CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Fairly easily disabled by malicious software?

 
Post new topic   Reply to topic       All -> FavForums -> Sunbelt KerioPF [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
kurio

Cadet
Cadet


Joined: Feb 15, 2006
Posts: 1
Location: Canada

PostPosted: Thu Feb 16, 2006 1:35 am    Post subject: Fairly easily disabled by malicious software?
Reply with quote

In PC Magazine's review of Kerio firewall they say that it's "fairly easily disabled by malicious software".
Would somebody comment about that?

http://www.pcmag.com/article2/0,1895,1864604,00.asp

Thanks.

Back to top
View users profile Send private message
steveUK

Guest
IP: 84.68.*.*






PostPosted: Fri Feb 17, 2006 6:59 pm    Post subject:
Reply with quote

All software firewalls are, some easier than others. I saw a trojan on a security site that disables all including ZA Pro, Sygate Pro, NIS etc... thats if it gets passed your antivirus undetected in the first place.

Back to top
Kerodo

Private
Private


Joined: Feb 02, 2006
Posts: 36


PostPosted: Fri Feb 17, 2006 10:58 pm    Post subject:
Reply with quote

I wouldn't give that comment by PC Mag too much credence.. As mentioned already, just about all firewalls can be disabled by nasty software if it's determined enough. You have to ask how likely is this to happen I guess. I personally have never worried about it, but then again, I'm not in the habit of having terrible stuff execute on my machine either, so there you go.. Smile

Back to top
View users profile Send private message
Kerodo

Private
Private


Joined: Feb 02, 2006
Posts: 36


PostPosted: Fri Feb 17, 2006 10:58 pm    Post subject:
Reply with quote

I wouldn't give that comment by PC Mag too much credence.. As mentioned already, just about all firewalls can be disabled by nasty software if it's determined enough. You have to ask how likely is this to happen I guess. I personally have never worried about it, but then again, I'm not in the habit of having terrible stuff execute on my machine either, so there you go.. Smile

Back to top
View users profile Send private message
Freegoo

Cadet
Cadet


Joined: Feb 18, 2006
Posts: 1
Location: USA

PostPosted: Sat Feb 18, 2006 7:36 am    Post subject:
Reply with quote

IMHO, this is something to be concerned about. I checked out DiamondCS's APT program and it easily shut down kerio. I've tried it on a friends computer who had Zone Alarm installed and it withstood it, and Outpost survived most of them. Kerio didn't survive any of the tests. Clearly, compared to other firewalls this is a valid point by PC Mag in my opinion.

That said, I use AppDefend right now and with it running Kerio was unaffected by any of the tests. DiamondCD also offers a free version of Process Guard that protects processes from being terminated. Perhaps the program IS overkill, and I'm sure they have their weaknesses as well... but with 0-day virii and trojans out there you can't always rely on your AV program and if your firewall is easily shut down what's the point of even running it?

That's why I run HIPS anyway, on the downside... they do get to be annoying with popup messages and constant configuring. But then again, a few weeks back our home network got infected by a worm. Every computer got nailed except for mine. It's not always paranoin. Laughing

Back to top
View users profile Send private message
cm64

Corporal
Corporal


Joined: Feb 03, 2006
Posts: 63
Location: Melbourne, Australia

PostPosted: Tue Feb 21, 2006 11:36 am    Post subject:
Reply with quote

Hi Freegoo
I tend to agree with you. It is a defect. If Zonealarm can resist these attacks I would expect Kerio be able to do the same (or better) An update to Kerio to fix this problem & the blue screen crash is overdue.
Come on Sunbelt - when will these problems be fixed ?

Back to top
View users profile Send private message
Graham1

Captain
Captain


Joined: Dec 21, 2005
Posts: 340


PostPosted: Tue Feb 21, 2006 6:22 pm    Post subject:
Reply with quote

By running these tests, you have to take into account that you've already downloaded and run these "malicious" programs from your computer. In real life, it depends on your surfing habits Wink but would you download something that you wasn't sure about (and run it). If your downloading illigal software, then your asking for trouble Crying or Very sad.

Smile

Back to top
View users profile Send private message
nicM

Sergeant
Sergeant


Joined: Aug 23, 2004
Posts: 128


PostPosted: Wed Feb 22, 2006 3:33 am    Post subject:
Reply with quote

Graham1 wrote:
By running these tests, you have to take into account that you've already downloaded and run these "malicious" programs from your computer.


...And Kerio does allow to control process execution (yes/no), including bad processes Smile : something ZA doesn't do ! So this "flaw", if that's really a Sunbelt-Kerio flaw, is largely balanced by this feature.

Cheers,
nicM

Back to top
View users profile Send private message
nowshining
Currently banned

Sergeant
Sergeant


Joined: Feb 02, 2006
Posts: 96


PostPosted: Sun Feb 26, 2006 11:40 am    Post subject:
Reply with quote

get processguard free version yeah after ever so attack it says u've had a million and directs u to the webpage with its popup even if u click yes/no or X to close it..other than that once its set up and locked and that's also locked into processguards own grip..it won't be easily disabled and neither will ur antivirus if u add it to be protected by processguard. It has a demo to test it out. If its in learning mode (IE the Process guard) it will close...but set it up, lock it, let it detect ur items and itta protect it..also can be used to add programs such as antitrojans adaware scanners and the like from being shutdown when scanning by malicious processes.. Smile


_________________
mmm...sig........ -Homer Simpson from "What I Homer would say"
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Sunbelt KerioPF All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer