Security Basics mailing list archives

RE: Opinion about 3rd party security patch for Windows


From: "Ferino Mardo" <RMardo () ALJOMAIHBEV com>
Date: Tue, 3 Aug 2004 08:34:47 +0300


First time I've heard of the tool but judging from your post, one cannot
protect their Win2K/XP systems and forget about patching the OS just
like that.

Malwares can and will infect your non-patched OS even if there's a
single port open. You might as well disconnect your system from the
network if you're going to close all ports.

The best thing to do is do a google search for "hardening windows 2000"
and you would surely find links to important sites that will guide you
in preventing your OS from unwanted guests.


-----Original Message-----
From: tim_edwards () dodgeit com [mailto:tim_edwards () dodgeit com] 
Sent: Monday, August 02, 2004 5:07 AM
To: security-basics () securityfocus com
Subject: Opinion about 3rd party security patch for Windows




Hi,



I have heard of the "StopListening" patch offered on nonebar.com 

via the GRC newsgroups. The author claims to be able to close 

down ALL ports that are open by default on a Win 2K/XP system,

thus closing the door to any worm-based infections and alleviating

the need for more OS patching. I haven't had a chance to try it out

yet, but can anyone who did let me know how much truth there is in 

that claim? 



Cheers,



Tim

--------------------------------------------------------------
-------------
Ethical Hacking at the InfoSec Institute. Mention this ad and 
get $545 off 
any course! All of our class sizes are guaranteed to be 10 
students or less 
to facilitate one-on-one interaction with one of our expert 
instructors. 
Attend a course taught by an expert instructor with years of 
in-the-field 
pen testing experience in our state of the art hacking lab. 
Master the skills 
of an Ethical Hacker to better assess the security of your 
organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
--------------------------------------------------------------
--------------



---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
any course! All of our class sizes are guaranteed to be 10 students or less
to facilitate one-on-one interaction with one of our expert instructors.
Attend a course taught by an expert instructor with years of in-the-field
pen testing experience in our state of the art hacking lab. Master the skills
of an Ethical Hacker to better assess the security of your organization.
Visit us at:
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: