Welcome to Smokey's Security Forums.
Guests have only limited access to the board and it's features, please consider registering to gain full access!
Registration is free and it only takes a few moments to complete.

Smokey's Security Forums

Please login or register.

Login with username, password and session length
Advanced search  

News:

Smokeys is looking for 'Updaters.
If you have  knowledge of Updates or a willingness to learn, please send  'Starbuck' or 'Tinker' a PM with your details.
Thanks.

OTL Log Analysis and Malware Removal - Qualified PC Disinfection & Cleaning - Microsoft Security Info & Alert Center - Official Jetico Inc. Support Forums

Share this topic on FacebookShare this topic on MySpaceShare this topic on Del.icio.usShare this topic on DiggShare this topic on RedditShare this topic on StumbleUponShare this topic on TwitterAuthorTopic: Suggestions for Jetico2 - post Feature Requests here!  (Read 13000 times)

0 Members and 1 Guest are viewing this topic.

TommyTopic starter

  • Jetico Forums Team Leader
  • Administrator
  • *
  • Online Online
  • location: Buenos Aires - München
  • Posts: 1061
    • WWW
(No subject)
« Reply #19 on: March 01, 2007, 05:24:59 PM »
That's in the moment not possible with Jetcio v2 directly (but with some browser).
For Jetico you have to do that manualy, Find out the whole IP range by using IP Whois. This gives you the full IP-Range and add them into the 'Blocked Adresses' Group.

P.S. It's easier with Firefox, or Opera itself.

Gerard

  • VIP Member
  • *****
  • Offline Offline
  • Posts: 2124
(No subject)
« Reply #18 on: March 01, 2007, 05:23:04 PM »
Quote from: "Geri"
I'd like to see a way to add DNS names to lists. For instance: I want do block all ads by doubleclick. Problem is, they use many servers, in many IP ranges, some seem totally unrelated.
It would therefore be great to be able to add *.doubleclick.net to the blocked addresses.

Or is it is already possible?

Kind regards,

  Geri



That is possible depending on the browser you are using.

Gerard

Geri

  • Full Member
  • **
  • Offline Offline
  • Posts: 23
(No subject)
« Reply #17 on: March 01, 2007, 05:07:17 PM »
I'd like to see a way to add DNS names to lists. For instance: I want do block all ads by doubleclick. Problem is, they use many servers, in many IP ranges, some seem totally unrelated.
It would therefore be great to be able to add *.doubleclick.net to the blocked addresses.

Or is it is already possible?

Kind regards,

  Geri

Manii as Guest

  • Guest
  • **
  • Offline Offline
  • Posts: 12
(No subject)
« Reply #16 on: February 28, 2007, 01:14:33 AM »
Jetico should save the window layout. I always move the 'application' column to second position (since 'description' is useless here) but everytime system is restarted positions are reset.

Geri

  • Full Member
  • **
  • Offline Offline
  • Posts: 23
(No subject)
« Reply #15 on: February 27, 2007, 11:28:32 PM »
I would like to see a way to monitor the firewall (things like currently opened connections, network throughputs, firewall statistics, etc.) exposed outside the UI, by means of an API or a WMI interface.

I know, this probably won't be a priority, and maybe not a very popular feature, but might help administrators, and semi-control freaks like me.
It never hurts to ask...

   Geri

PeterPaul

  • Full Member
  • **
  • Offline Offline
  • Posts: 228
Whois/reverse DNS feature request
« Reply #14 on: February 23, 2007, 04:00:22 PM »
Whois/reverse DNS feature request

Often it is hard to identify who the connection comes from or goes to. Knowing who the app wants to communicate to is helpful in determining malicious intent.

When the requester pops up with a remote IP, it would be very good to have an option to display the IP together with a reverse DNS lookup which could also be logged.

Additionally it would be desirable to be able to search for the IP upon double-click with a configurable whois or other search.

Named Port Ranges in  Groups feature request
Similar to the named IP-Ranges in the Groups tab, it would be helpful to be able to define named ports and port rages to be used/displayed in rules and requesters instead of port numbers.

anan321

  • Full Member
  • **
  • Offline Offline
  • Posts: 23
(No subject)
« Reply #13 on: February 22, 2007, 05:22:21 PM »
Feature request:

Colors used for various events in a log window should be clearly visible in the log_level drop down menu beside the name for that particular log_level. Also, colors representing different levels of logging should be user definabe.

Cosmetic, really, but helpful IMHO.

PeterPaul

  • Full Member
  • **
  • Offline Offline
  • Posts: 228
Re: Integration of an ip-filter Blocklist
« Reply #12 on: February 22, 2007, 12:25:35 PM »
Quote from: "Tommy"
Quote from: "peterpaulwinter"
Integration of an ipfilter blocklist:

Kind of you find here:
Tab 'Groups' -> IP adresses -> Blocked adresses (the right window)

The idea of the possibility to download and existing blocklist with update feature is not a bad idea.


I know, I have seen that feature, so in principle it should be easy to integrate a downloaded blocklist. The existing interface does not allow to enter tens of thousands of address ranges that a typical p2p blocklist contains.

Also some form of optimization will probably be necessary, if the firewall is not written to handle such large lists. Otherwise everything will slow down like when using the comparable Outpost-firewall blocklist plugin.

TommyTopic starter

  • Jetico Forums Team Leader
  • Administrator
  • *
  • Online Online
  • location: Buenos Aires - München
  • Posts: 1061
    • WWW
Re: Integration of an ip-filter Blocklist
« Reply #11 on: February 21, 2007, 09:56:40 PM »
Quote from: "peterpaulwinter"
Integration of an ipfilter blocklist:

Kind of you find here:
Tab 'Groups' -> IP adresses -> Blocked adresses (the right window)

The idea of the possibility to download and existing blocklist with update feature is not a bad idea.

PeterPaul

  • Full Member
  • **
  • Offline Offline
  • Posts: 228
Integration of an ip-filter Blocklist
« Reply #10 on: February 21, 2007, 07:08:23 PM »
Integration of an ipfilter blocklist:

The firewall would certainly be the best place to integrate an ip-filter blocklist, rather than having a separate app such as PeerGuardian2. An auto-updater should be included, too.

This would be useful for anti-P2P blocklists as well as malware blocking from known sites.

egressor

  • Member
  • *
  • Offline Offline
  • Posts: 4
(No subject)
« Reply #9 on: February 02, 2007, 01:11:31 AM »
Exactly!  So let's say you get a svchost receive datagram on local port 1026 (CAP, calendar access protocol),  for what service is this meant?  Hard to say.

So I have three rules now for it DNS CLient, w32Time, and a block rule where I block local 1024, 1026-1033, 1434,  1984 and 1986.  Kinda messy.

Also noticed a problem with the DNS client rule.  I just recently understood why it  periodically went invalid.   When i renew my IP (dialup disco :x )  the Group IP address/name server becomes empty.  As a result since it is empty the DNS Client rule fails and turns invalid.  Upon reconnect the rule remains invalid, and cannot be made valid again unless you manually click the checkboxes.

Sure hope this gets fixed since I have to keep an explicit rule set just so that the DNS doesn't fail.

BTW anyone up for sharing some cool rules?  Maybe a topic dedicated to just this?

pcaca

  • Full Member
  • **
  • Offline Offline
  • Posts: 12
Re: svchost.exe
« Reply #8 on: January 28, 2007, 03:22:59 AM »
Quote from: "egressor"
Recently I've made some rules for svchost after noticing that my computer clock was slow by more than 2 hours  :o

So I created a new table for w32time.  I specified an ip and a port (123).

However creating rules for svchost is a real pain since it runs so many services.

What i'd like to see is someting like the output from tasklist /svc, where the services run by svchost are clearly diferentiated.

I'd seen this in a firewall but I forget which, since i ran most of them at one time or another.


Good point. That would be very useful!

Creating rules for services instead of executable files would be much better, especially for svchost. So, if I create rule for Windows Update Service (HTTP/HTTPS), Jetico will allow HTTP/HTTPS connections only for svchost.exe instance which is runing Windows Update sevice and other istances like DNS Client should be denied from accessing HTTP/HTTPS. This way we will have better security and better organization of rules.

egressor

  • Member
  • *
  • Offline Offline
  • Posts: 4
svchost.exe
« Reply #7 on: January 27, 2007, 08:53:11 PM »
Recently I've made some rules for svchost after noticing that my computer clock was slow by more than 2 hours  :o

So I created a new table for w32time.  I specified an ip and a port (123).

However creating rules for svchost is a real pain since it runs so many services.

What i'd like to see is someting like the output from tasklist /svc, where the services run by svchost are clearly diferentiated.

I'd seen this in a firewall but I forget which, since i ran most of them at one time or another.

Smokey

  • Site Administrator
  • *
  • Offline Offline
  • location: Annie's Pub
  • Posts: 6240
  • -: veritas odium parit
Needs Dynamic (IP Changes) Trusted *Domain* Tracking!
« Reply #6 on: January 23, 2007, 09:49:57 PM »
This is one for the wandering road warriors <g>.

We wander around the earth and have personal, dynamic domains, such
as {my.domain.biz}, which track our constant IP changes.

The JPFv2 needs a function that will follow these dynamic domain changes
and allow the changing IP numbers to be tracked and entered as a
*trusted* IP by the firewall.

Without this capability, a firewall is not very useful for us.

Surely, this will not be all that hard to implement?

Good luck and hope it works out for us all.

[rw]

Spectrowl

  • Full Member
  • **
  • Offline Offline
  • location: Paris
  • Posts: 109
(No subject)
« Reply #5 on: January 20, 2007, 07:11:32 PM »
- Add custom Policy
- A plugins capability
 

* Permissions
You can't post new topics.
You can't post replies.
You can't post attachments.
You can't modify your posts.
BBCode Enabled
Smilies Enabled
[img] Enabled
HTML Disabled


Except where otherwise stated, all content Copyright © 2006 - 2010 Smokey Services™ -- All rights reserved

Surf Smokey's with confidence: all external links in posts are checked and rated by WOT - Web of Trust
Security Knowledge-, Alert- & News Center and Comprehensive Microsoft Windows Information & Download Center
Board- and databases search functions and the download of post attachments are only available to registered board members

    


==>Think your PC is infected? Click here for OTL Log Analysis and Malware Removal Assistance<==


Smokey's Security Forums provide full qualified OTL Log Analysis & Cleaning Services
OTL (formerly OTListIt2) by OldTimer is a sophisticated, comprehensive log analysis tool to clean PCs with malicious content

Microsoft Security Info & Alert Center - most recent, real-time released Microsoft Security Bulletins, Alerts, Advisories and Vulnerabilities:
<div style="background-color: none transparent;"><a href="http://www.rsspump.com/?web_widget/rss_widget" title="rss widget">Rss widget</a></div>