<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/">

  <channel rdf:about="http://www.matousec.com/info/">

    <title>Matousec - Blog</title>

    <link>http://www.matousec.com/matousec/blog.php</link>

    <description>Blog on matousec.com site</description>

    <items>

      <rdf:Seq>

<rdf:li resource="http://www.matousec.com/matousec/blog.php#Do-not-use-GRC_____s-LeakTest" />
<rdf:li resource="http://www.matousec.com/matousec/blog.php#New-versions-of-ZoneAlarm-and-PC-Tools" />
<rdf:li resource="http://www.matousec.com/matousec/blog.php#Privatefirewall-goes-free_" />
<rdf:li resource="http://www.matousec.com/matousec/blog.php#Outpost-___" />
<rdf:li resource="http://www.matousec.com/matousec/blog.php#KIS-____" />
<rdf:li resource="http://www.matousec.com/matousec/blog.php#Outpost-Firewall-Free-____" />
<rdf:li resource="http://www.matousec.com/matousec/blog.php#Comodo-Internet-Security" />
<rdf:li resource="http://www.matousec.com/matousec/blog.php#Checkmark-Desktop-Firewall-Certification-and-Rising-Firewall" />
      </rdf:Seq>

    </items>

  </channel>

<item rdf:about="http://www.matousec.com/matousec/blog.php#Do-not-use-GRC_____s-LeakTest">
<title>Do not use GRC&amp;#39;s LeakTest
</title>
<link>http://www.matousec.com/matousec/blog.php?blog=135-Do-not-use-GRC_____s-LeakTest</link>
<description>&lt;p&gt;During the last few weeks, we have received a couple of emails concerning the security of PC Tools Firewall Plus. Our visitors ask us, &lt;b&gt;how is it possible that PC Tools Firewall Plus is rated highly in &lt;a href=&quot;http://www.matousec.com/projects/proactive-security-challenge/&quot;&gt;Proactive Security Challenge&lt;/a&gt; when it is not able to block the very simple &lt;a href=&quot;http://www.grc.com/lt/leaktest.htm&quot; class=&quot;link_out&quot; target=&quot;_blank&quot;&gt;GRC's LeakTest&lt;/a&gt;&lt;/b&gt;, a tiny testing program that was written many years ago. Regardless the configuration of PC Tools Firewall Plus, clicking Test For Leaks button in GRC's LeakTest leads to the big red &lt;q&gt;Firewall Penetrated!&lt;/q&gt; alert. 

&lt;p class=&quot;blog_body&quot;&gt;Being that a repetitive question, we have decided to analyze the situation. We found out that &lt;b&gt;GRC's LeakTest is just a poorly written program that suffers from reporting false results in some cases, especially in case of PC Tools Firewall Plus&lt;/b&gt;. Why is PC Tools Firewall Plus so special compared to others in a way it does not pass GRC's LeakTest even if the user uses the block button in PC Tools Firewall Plus's alert? In case of most products on the market, when the action of outbound connection is blocked, the product cuts the connection completely and report an error message to the offending application. For example if a web browser is blocked, it reports some kind of connection failure message to the user. PC Tools Firewall Plus, however, does not do it that way. Its developers implemented it in a way that might be considered as more polite to the end user. If the connection is blocked on the machine via PC Tools Firewall Plus, it seems to the application as if the connection was successful and then any attempt to read the data from the server leads to reception of an &lt;b&gt;informative message that explains that the connection was blocked by PC Tools Firewall Plus and also explains what to do to allow the blocked application to connect in case it was not the real user's intention to block it&lt;/b&gt;. So, if the user accidentally blocked the legitimate browser application, they will see the informative message and will have no problem to fix the situation. This may be considered as a better approach compared to the situation when the default error message is shown to the user, which is also displayed in case of many other error situations including the target server failure, network failure etc.

&lt;p class=&quot;blog_body&quot;&gt;The problem with GRC's LeakTest is that it does not verify that it connected to the target server. &lt;b&gt;No proper verification is done&lt;/b&gt; and since it is able to read some data it suppose the firewall was penetrated while in fact it is just a message from PC Tools Firewall Plus. 

