View Full Version : Need help with Jetico v2
Durad
August 12th, 2006, 12:34 AM
It ask me several times to allow svchost.exe to connect to the internet even if I selected Allow/Permanently
Same for other files.
Also which of these i MUST allow to the internet and which are not necessary:
svchost.exe
csrss.exe
explorer.exe
services.exe
lsass.exe
winlogon.exe
userinit.exe
dwwin.exe
Also this message appear all the time:
-{ Quote: "Detected Network Activity!
Application: System
Activity type: send datagram (listen datagram)
Local port: 137
Remote Address: 192.168.0.113:137
Do you want to authorize it?" }-
Can anybody take few minutes to explane me?
Thanks
WSFuser
August 12th, 2006, 12:54 AM
-{ Quote: "Also which of these i MUST allow to the internet and which are not necessary:
svchost.exe
csrss.exe
explorer.exe
services.exe
lsass.exe
winlogon.exe
userinit.exe
dwwin.exe
" }-
i allow svchost.exe and block csrss.exe, explorer.exe, and services.exe. i havent gotten prompts for the others.
heres more specific info for svchost:
-{ Quote: "Windows System
If you are running Windows XP, the following applies:
C:\WINDOWS\System32\Svchost.exe
Allow access for DNS and DHCP protocols in order to connect to the Internet (required).
Allow access for NTP (to time.windows.com, time.nist.gov) for clock synchronisation (optional);
Allow access for HTTP, HTTPS (to *.microsoft.com) to access online Windows Help (optional).
Block access if any is requested for the RPC protocol to any address (a good indication of a compromised system) and for SSDP/UPnP (Universal Plug and Play) unless you are sure that you need it.
Block access for any other incoming traffic (known as Server access in ZoneAlarm or Sygate) - this is to prevent Windows Messenger spam which targets svchost.
Do not allow any network access to files named svchost.exe in other folders - they are likely to be malware" }-
taken from: Firewall Questions for beginners thread (http://www.wilderssecurity.com/showthread.php?t=142036)
Tommy
August 12th, 2006, 01:19 AM
First install Jetico1 and not v2. Its a bugy Beta. Also very complicatet. Sometimes you have to click 4 times for each aplication (access to network, network ativity, hash for access to network, hash for network comunication)
Also have a look at this #Post (http://www.wilderssecurity.com/showpost.php?p=810602&postcount=9) regarding to many Popups.
Durad
August 12th, 2006, 01:32 AM
Also these test failed at ShieldsUp (v2):
-{ Quote: "Solicited TCP Packets: RECEIVED (FAILED) — As detailed in the port report below, one or more of your system's ports actively responded to our deliberate attempts to establish a connection. It is generally possible to increase your system's security by hiding it from the probes of potentially hostile hackers. Please see the details presented by the specific port links below, as well as the various resources on this site, and in our extremely helpful and active user community.
Ping Reply: RECEIVED (FAILED) — Your system REPLIED to our Ping (ICMP Echo) requests, making it visible on the Internet. Most personal firewalls can be configured to block, drop, and ignore such ping requests in order to better hide systems from hackers. This is highly recommended since "Ping" is among the oldest and most common methods used to locate systems prior to further exploitation." }-
Is there any comparation list between 1 and 2 version of Jetico?
When v2 is planed to be final?
WSFuser
August 12th, 2006, 01:42 AM
theres no handy chart comparing the two, but the jetico site has info (http://www.jetico.com/index.htm#/jpf2.htm) on whats new and what has changed.
Stem
August 12th, 2006, 01:57 AM
-{ Quote: "Also these test failed at ShieldsUp (v2):
" }-But from your earlier post, it looks like you are behind a router,.. are you? If yes then the replies are being made from your router.
Tommy
August 12th, 2006, 01:18 PM
I can only say, that in my case Jetico v1/v2 with a proper configuration (and i think also in the setup configuration) does not fail any test from what ever side, Shildups, Sygate test and so on. The only problem seams to be the pcflanktest for Web Browser, which is a very doudable and discussable test.
As Stem says, if you are behind a router the replies are coming from your Router.
kr4ey
August 13th, 2006, 09:02 AM
Hello
I just installed Jetico v.1, I have tried it before and was never able to
get to work for me, until I read this forum.
I am able to pass the Shields Up test on grc.com and all the tests but
the Browser test. Anybody have any ideas on how to configure Jetico
to pass the Browser test, or it that more on what you setup in IE?
BTW. I am using Process Guard and Prevx 1 Beta version 2.0.0.56.
I have used Prevx on and off for a few years and allways come
back to it. Excellent program!!
It was very simple to setup Jetico this time thanks to this Forum!!
Rick
Tommy
August 13th, 2006, 10:23 AM
-{ Quote: "Hello
I just installed Jetico v.1, I have tried it before and was never able to
get to work for me, until I read this forum.
I am able to pass the Shields Up test on grc.com and all the tests but
the Browser test. Anybody have any ideas on how to configure Jetico
to pass the Browser test, or it that more on what you setup in IE?
BTW. I am using Process Guard and Prevx 1 Beta version 2.0.0.56.
I have used Prevx on and off for a few years and allways come
back to it. Excellent program!!
It was very simple to setup Jetico this time thanks to this Forum!!
" }-
Welcome Rick.
I don't think that with the possibilities of Jetico v1 you will pass the Browser test from PCFlank. Jetico v2 will have, regarding to the suport, the possibility through 'internal com - internal network' access, but is does not seam to work in this arly beta stage.
So just block referies, cookies, activeX or better 'block' IE itself as he is a dangerous :) aplication at all and use FF or Opera. IMHO tha'ts for the moment the only possibility.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums