Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 26th, 2009, 05:21 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Exclamation Sneaky Prevx

Sir,

In ZA all my Apps are configured to Always ask me for permission for access to the internet. So how does Prevx manage to sneak out data after detecting something new, or a potentially FP ?

Malware could quite easily make use of this technique surely ! So how to only allow the good guys like Prevx, and block the bad ?

Concerned in Tunbridge Wells.
  #2  
Old July 26th, 2009, 05:36 AM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: Sneaky Prevx

are you sure you have not allowed Prevx, and whatever .exe it uses, access to the net?
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #3  
Old July 26th, 2009, 05:40 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Exclamation Re: Sneaky Prevx

Hi, yes i've just rechecked for you, and, Everything in ZA is set with a ? or X
  #4  
Old July 26th, 2009, 05:58 AM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: Sneaky Prevx

if you click block all network traffic can Prevx connect?
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #5  
Old July 26th, 2009, 06:03 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: Sneaky Prevx

No, just tried by double clicking on a new file.
  #6  
Old July 26th, 2009, 06:07 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Lightbulb Re: Sneaky Prevx

Just thought, it might be using FF to sneak out ? Going to log off and close all browsers and try. I'll be back.
  #7  
Old July 26th, 2009, 06:23 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Question Re: Sneaky Prevx

No it wasn't that, so
  #8  
Old July 26th, 2009, 06:29 AM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: Sneaky Prevx

in ZA amongst the apps allowed out there will be a prevx component
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #9  
Old July 26th, 2009, 06:35 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: Sneaky Prevx

Not that i can see, have a look
Attached Thumbnails
Click image for larger version

Name:	za.png
Views:	11
Size:	34.5 KB
ID:	210748  

  #10  
Old July 26th, 2009, 06:50 AM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: Sneaky Prevx

what happens if you block that prevx entry?
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #11  
Old July 26th, 2009, 08:23 AM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Angry Re: Sneaky Prevx

It doesn't get out when i block all 4, but then ....

Jeepers creepers, would you belive it ? All i did was change 1 thing as in the screenie, and out it goes with NO warning. What's up with that

Not good at all, and makes me now wonder about what else could escape, or has !

Well i'm looking forward to an answer from someone at Prevx ASAP, not that it's possibly their fault of course. But if they need data out and peoples FW's block it, then it won't reach them. But it shouldn't surrupticiously bypass a FW, if that's what it's doing !

I'm all ears, i mean eyes.

Cudni Thanx for your input.

S
Attached Images
 
  #12  
Old July 26th, 2009, 08:51 AM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: Sneaky Prevx

it would interesting to hear what ZA has to say and why is there no prompt for connection (could be a bug)
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #13  
Old July 26th, 2009, 12:34 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,582
Default Re: Sneaky Prevx

That's weird indeed We aren't using anything strange to connect out... if you ask someone at ZL, you can tell them that Prevx uses the 'cURL' library to connect out.
  #14  
Old July 26th, 2009, 01:12 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Sneaky Prevx

Just curious, StevieO... you're using Online Armor Firewall and ZoneAlarm together?
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #15  
Old July 26th, 2009, 05:02 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Unhappy Re: Sneaky Prevx

Cudni

Quite honestly i doubt if ZA would even respond, as i'm using v5.5.062.000 on XP.

PrevxHelp

OK that's good to hear. Not sure exactly what 'cURL' library is, so i'll look it up.

Page42

Actually no, that entry must be from a previous OA version i tried, and i'm using the free version not Premium, so i don't know why it shows that ?

Thanx all
  #16  
Old July 27th, 2009, 04:35 AM
HKEY1952 HKEY1952 is offline
Frequent Poster
 
Join Date: Jul 2009
Location: HKEY/SECURITY/ (value not set)
Posts: 638
Default Re: Sneaky Prevx

In the background ZoneAlarm silently uses the Application Layer Gateway Service for communications to bypass its Firewall.
With ZoneAlarm the Firewall Rules are superficial because ZoneAlarm does as it wants when it comes to communications.
One can create an Block Rule and ZoneAlarm will find away around the block through the Application Layer Gateway Service.
The TrueVector Service patches the Windows Kernel far too deep for my comfort.

