doesn't work you may need to turn on a useless Windows Service which you don't need to get an effect.

I would take off your local port range for explorer(block) and perhaps make it both UDP/TCP both directions, just for the sake of it.

Looking at your rules the biggest weakness is a trojan attaching itself to an application with any address port 80 and sending data to port 80 of the attacker's computer. That said, everyone's probably vulnerable to such a thing and there's little you can do about it; you probably have a better chance of winning the lotto than this occuring if you practise safe computing.

In the future if you decide to implement some kind of local proxy filtering (eg. Proxomitron) just be aware that localhost filtering (eg localhost:8080 out allow followed by localhost:8080 in deny) just doesn't work in Kerio 2.15/4

Lilla1

join:2002-04-22
Fall City, WA


1 edit
said by ghost16825 See Profile:
I have to say this is one of the better rulesets I have seen. There's not very much to criticise in it. Regardless, now that you seem pretty happy with it, it's important to see where the weakest parts are even if there's nothing you can do to restrict the rule further.

I'm delighted that you like my rule set (work in progress), I give credit to BZ's wonderful rule set. I endevor to follow the lead of those that understand firewalls, because most of it is greek to me.

said by ghost16825 See Profile:

Some people end their local port range at 4999 instead of 5000. (1024-4999) because of SSDP Discovery Service. (Incoming->5000). Do so if it makes you feel any safer.

I used 1024-5000 because that's what BZ uses in his rule set, and because I have disabled UPnP and SSDP. Still I suppose I could use 1024-4999 as an added safety net.

Below is some discussion that relates to this:

BZ 2003-09-22 00:32:21
Q: I notice on your rule set that you have ports 135, 445 and 500?? for xp services block. Is it 500 or 5000?
BZ: Its 500, and 5000(UPnP) is easily turned off, it’s not even as huge as a threat as it was made out to be. However you could add 5000 to that list, but once you do the task below, it won't be listening anymore. You don't even need those services.

Start -> Run: services.msc
In the properties of these services, stop, and disable them. SSDP Discovery Protocol, and Universal Plug n' Pray.

said by ghost16825 See Profile:

3. See if you can come up with a list of IP addresses for Spybot.

Good idea. Done.

said by ghost16825 See Profile:

I would take off your local port range for explorer(block) and perhaps make it both UDP/TCP both directions, just for the sake of it.

Good idea. Done.

Thanks for all the ideas you gave me, some I am still thinking about.

Lilla
Forums » The Site » Old Forums » Kerio - Tiny Support[Kerio 2.x] Rule 'Packet to unopened port received': Permitted »
« [Kerio 4.x] How to make Kerio old approve internet related pro  


Thursday, 10-Dec 06:14:18 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [117] AT&T Launching New 24 Mbps U-Verse Tier
· [82] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [67] AT&T Hints At Usage-Based iPhone Data Pricing
· [66] Sprint Poised For A Turnaround?
· [66] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [51] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [45] Microwaving Your Innards Is Not 'Extreme'
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Cross Server Dungeon Experience [World of Warcraft]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Comcast refused to install 400' feet. [Comcast HSI]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· [Equipment] Low Cost CPE For Customers [Wireless Service Providers]
· Opening a file download dialog from a JavaScript function. [Webmasters and Developers]
· The aftermath [World of Warcraft]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]