Jump to content


"ShieldsUP" Fail grade for reply to Ping


  • Please log in to reply
8 replies to this topic

#1 OFFLINE   frapper

frapper

    Thread Head

  • Members
  • PipPipPipPipPipPip
  • 682 posts

Posted 03 August 2012 - 04:16 PM

When I go to Steve Gibson's "ShieldsUP" site https://www.grc.com/x/ne.dll?bh0bkyd2
whether in XP using the Comodo firewall or on machines running Win7 Home Premium running the Win7 firewall, I get the same result. Everything is fine except for responding to "ping" when I run the "common ports" test.

Quote

Ping Reply: RECEIVED (FAILED) — Your system REPLIED to our Ping (ICMP Echo) requests, making it visible on the Internet. Most personal firewalls can be configured to block, drop, and ignore such ping requests in order to better hide systems from hackers. This is highly recommended since "Ping" is among the oldest and most common methods used to locate systems prior to further exploitation.

What can be done, and is this really an issue? Do all Win7 firewall machines fail in this? Why aren't all firewells set up to block this by default?

Also, is there a better lightweight firewall-only for XP? The machine runs  MSSE and MBAM in realtime.

Norm
Windows 7 Home Premium SP1
USAF - '67-'71

#2 OFFLINE   Corrine

Corrine

    The Mystical Rose

  • Forum Admins
  • 2,912 posts

Posted 03 August 2012 - 08:38 PM

Both Windows Vista Firewall and Windows 7 Firewall were "true stealth"

Quote

Your system has achieved a perfect "TruStealth" rating. Not a single packet — solicited or otherwise — was received from your system as a result of our security probing tests. Your system ignored and refused to reply to repeated Pings (ICMP Echo Requests). From the standpoint of the passing probes of any hacker, this machine does not exist on the Internet. Some questionable personal security systems expose their users by attempting to "counter-probe the prober", thus revealing themselves. But your system wisely remained silent in every way. Very nice.

For Windows XP, I've heard favorable comments for Private Firewall:  Intrusion Detection and Prevention, Security Data Analytics, Personal Firewall - Privacyware.
,

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

#3 OFFLINE   frapper

frapper

    Thread Head

  • Members
  • PipPipPipPipPipPip
  • 682 posts

Posted 03 August 2012 - 09:52 PM

I tested this on two new Win7 machines, a netbook and a desktop, both connected to a DSL modem and switch. Why would both fail if yours is "true stealth"?

Norm
Windows 7 Home Premium SP1
USAF - '67-'71

#4 OFFLINE   Corrine

Corrine

    The Mystical Rose

  • Forum Admins
  • 2,912 posts

Posted 03 August 2012 - 09:59 PM

Have you made any changes to the Windows firewall?
,

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

#5 OFFLINE   frapper

frapper

    Thread Head

  • Members
  • PipPipPipPipPipPip
  • 682 posts

Posted 03 August 2012 - 10:25 PM

View PostCorrine, on 03 August 2012 - 09:59 PM, said:

Have you made any changes to the Windows firewall?

None. All default settings as received from the factory.

Norm
Windows 7 Home Premium SP1
USAF - '67-'71

#6 OFFLINE   securitybreach

securitybreach

    CLI Phreak

  • Forum Admins
  • 12,851 posts

Posted 04 August 2012 - 12:55 AM

Most routers have the option to block ping requests (block anonymous WAN Requests or something similar) :

Posted Image
Posted ImagePosted Image
Posted Image π
Comhack.com/CNI Radio/Linux User #363317/G+/Configs

"Do you begin to see, then, what kind of world we are creating? It is the exact opposite of the stupid hedonistic Utopias that the old reformers imagined. A world of fear and treachery and torment, a world of trampling and being trampled upon, a world which will grow not less but more merciless as it refines itself. Progress in our world will be progress toward more pain." -George Orwell, 1984

#7 OFFLINE   ross549

ross549

    I live here.

  • Forum Admins
  • 7,620 posts

Posted 04 August 2012 - 08:27 AM

Yes, your router's firewall is the problem here, unless you don't have one.

Adam
I don't suffer from insanity, I enjoy it.
Posted Image Posted Image Posted Image Posted Image

#8 OFFLINE   frapper

frapper

    Thread Head

  • Members
  • PipPipPipPipPipPip
  • 682 posts

Posted 04 August 2012 - 10:28 AM

I'm not a security expert, but the DSL modem* shows activity even when the machine(s) are shut down. I assume it's responding to random pings from the ISP to verify that it's "still there". That's what the ISP has told me. So couldn't it be the modem that responds to Steve Gibson's pings, and not the machine?

Adam, there is no router. It's a DSL modem that runs through a switch, and that's connected to Netgear powerline adapters for two other PC's in the house.

*Gigaset 4300 ADSL modem, Part # 060R-D148-A27

Norm
Windows 7 Home Premium SP1
USAF - '67-'71

#9 OFFLINE   frapper

frapper

    Thread Head

  • Members
  • PipPipPipPipPipPip
  • 682 posts

Posted 04 August 2012 - 11:29 AM

PC Flank's tests say it's stealthed.

Posted Image

Recommendation:

All the ports we have scanned are Stealthed (by a firewall). So just continue following the fundamental security measures and regularly update your security software.

I also ran the full port scan at https://www.securitymetrics.com/ and everything came up "stealth" including the common  trojan ports. Both tests used the Win7 firewall.

Norm
Windows 7 Home Premium SP1
USAF - '67-'71




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users