Kazza Lite.
Joined: Nov 2001
Posts: 17,864
Likes: 0
From: Not all those who wander are lost
Trending Topics
Thread Starter
Scooby Regular
iTrader: (13)
Joined: Jan 2001
Posts: 4,997
Likes: 0
From: Midlands - between notts and derby !
Anybody had any issues with the software allowing access to other parts of the PC besides the shared area.
Any issues with virus or worms.
Just interested because I am working on somebodies PC that has the lite version installed and there seems to be a lot on the network !
Dave.
Any issues with virus or worms.
Just interested because I am working on somebodies PC that has the lite version installed and there seems to be a lot on the network !
Dave.
Scooby Regular
Joined: May 2000
Posts: 10,371
Likes: 0
From: MY00,MY01,RX-8, Alfa 147 & Focus ST :-)
Just do a search on P2P (peer to peer) programs, rogue protocols and KaZaA (lite or otherwise) and you'll know why we advise clients never to let these apps within a million miles of your coporate LAN (or home PC for that matter). If you think I'm scare mongering, we have had customers whose networks have been compromised by such programs.
Chris
Chris
Thread Starter
Scooby Regular
iTrader: (13)
Joined: Jan 2001
Posts: 4,997
Likes: 0
From: Midlands - between notts and derby !
Chris,
How much risk on a home pc running norton internet security and a router running a firewall as well ?
Is the exposure to other files manageable if configured correctly or is the risk else where.
I don't want to suggest taking it out unless there is a very solid risk. From some of the issues I am finding it is only if you allow wider access.
Dave.
How much risk on a home pc running norton internet security and a router running a firewall as well ?
Is the exposure to other files manageable if configured correctly or is the risk else where.
I don't want to suggest taking it out unless there is a very solid risk. From some of the issues I am finding it is only if you allow wider access.
Dave.
Scooby Regular
Joined: May 2000
Posts: 10,371
Likes: 0
From: MY00,MY01,RX-8, Alfa 147 & Focus ST :-)
Dave
I only post this kind of thing as general warning. The problem with these kind of apps is that they can be basically configured to run as HTTP (TCP port 80) or something similar which your average firewall will see as legit traffic. We have documented cases at work of virus / trojan apps being sent 'under' or 'through' the normal flow of data i.e. a music download from KaZaA - the firewall will see this as a legitmate http traffic flow and allow it through. The end user was completely unaware that this had happened.
How good your AV software is depends on how up to date it is. The same applies to intrusion detection systems - most rely on a signature file similar to an AV signature file. IDS is improving all the time, but it is not fool proof and many systems can only detect and not block an attack - big difference.
This is why we advise against these apps (it can also apply to MS Messenger and AOL Instant Messenger) at the current time. There is also the very real issue of employees downloading illegal and/or copyright protected material which could land the company he works for in trouble aswell.
It's all about percentage risks and what you are prepared to accept. These apps will always exist and many people will use for them and never experence a problem. I prefer not to trust them at the moment.
Chris
I only post this kind of thing as general warning. The problem with these kind of apps is that they can be basically configured to run as HTTP (TCP port 80) or something similar which your average firewall will see as legit traffic. We have documented cases at work of virus / trojan apps being sent 'under' or 'through' the normal flow of data i.e. a music download from KaZaA - the firewall will see this as a legitmate http traffic flow and allow it through. The end user was completely unaware that this had happened.
How good your AV software is depends on how up to date it is. The same applies to intrusion detection systems - most rely on a signature file similar to an AV signature file. IDS is improving all the time, but it is not fool proof and many systems can only detect and not block an attack - big difference.
This is why we advise against these apps (it can also apply to MS Messenger and AOL Instant Messenger) at the current time. There is also the very real issue of employees downloading illegal and/or copyright protected material which could land the company he works for in trouble aswell.
It's all about percentage risks and what you are prepared to accept. These apps will always exist and many people will use for them and never experence a problem. I prefer not to trust them at the moment.
Chris
Thread
Thread Starter
Forum
Replies
Last Post
Funkii Munkii
Computer & Technology Related
5
Jul 12, 2004 07:04 PM