HKEY1952
  #17  
Old July 27th, 2009, 05:49 AM
Airflow Airflow is offline
Infrequent Poster
 
Join Date: Jul 2009
Posts: 39
Post Re: Sneaky Prevx

Quote:
But it shouldn't surrupticiously bypass a FW,
lol, what did you expect?
__________________
It´s all about fun
  #18  
Old July 27th, 2009, 05:41 PM
StevieO's Avatar
StevieO StevieO is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 1,068
Default Re: Sneaky Prevx

HKEY1952

Really, sheesh, how about that, the barstewards !

After you wrote that i X'd all the lines in ZA for ALG, which didn't seem to prevent any problems to anything. But now i'm trying out the FW in OA, so i'll see what does, or doesn't !

Thanx for the Very helpful insight.

Airflow

Err, not that lol.


S
  #19  
Old July 27th, 2009, 11:32 PM
fax's Avatar
fax fax is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,553
Default Re: Sneaky Prevx

Quote:
Originally Posted by HKEY1952
In the background ZoneAlarm silently uses the Application Layer Gateway Service for communications to bypass its Firewall. HKEY1952

LOL what a crap, ZA does not need alg.exe, it filters all communication via vsmon.exe, the firewall driver cannot be blocked via ZA. ZA cannot block itself (you can however turn off all the features that communicate out).

Every year a new conspiracy theory on ZA. Must be like MS BS secret code... ZA was tested here by Stem and others and there was NO leaks OUT, stop posting BS!!

On the other issue... well XP was not even there with version 5.5... sooo you can draw your own conclusions. Have you tried any more recent versions?

Fax

Last edited by fax : July 28th, 2009 at 12:14 AM. Reason: checked spelling
  #20  
Old July 28th, 2009, 02:15 AM
HKEY1952 HKEY1952 is offline
Frequent Poster
 
Join Date: Jul 2009
Location: HKEY/SECURITY/ (value not set)
Posts: 638
Default Re: Sneaky Prevx

Quote:
Originally Posted by fax
LOL what a crap, ZA does not need alg.exe, it filters all communication via vsmon.exe, the firewall driver cannot be blocked via ZA. ZA cannot block itself (you can however turn off all the features that communicate out).

Every year a new conspiracy theory on ZA. Must be like MS BS secret code... ZA was tested here by Stem and others and there was NO leaks OUT, stop posting BS!!

On the other issue... well XP was not even there with version 5.5... sooo you can draw your own conclusions. Have you tried any more recent versions?

Fax

No one is talking about blocking ZoneAlarm or blocking the firewall driver, why don't you get your FAX straight before you Post.
Also, the ZoneAlarm Forum tactics of defending ZoneAlarm do not work over here at the Wilders Security Forums.
It is an FAX that the Application Layer Gateway Service can be used to bypass Firewalls.
ZoneAlarm is currently only surviving on past reputation, and that reputation is rapidly decaying.
Perhaps I sentenced it wrong in my first Post, it should have read:
The ZoneAlarm vsmon.exe uses the Application Layer Gateway Service in its communications to bypass its Firewall.
You know for an FAX that most of the ZoneAlarm Rules, especially the Expert Rules are ignored by ZoneAlarm and most of the Rules are superficial.
Trying to setup Custom Rules or Expert Rules always corrupts ZoneAlarm and the ZoneAlarm user receives the famous ZoneAlarm Forum remedy:
You have corrupted your installation of ZoneAlarm, you need to Reset ZoneAlarm. Now that's BS.


HKEY1952
  #21  
Old July 28th, 2009, 02:38 AM
fax's Avatar
fax fax is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,553
Default Re: Sneaky Prevx

Quote:
Originally Posted by HKEY1952
The ZoneAlarm vsmon.exe uses the Application Layer Gateway Service in its communications to bypass its Firewall. HKEY1952
ehu? LoL What are you talking about?
ZA using ALG to avoid itself? It does not need to.
It will use its own/MS services to connects out! May be you should put some FACTS on the table. Because otherwise it looks like you have been smoking something strange

No comment on the rest of the post... already gives the reader a clear flavour on your ZA feelings

Fax
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:58 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums