PDA

View Full Version : PG 3.4x does not protect against APT kill processes


djg05
September 27th, 2006, 09:53 AM
I have been trying to protect Kerio 2.1.5 with PG and found with ver 3.4 and the latest that Kill 3 or 4 in APT will shut Kerio down. This protecting Kerio by ticking boxes "Termination" & "Modification. I tried ver 3.1.4.0 and it was successfull in stopping the closure.

Has anyone else found this?

Paranoid2000
September 27th, 2006, 09:52 PM
You need to enable the SMH (Secure Message Handling) option on the process in PG's Protection tab to counter APT methods 3 and 4.

djg05
September 29th, 2006, 11:17 AM
-{ Quote: "You need to enable the SMH (Secure Message Handling) option on the process in PG's Protection tab to counter APT methods 3 and 4." }-

Thanks Paranoid

Never sure when this should be enabled, obviously this is a case in point and it does prevent the exploit.

nadirah
October 1st, 2006, 01:56 AM
-{ Quote: " This protecting Kerio by ticking boxes "Termination" & "Modification." }-

What about reading?

Did you enable reading protection for all programs listed in PG? I'm surprised that apt could kill your firewall, APT by right should not be able to 'see' any processes on your computer at all IF you have reading protection on for all programs in PG. You don't even need SMH when you've got reading protection enabled, because APT can't read the running programs on your computer! :isay:

It's NOT PG failing to protect against APT, it's because you did not configure it correctly! With "reading" protection enabled APT CANNOT touch any process on your computer!

nadirah
October 1st, 2006, 02:01 AM
-{ Quote: "You need to enable the SMH (Secure Message Handling) option on the process in PG's Protection tab to counter APT methods 3 and 4." }-

I think she failed to notice the 'reading' protection feature in PG and did not enable it, thus APT could meddle with her firewall. ;) Maybe pictures will explain this situation further.

nadirah
October 1st, 2006, 02:04 AM
APT says 37 processes, but nothing is shown!

nadirah
October 1st, 2006, 02:08 AM
Do you get this in your PG logfile? Hope my explanation reveals the answer to this thread...

djg05
October 1st, 2006, 08:47 AM
-{ Quote: "[/B]What about reading?

Did you enable reading protection for all programs listed in PG? I'm surprised that apt could kill your firewall, APT by right should not be able to 'see' any processes on your computer at all IF you have reading protection on for all programs in PG. You don't even need SMH when you've got reading protection enabled, because APT can't read the running programs on your computer! :isay:

It's NOT PG failing to protect against APT, it's because you did not configure it correctly! With "reading" protection enabled APT CANNOT touch any process on your computer!" }-

That is true, but it does not stop the process being killed.

Untick the reading, run APT and the process is displayed. Re enable Reading, and APT can still kill the process. So if APT had a command line I assume that Kerio could still be targetted.

As I understand it, the reading only makes it invisible not protected. Kerio is still listed in Windows Task Manager.

Paranoid2000
October 2nd, 2006, 08:47 AM
-{ Quote: "That is true, but it does not stop the process being killed." }-Indeed, if you were using an earlier version of APT, you could have terminated the process by specifying its ID manually (v4 dropped this feature).