Why you shouldn't just use Windows Firewall

preview_player
Показать описание
Turn Off Windows Firewall and use something else. This video demonstrates with a trojan backdoor malware test, why you shouldn't use Windows Defender Firewall,although it comes with Microsoft Windows 10 and isn't necessarily bad. ▼ Links, Resources and Contact Information ▼

🔥 Love the channel? Become a Patreon:

🔥 Buy the best antivirus/security products with exclusive discounts and support this channel:

🔥 Join us on Discord and participate in our active community:

▶️ See how your product performs in a Test vs Malware:

▶️ Want to learn cybersecurity? Get started here:
Рекомендации по теме
Комментарии
Автор

This video shouldn't be *misinterpreted as advice not to use any firewall* especially if you're using a laptop and connecting to random Wifi networks.
Also, since everyone is asking why I ran the sample in a Win 7 environment (yes, this happens the same way in Windows 8/10). The purpose here isn't to bash Windows Firewall.
It is a demonstration of the problem with a security model relying on the firewall on the same system the malware is executing from a cybersecurity perspective with real backdoor example.

pcsecuritychannel
Автор

You should do a video on the best Firewalls available.

rfunk
Автор

please make more videos about malware analytics techniques, and it will be much better if you make a series from beginner to advanced.
your channel is really great
thank you

Leokhawarizmi
Автор

Don’t run as a administrator. A limited user can’t change firewall settings. Thus the script won’t be able to either.

briangullens
Автор

UAC was supposed to protect against that. But people kept complaining about annoying prompts so Windows made the default security level for never OSes "medium" which doesn't ask about built-in programs running with Admin priviledges. Instead they now use safe screen stuff that looks a program trying to run on up on the internet to determine if it should display an additional prompt.
Basically just turn UAC to high first thing on a new PC and never have an issue like the one displayed.

MattiKoopa
Автор

Shouldnt windows always ask you when a program tries to add a rule on the firewall?

Lopoi
Автор

You are testing your assertion using Windows 7 32-bit, which has entered end-of-life Jan-2020 and has not been receiving any meaningful updates for quite some time. It would have been more relevant if you run this experiment on an up to date Windows 10. Then see that the assertion you make does not hold true, at least for this test.

nuorizon
Автор

Someone clearly has a rather limited knowledge about firewalls and security in general. As an IT security guy for over 17 years this was quite painful to watch.

lev
Автор

Since more and more people are running smartphone devices, I was just wondering if you could make in the future a video about Antivirus software for Android/iOS?

theastroquantumguy
Автор

"Download his friends and have a party on your system" 🤣
Well so what should we use?

ankitminz
Автор

So, I've just never heard of that site until this video. It's very interesting to see what it can do. Are there any other sites of this type that you are aware of? Maybe you could do a video on such sites which you think are beneficial to people interested in cyber security. Thanks.

spectretacitus
Автор

Can you do a video on how to get a router level firewall? I know it would be different for each router but it would be helpful.

lilstimmy
Автор

Title: You shouldn't use Windows Firewall.
Me: He said nothing about Windows Firewall with Advanced Security.

Marioa
Автор

If you are someone who use the Windows Firewall at least in a corporate environment, one other thing you can do is use a GPO to control the Windows Firewall and tell the firewall to ignore any locally made rules. Is not a guarantee obviously but would provide some minor to moderate additional resistance to this attack. Ideally though, ya you want a hardware firewall that can actually scan into the packets and an IPS on the host that will run hashs against executables.

mymediapc
Автор

Doesn't f-secure use a modified windows firewall?

lebaquette
Автор

so how does this malware obtein premissions to change firewall settings? doesn't that need admin perms?

nitaihat
Автор

Why is this so misleading? Executing the "netsh advfirewall firewall add rule" requires elevation, so unless you disabled UAC you will be perfectly protected by Windows firewall. Also it seems that in order to execute the Fire.exe you would need to disable the AV as well.

stefantomas
Автор

A list of good firewalls would be nice. Also what kind of system do you use to test these? What Linux distro do you like?

realmtl
Автор

That video is misleading, you skipped the vector part which can be easily blocked by the firewall.

udi
Автор

"Why you shouldn't just use Windows Firewall". Does this post also apply to [Windows 10 Firewall]?

WhattEvery