&lt;p class=&quot;blog_body&quot;&gt;Testing programs are important tools for developers, testers and users, but they should never be blindly trusted. Unlike GRC's LeakTest, our tests in &lt;a href=&quot;http://www.matousec.com/projects/security-software-testing-suite/&quot;&gt;Security Software Testing Suite&lt;/a&gt; are designed to always verify and provide proves of the reported results if possible and even then our testers never blindly rely on the test's output. 
</description>
<dc:date>2010-02-17T13:37:52Z</dc:date>
</item>
<item rdf:about="http://www.matousec.com/matousec/blog.php#New-versions-of-ZoneAlarm-and-PC-Tools">
<title>New versions of ZoneAlarm and PC Tools
</title>
<link>http://www.matousec.com/matousec/blog.php?blog=130-New-versions-of-ZoneAlarm-and-PC-Tools</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.matousec.com/matousec/redirect.php?product=25&quot; class=&quot;link_out&quot; target=&quot;_blank&quot;&gt;PC Tools Firewall Plus 6&lt;/a&gt; has been released. The new version should come with Windows 7 support and significant improvements of application protection module. We will test the new version in our next &lt;a href=&quot;http://www.matousec.com/projects/proactive-security-challenge/&quot;&gt;Proactive Security Challenge&lt;/a&gt; update.

