Blackice Ken read [Archive] - SpeedGuide.net Broadband Community

View Full Version : Blackice Ken read


Boon
02-01-01, 09:49 AM
The faults of Black Ice are well known and documented. It doesn't keep anything in your puter and should actually be called an intrusion detection device as it has been known to advise a detection and let it go through anyway...Contrary to a firewall that would advise and stop it with out a doubt...

ken if you read this post please tell me more about this i copyed this from a reply you made to downhill in hes post about freedrive, as i use blackice and thought it was a great wall.

thanks

Scoot
02-01-01, 02:44 PM
LEAKY (UNSAFE) PERSONAL FIREWALLS
Firewall Trivial EXPLOITS Masquerade VULNERABLE
AtGuard None Known YES (in same directory)
BlackICE Defender Doesn't block unknown Trojans, Viruses, or Spyware
Conseal Desktop None Known YES (in any directory)
Conseal PC FW No Provision to block Trojans, Viruses, or Spyware
eSafe Desktop YES (stealth) YES (in any directory)
Lockdown 2000 No Provision to block Trojans, Viruses, or Spyware
McAfee Firewall None Known YES (in any directory)
Sygate Personal FW YES (stealth) YES (in any directory)


Read all about it at Personal Firewall Scoreboard (http://grc.com/lt/scoreboard.htm)
Response from Black Ice:
Network ICE / BlackICE Defender
A NetworkICE customer writes:
"I really like BlackICE Defender. It showed me a lot of things happening "on the wire" that I was previously unaware of. Now, when I ask for them to do the same thing for my outbound traffic, they give me a lot of run-around regarding the specific program I used to test for this feature. Oh well..."

Network ICE (reportedly) replies to this customer:
Dear Customer,

Thank you for your input. A feature request has been submitted, and your suggestion may well be included in a future version of BlackICE.

The leaktest is a specific program designed to test the "User-Initiated Outbound Blocking" feature of certain personal firewalls. It is not a generic hacker test, nor it is a test of your computer's security. In fact, leaktest does not do anything malicious. If it was a hacker program, we would add it to the list of detected Trojans, just like we detect BackOrifice and SubSeven.

Leaktest uses standard FTP programming, just like any other FTP client. Again, it does not do anything malicious. It is a test for outbound blocking only. The protection of the firewalls with user-initiated outbound blocking is based on a user having enough knowledge to know that a program should be blocked. Network ICE Corporation believes that having users guess at the intentions of a program based on the executable name is not good security. How does a user know if a program is malicious? We automate our protection against malicious programs. If leaktest is deemed a malicious program, then we will add protection against it. Otherwise, at this point in time, it is simply another program transferring data over the internet, just like 100's of other legitimate programs that transfer data over the internet.

Firewalls with outbound blocking only protect against Trojan horse programs, and then they only work if the user knows enough to recognize the program as a dangerous program. Standard personal firewalls without intrusion detection cannot stop 100's of other hacker attacks that do not use Trojan horses. Standard personal firewalls cannot stop a buffer overflow attack nor can they stop a fragmentation attack. BlackICE Defender with its intrusion detection is designed to automatically recognize and protect computer's from malicious traffic.

Please let us know if you have further questions.

Regards,
Technical Support
Network ICE Corp.

I hope this information helps :)

Boon
02-01-01, 04:01 PM
wow you guys are great to spend your time helping others like this i will do what you both said and find out more about all this, 65000 ports i did not know this i run norton firewall and blackice i have zonealarm but i never installed it i use ice more then norton because norton keeps poping up and gets a bit much after a while i had the same problem with zonealarm when i used it on my old pc, i just installed antitrojan 5 and updated it,it said my pc was clean, i also use norton antivirus which i update often what should i do now to be safer? i have adsl modem so i use the same ip and really thought ice was great, well again thanks for your time.

Boon
02-02-01, 12:17 AM
ive looked and now read everything in this forum about blackice but i dont agree with what is being said, the stuff about ice not stelthing all the ports, i have tested my ports with differnt test and all show me the same only port 139 was detected but will not reply all the others were stelthed, my main worrie is still what ken said about ice will detect but only detect and not block, if anyone knows any more about this please post.

thanks

keeper
02-02-01, 07:14 AM
Get rid of the Norton and then install Zone Alarm.
Lose the BI, too.

You might want to get Adaware 4.1 from www.lavasoft.de (http://www.lavasoft.de) [freeware] it will remove 'spyware' and 'adware' from your puter. Is easy to config & works automatically.

For Anti-Virus try InnoculateIT from www.antivirus.cai.com (http://www.antivirus.cai.com) [freeware] uses minimal resourses, won't invade your apps like Norton or call Home all the time. It updates at least 2 times per week. Is the best AV I've found.

Boon
02-03-01, 08:58 AM
ok this is what i have done Adaware i got it tryed it found a few things webagent and other files, so i cleaned them all i think was about 20 in all, BUT after doing this i clicked my internet icon to log on to net and all i could get was whitepage cant be displayed hmm so i checked my email and same thing haha well not funny really, i messed with a few settings to try and fix this but no joy, so i did a reformat np i can reformat in about an hour now, and i back everything up so i lose an hour of my time but get a fresh drive, now ive installed inoculate and its fine but when i click icon in taskbar a box pops up and it tels me this version needs to to upgraded, i have the 5.2 and apart from this poip up it works well and i can auto update, now i will install zonealarm pro and do a testleak i got from 1 of the links you guys gave me, also i did try this leaktest with norton running and it did not leak, also i did it with ice and guess what "yep" ice did not pass, ok thanks again for this help and i will post a update when all this is done if you dont mind checking back thanks guys.