1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Other Firewall block list

Discussion in 'Software' started by Deders, 25 Mar 2011.

  1. Deders

    Deders Modder

    Joined:
    14 Nov 2010
    Posts:
    4,053
    Likes Received:
    106
    Just wondering if there is any reason to have System or Svchost on the block list for a firewall?

    For instance could some malware call itself one of these to get round a firewall?

    I've got SVChost blocked and i still have full connectivity, any reason why it should want to access the internet?

    For some reason it keeps trying to contact various Network Information Centres around the globe
     
  2. Fingers66

    Fingers66 Kiwi in London

    Joined:
    30 Apr 2010
    Posts:
    8,875
    Likes Received:
    1,055
  3. Deders

    Deders Modder

    Joined:
    14 Nov 2010
    Posts:
    4,053
    Likes Received:
    106
    Well I don't seem to have any issues with either so far, can update and access other computers on the network.
     
  4. Fingers66

    Fingers66 Kiwi in London

    Joined:
    30 Apr 2010
    Posts:
    8,875
    Likes Received:
    1,055
    afaik Windows Update and the Windows Time Service use svchost to connect to the internet.

    Try a manual windows Update and see if it still works.

    It only needs outbound.
     
  5. Deders

    Deders Modder

    Joined:
    14 Nov 2010
    Posts:
    4,053
    Likes Received:
    106
    All my updates are done manually anyway, and I've just manually updated the windows time service, last successful auto update was 1am.
     
  6. Fingers66

    Fingers66 Kiwi in London

    Joined:
    30 Apr 2010
    Posts:
    8,875
    Likes Received:
    1,055
    So have you blocked svchost inbound only then?
     
  7. Deders

    Deders Modder

    Joined:
    14 Nov 2010
    Posts:
    4,053
    Likes Received:
    106
    ahh that seems to be the case, all the logged blocked connections for it are inbound only.

    I've always been slightly suspicious of svchost as there are so many instances that appear in the task manager, If i was going to attempt to write some malware it would be the first thing i'd try to infiltrate so when commodo asked me if I wanted to block it I said yes.
     
    Last edited: 25 Mar 2011
  8. tehBoris

    tehBoris What's a Dremel?

    Joined:
    30 Jan 2011
    Posts:
    616
    Likes Received:
    25
    I would just block all inbound connections then finish, simple and effective.
     

Share This Page