&lt;p class=&quot;blog_body&quot;&gt;Also new versions of &lt;a href=&quot;http://www.matousec.com/matousec/redirect.php?product=9&quot; class=&quot;link_out&quot; target=&quot;_blank&quot;&gt;ZoneAlarm&lt;/a&gt; products have been released recently. The 2010 series newly supports Windows 7. In our security testing project, we will replace ZoneAlarm Pro with ZoneAlarm Extreme Security to get the best ZoneAlarm products can offer. The new version will be tested soon.
</description>
<dc:date>2009-09-02T14:12:34Z</dc:date>
</item>
<item rdf:about="http://www.matousec.com/matousec/blog.php#Privatefirewall-goes-free_">
<title>Privatefirewall goes free!
</title>
<link>http://www.matousec.com/matousec/blog.php?blog=129-Privatefirewall-goes-free_</link>
<description>&lt;p&gt;A great news for all fans of &lt;a href=&quot;http://www.privacyware.com/personal_firewall.html&quot; class=&quot;link_out&quot; target=&quot;_blank&quot;&gt;Privatefirewall&lt;/a&gt; has been announced by its vendor PWI, Inc. Since Privatefirewall 6.1.20.24 (the latest version at the time of this announcement), &lt;b&gt;the whole product is free of charge, without any limitations&lt;/b&gt;. Also, the new version is ready for Windows 7. Other related products of PWI, Inc. including DSA (free product with only a part of the functionality provided by Privatefirewall) have been discontinued.
</description>
<dc:date>2009-07-30T18:36:24Z</dc:date>
</item>
<item rdf:about="http://www.matousec.com/matousec/blog.php#Outpost-___">
<title>Outpost 6.7
</title>
<link>http://www.matousec.com/matousec/blog.php?blog=128-Outpost-___</link>
<description>&lt;p&gt;Agnitum Ltd. released new versions of their &lt;a href=&quot;http://www.matousec.com/matousec/redirect.php?product=12&quot; class=&quot;link_out&quot; target=&quot;_blank&quot;&gt;Outpost products&lt;/a&gt;. Even if this is not a major release, 6.7 series might be interesting for many because of its support of Microsoft's new operating system Windows 7, which  final version should be available in autumn this year. Another interesting improvement in new Outpost is that the content filtering is now fully compatible with P2P clients and rich-media websites.
</description>
<dc:date>2009-07-23T13:08:57Z</dc:date>
</item>
<item rdf:about="http://www.matousec.com/matousec/blog.php#KIS-____">
<title>KIS 2010
</title>
<link>http://www.matousec.com/matousec/blog.php?blog=126-KIS-____</link>
<description>&lt;p&gt;&lt;a href=&quot;http://www.matousec.com/matousec/redirect.php?product=17&quot; class=&quot;link_out&quot; target=&quot;_blank&quot;&gt;Kaspersky Internet Security 2010&lt;/a&gt; is out. It comes with several new functions and various improvements. Among the noticeable new features, we can mention the Safe Run mode which enables the users to run new software in an isolated environment so that it can not harm the operating system or other applications. Another new features are the Game Mode &amp;ndash; reducing alerts during playing games, and Kaspersky Toolbar for Internet browsers that warns about known dangerous websites. Read more in &lt;a href=&quot;http://www.kaspersky.com/news?id=207575849&quot; class=&quot;link_out&quot; target=&quot;_blank&quot;&gt;the official press release&lt;/a&gt; on Kaspersky Lab's website. We will schedule the testing of KIS 2010 as soon as possible.
</description>
<dc:date>2009-06-25T09:54:49Z</dc:date>
</item>
<item rdf:about="http://www.matousec.com/matousec/blog.php#Outpost-Firewall-Free-____">
<title>Outpost Firewall Free 2009
</title>
<link>http://www.matousec.com/matousec/blog.php?blog=123-Outpost-Firewall-Free-____</link>
<description>&lt;p&gt;Very popular Outpost Firewall is now also available in a lightweight version called &lt;a href=&quot;http://free.agnitum.com/&quot; class=&quot;link_out&quot; target=&quot;_blank&quot;&gt;Outpost Firewall Free&lt;/a&gt;. The previous free version of Outpost Firewall was released in 2002 and its protection was outdated for several years. The new free version is based on the engine of the commercial version with some features removed. Outpost Firewall Free offers Firewall, Proactive host protection and Self protection features as the Pro version but it misses Anti-Spyware, Web control, Identity Protection features and Multi-language support. This product may quickly become a great alternative for the users that require free solutions.
</description>
<dc:date>2009-04-27T12:47:36Z</dc:date>
</item>
<item rdf:about="http://www.matousec.com/matousec/blog.php#Comodo-Internet-Security">
<title>Comodo Internet Security
</title>
<link>http://www.matousec.com/matousec/blog.php?blog=115-Comodo-Internet-Security</link>
<description>&lt;p&gt;A few days ago, &lt;a href=&quot;http://www.matousec.com/matousec/redirect.php?vendor=7&quot; class=&quot;link_out&quot; target=&quot;_blank&quot;&gt;Comodo Security Solutions, Inc.&lt;/a&gt; released new security products called &lt;a href=&quot;http://www.matousec.com/matousec/redirect.php?product=7&quot; class=&quot;link_out&quot; target=&quot;_blank&quot;&gt;Comodo Internet Security and Comodo Internet Security Pro&lt;/a&gt;. These are security suites that combine classic firewall, personal firewall and anti-virus features. Comodo Internet Security is completely free while Comodo Internet Security Pro includes paid services. For more information, visit the vendor's website.
</description>
<dc:date>2008-10-28T11:31:27Z</dc:date>
</item>
<item rdf:about="http://www.matousec.com/matousec/blog.php#Checkmark-Desktop-Firewall-Certification-and-Rising-Firewall">
<title>Checkmark Desktop Firewall Certification and Rising Firewall
</title>
<link>http://www.matousec.com/matousec/blog.php?blog=114-Checkmark-Desktop-Firewall-Certification-and-Rising-Firewall</link>
<description>&lt;p&gt;One of our visitors asked us a question about Rising Firewall passing Checkmark Desktop Firewall Certification. He asked how it was possible that Rising scored so bad in our tests while it was able to pass the certification by West Coast Labs. This blog post is about what Checkmark Desktop Firewall Certification really means and how it is related to Firewall Challenge testing.
</description>
<dc:date>2008-10-20T08:22:53Z</dc:date>
</item>
</rdf:RDF>

