Op maandag 25 juni 2001 20:26 schreef Destruction het volgende:
Black-ice

Als je de moeite had genomen om de link te volgen die hierboven gegeven had je een erg interessant artikel gevonden, over DoS en DDoS attacks en had je onderaan een test gevonden waaraan Zonalarm en BlackIce zijn onderworpen, ik citeer maar even. Over Zonealarm en BlackIce wordt het volgende geschreven:
ZoneAlarm v2.6 (Free)
The last of my testing was to see whether the firewall I keep telling everyone to use: ZoneAlarm either FREE or Pro would be effective in stopping the IRC Zombie/Bot and the Sub7 Servers that had taken up residence in my poor "Sitting Duck" laptop.
I downloaded the current, completely free, version of ZoneAlarm 2.6 from the ZoneLabs web site and installed it on the "Sitting Duck" laptop. Upon restarting the machine I was gratified to receive immediate notification that the Zombie/Bot was attempting to make an outbound connection to its IRC chat server.
Meanwhile, the Sub7 Trojan was sitting quietly waiting for someone to connect to it. So I used another machine to "Telnet" to the port the Sub7Server Trojan was listening on. Up popped ZoneAlarm asking whether the nonsense-looking random character name the Sub7Server had chosen for itself should be allowed to accept a connection from the Internet.
Perfect performance from ZoneAlarm.
Then I had a thought: What would Network ICE's BlackICE Defender do under the same circumstances?
___________________________________________
BlackICE Defender v2.5 ($39.95)
I did not have a current copy of BlackICE Defender around, but I felt that this was an important test. So I laid out $39.95 through Network ICE's connection to the Digital River eCommerce retailer and purchased the latest version (v2.5) of BlackICE Defender hot off the Internet. I had already removed all traces of ZoneAlarm and restarted the machine, so I installed BlackICE Defender, let everything settle down, and restarted the machine with my packet sniffer running on an adjacent PC.
As far as I could tell, BlackICE Defender had ABSOLUTELY NO EFFECT WHATSOEVER on the dialogs being held by the Zombies and Trojans running inside the poor "Sitting Duck" laptop. I knew that BlackICE Defender was a lame personal firewall, but this even surprised me.
The Zombie/Bot happily connected without a hitch to its IRC chat server to await further instructions. The Sub7 Trojan sent off its eMail containing the machine's IP and the port where it was listening. Then it connected and logged itself into the Sub7 IRC server, repeating the disclosure of the machine's IP address and awaiting port number. No alerts were raised, nothing was flashing in the system tray. The Trojans were not hampered and I received no indication that anything wrong or dangerous was going on.
toon volledige bericht
Het is natuurlijk geschreven op de test, maar de kern van het verhaal, een laptop (sitting duck) waar een trojan én een IRC-Bot op is geinstalleerd is getest met zowel Zonealarm als BlackIce.
- zonalarm registreert beide en vraagt of ze mogen communiceren.
- blackice registreerd
niets en laat beide programma's hun gang gaan.