CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[BIG SECURITY BUG]KPFGUI is not isolated by Internet!!! why?

 
Post new topic   Reply to topic       All -> FavForums -> Sunbelt KerioPF [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Dan

Guest
IP: 82.61.*.*






PostPosted: Tue Aug 01, 2006 9:39 am    Post subject: [BIG SECURITY BUG]KPFGUI is not isolated by Internet!!! why?
Reply with quote

Why KPFGUI.exe is not isolated by Internet? Why I always get a lot of incoming attempts from the Internet towards KPFGUI.exe? Please fix this big security issue!

Back to top
Graham1

Captain
Captain


Joined: Dec 21, 2005
Posts: 340


PostPosted: Tue Aug 01, 2006 12:56 pm    Post subject:
Reply with quote

Manually create a packet filter rule denying access (both directions) to kpf4gui.exe (or application rule after prompt). Skpf4 will function without problems using internal rules.

Smile

Back to top
View users profile Send private message
ondrej

Guest
IP: 147.229.*.*






PostPosted: Sat Nov 04, 2006 2:40 am    Post subject: Re: [BIG SECURITY BUG]KPFGUI is not isolated by Internet!!!
Reply with quote

Dan wrote:
Why KPFGUI.exe is not isolated by Internet? Why I always get a lot of incoming attempts from the Internet towards KPFGUI.exe? Please fix this big security issue!


I think there is no reason to be worried about these processes. At least kpfgui.exe should'nt be dangerous. From what I know kpfgui is trying to resolve port, protocol and adress of connections listed in its gui. So mostly you'll see dns lookups, udp traffic and nothing that looks really consistent to make a rule of. You can create a rule to allow (decreases your exposure to potential threats) or deny (doesn't affect working of fw) this kind of communication or you can ignore it.

Back to top
carl

Guest
IP: 87.16.*.*






PostPosted: Sat Nov 04, 2006 10:13 am    Post subject: Re: [BIG SECURITY BUG]KPFGUI is not isolated by Internet!!!
Reply with quote

ondrej wrote:

I think there is no reason to be worried about these processes. At least kpfgui.exe should'nt be dangerous. From what I know kpfgui is trying to resolve port, protocol and adress of connections listed in its gui. So mostly you'll see dns lookups, udp traffic and nothing that looks really consistent to make a rule of. You can create a rule to allow (decreases your exposure to potential threats) or deny (doesn't affect working of fw) this kind of communication or you can ignore it.


But sometimes an INCOMING connection go to kpfgui.exe and this is bad!!!

Back to top
Graham1

Captain
Captain


Joined: Dec 21, 2005
Posts: 340


PostPosted: Sat Nov 04, 2006 6:26 pm    Post subject:
Reply with quote

You just need to create a rule denying access to this process. The worst that would happen, if allowed, would show an open port when scanned (i.e showing your computer as online). Any functions by SKPF4 are performed as normal, regardless of the rule in place.

Smile

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Sunbelt KerioPF All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer