XP firewall doen't work on startup or shutdown?

M

marx404

This is old news, but as I have been comparing ICF (Internet Connection
Firewall in XP) to ZoneAlarm, I came across this in Technet:

Internet Connection Firewall Does Not Filter or Provide Firewall Services
During Startup and Shutdown
http://support.microsoft.com/default.aspx?scid=kb;EN-US;323009

This article was previously published under Q323009
SYMPTOMS
When you start or shut down your Windows XP-based computer, the Internet
Connection Firewall (ICF) does not filter or provide firewall services.
During the startup or shutdown process, users can connect to your computer
or to any program or service that may be available. Note that other than
these two times, ICF works correctly.
CAUSE
This issue occurs because during startup and shutdown, the user-mode service
is not available. Because of this, the filter driver does not know which
policy to enforce, and does not filter anything.

So, assuming that you are shutting down or booting up and your IP is being
bombarded with a trojan attack, there is a chance of the attack being
sucessful if ICF drivers haven't loaded yet. I see this as a probable
scenario for ppl who are on a broadband connection and using auto-logins
(ie: via Powertoys).

I went back to ZA immediately upon seeing this bug in ICF. Or does ZA work
in the same manner? Is an open network connection created before ZA drivers
load?
 
D

David Jones

This isn't different from ZA or any other software
firewall as far as I can tell.

There can always be a slight time window during boot
where the network stack may have loaded, but other
services (such as ICF, or ZA, etc) have not yet loaded.

The reverse can be true for shutdown, there can always be
a slight window where your firewall service has shut
down, but the network stack is still up.

Note, this is not related to autologins, user logins, or
anything like that. This is simply when the power is
turned on and the OS loads all the various services that
start, and conversely, when the OS tells all the various
services to shut down so the power can be turned off.

In most cases this window is extremely tiny, a manner of
seconds if that.

I'd be surprised if this wasn't the case with ZA as well.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top