| View previous topic :: View next topic |
| Author |
Message |
kurio
Cadet

 Joined: Feb 15, 2006 Posts: 1 Location: Canada
|
Posted: Thu Feb 16, 2006 1:35 am Post subject: Fairly easily disabled by malicious software? |
|
|
In PC Magazine's review of Kerio firewall they say that it's "fairly easily disabled by malicious software".
Would somebody comment about that?
http://www.pcmag.com/article2/0,1895,1864604,00.asp
Thanks.
|
|
| Back to top |
|
 |
steveUK
Guest IP: 84.68.*.*
|
Posted: Fri Feb 17, 2006 6:59 pm Post subject: |
|
|
All software firewalls are, some easier than others. I saw a trojan on a security site that disables all including ZA Pro, Sygate Pro, NIS etc... thats if it gets passed your antivirus undetected in the first place.
|
|
| Back to top |
|
 |
Kerodo
Private

 Joined: Feb 02, 2006 Posts: 36
|
Posted: Fri Feb 17, 2006 10:58 pm Post subject: |
|
|
I wouldn't give that comment by PC Mag too much credence.. As mentioned already, just about all firewalls can be disabled by nasty software if it's determined enough. You have to ask how likely is this to happen I guess. I personally have never worried about it, but then again, I'm not in the habit of having terrible stuff execute on my machine either, so there you go.. 
|
|
| Back to top |
|
 |
Kerodo
Private

 Joined: Feb 02, 2006 Posts: 36
|
Posted: Fri Feb 17, 2006 10:58 pm Post subject: |
|
|
I wouldn't give that comment by PC Mag too much credence.. As mentioned already, just about all firewalls can be disabled by nasty software if it's determined enough. You have to ask how likely is this to happen I guess. I personally have never worried about it, but then again, I'm not in the habit of having terrible stuff execute on my machine either, so there you go.. 
|
|
| Back to top |
|
 |
Freegoo
Cadet

 Joined: Feb 18, 2006 Posts: 1 Location: USA
|
Posted: Sat Feb 18, 2006 7:36 am Post subject: |
|
|
IMHO, this is something to be concerned about. I checked out DiamondCS's APT program and it easily shut down kerio. I've tried it on a friends computer who had Zone Alarm installed and it withstood it, and Outpost survived most of them. Kerio didn't survive any of the tests. Clearly, compared to other firewalls this is a valid point by PC Mag in my opinion.
That said, I use AppDefend right now and with it running Kerio was unaffected by any of the tests. DiamondCD also offers a free version of Process Guard that protects processes from being terminated. Perhaps the program IS overkill, and I'm sure they have their weaknesses as well... but with 0-day virii and trojans out there you can't always rely on your AV program and if your firewall is easily shut down what's the point of even running it?
That's why I run HIPS anyway, on the downside... they do get to be annoying with popup messages and constant configuring. But then again, a few weeks back our home network got infected by a worm. Every computer got nailed except for mine. It's not always paranoin. 
|
|
| Back to top |
|
 |
cm64
Corporal

 Joined: Feb 03, 2006 Posts: 63 Location: Melbourne, Australia
|
Posted: Tue Feb 21, 2006 11:36 am Post subject: |
|
|
Hi Freegoo
I tend to agree with you. It is a defect. If Zonealarm can resist these attacks I would expect Kerio be able to do the same (or better) An update to Kerio to fix this problem & the blue screen crash is overdue.
Come on Sunbelt - when will these problems be fixed ?
|
|
| Back to top |
|
 |
Graham1
Captain

 Joined: Dec 21, 2005 Posts: 340
|
|
| Back to top |
|
 |
nicM
Sergeant

 Joined: Aug 23, 2004 Posts: 128
|
Posted: Wed Feb 22, 2006 3:33 am Post subject: |
|
|
| Graham1 wrote: | | By running these tests, you have to take into account that you've already downloaded and run these "malicious" programs from your computer. |
...And Kerio does allow to control process execution (yes/no), including bad processes : something ZA doesn't do ! So this "flaw", if that's really a Sunbelt-Kerio flaw, is largely balanced by this feature.
Cheers,
nicM
|
|
| Back to top |
|
 |
nowshining Currently banned Sergeant

 Joined: Feb 02, 2006 Posts: 96
|
Posted: Sun Feb 26, 2006 11:40 am Post subject: |
|
|
get processguard free version yeah after ever so attack it says u've had a million and directs u to the webpage with its popup even if u click yes/no or X to close it..other than that once its set up and locked and that's also locked into processguards own grip..it won't be easily disabled and neither will ur antivirus if u add it to be protected by processguard. It has a demo to test it out. If its in learning mode (IE the Process guard) it will close...but set it up, lock it, let it detect ur items and itta protect it..also can be used to add programs such as antitrojans adaware scanners and the like from being shutdown when scanning by malicious processes..  _________________ mmm...sig........ -Homer Simpson from "What I Homer would say"
|
|
| Back to top |
|
 |
|
|