CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

RA and ZAP Bug

 
Post new topic   Reply to topic       All -> FavForums -> Zone Alarm [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Bill_Bright

General
General
Premium Member

Joined: Jan 16, 2004
Posts: 9046
Location: Nebraska, USA
MVP Premium

PostPosted: Tue Aug 29, 2006 2:16 am    Post subject: RA and ZAP Bug
Reply with quote

I just loaded up ZoneAlarm Pro on a remote machine and, as reported by others, I am unable to remotely control ZAP from my system. I can open the Control Center, but once open, I have no further control. I can select no option by mouse or keyboard, I cannot close the window. As mentioned, this can be resolved in the Free version of ZoneAlarm by unchecking the "protect the ZoneAlarm client" option found in ZA Free. However, that is not an option in ZAP.

It has been suggested to disable the OS Firewall option now found in current versions of ZA Pro, but that is not the same thing and still does not resolve the problem.

I have ZAP on my host machine too and I opened my host ZAP to look at it while looking at my remote ZAP. It was then I discovered a very odd bug. I can control the remote ZAP if I click on any open window, other than the remote application, on my host machine, then click on an option in the remote machine. BUT, I can only perform one operation/click. To perform another, I must return to the host machine, click on an open window, then go back to the remote machine, and click again - going back and forth, back and forth works repeatedly.

Not sure I could believe what I was seeing, I reversed roles - that is, I made my main machine the remote, and the remote machine became the controller and same thing. I could open up the ZAP control center, but could take no further action unless I moved my mouse back to the new controller machine, clicked on an open windows (not the desktop) then I could go back to the new remote machine and perform one action.

This bug is a real PITA and it needs to be addressed. In the mean time, I will roll that machine back to the free version. I will also post this over at the ZL forums.


_________________
image Bill, AFE7Ret
Freedom is NOT Free!

image
Back to top
View users profile Send private message
Hoov

Zone Alarm Host
Zone Alarm Host
PIRT Handler

Joined: Jun 21, 2002
Posts: 4613
Location: USA
1st Responders Phishing Squad Premium RootKit Detection Hosts Rootkit Responders Team F@H

PostPosted: Tue Aug 29, 2006 5:12 am    Post subject:
Reply with quote

Remote control of ZAP has actually been fairly well designed out. You have to go thru a lot of hoops to be able to do it. This is because ZoneLabs wanted to make it impossible for a third party to be able to take control of your machine remotely thru windows, and then turn off ZA. Or to control ZA by a virus or Trojan using virtual mouse clicks.

What software are you using for your RA?


_________________
For ZoneAlarm help http://www.donhoover.net
Back to top
View users profile Send private message Send email Visit posters website
Bill_Bright

General
General
Premium Member

Joined: Jan 16, 2004
Posts: 9046
Location: Nebraska, USA
MVP Premium

PostPosted: Tue Aug 29, 2006 2:07 pm    Post subject:
Reply with quote

Hey Hoov - Sure, I understand the need to ensure security - it would certainly be bad if badguys could easily tap in and gain RA to your remote systems.

I have tried TightVNC and RealVNC - both of which work great with ZA Free, and as noted above, I can it get to work with ZAP by going back and forth between server (remote) and viewer (controller) open windows. But that behavior is not right, and the fact that going back and forth between the two shows the capability is there, just not quite properly implemented.

There should be a relatively easy to find option in ZAP that relates to the ZA Free option of "protect the client" - if there is, I, and a Google search reveals many others, certainly can't find it.


_________________
image Bill, AFE7Ret
Freedom is NOT Free!

image
Back to top
View users profile Send private message
Hoov

Zone Alarm Host
Zone Alarm Host
PIRT Handler

Joined: Jun 21, 2002
Posts: 4613
Location: USA
1st Responders Phishing Squad Premium RootKit Detection Hosts Rootkit Responders Team F@H

PostPosted: Wed Aug 30, 2006 5:44 am    Post subject:
Reply with quote

Whatever program that you are using, go to the program control section in ZA, then to the program list, and for the program you are using try giving it a super trusted level. Also if your mouse has drivers that show up, give them super trusted level also.


_________________
For ZoneAlarm help http://www.donhoover.net
Back to top
View users profile Send private message Send email Visit posters website
Bill_Bright

General
General
Premium Member

Joined: Jan 16, 2004
Posts: 9046
Location: Nebraska, USA
MVP Premium

PostPosted: Wed Aug 30, 2006 2:37 pm    Post subject:
Reply with quote

I tried the Super Trusted levels for the RA programs I was using (RealVNC and TightVNC) and that did not work. I did not try it on the mouse program but note, I can do everything else on that remote machine remotely - edit the hosts file, change home page, reboot, download files, etc. It is only working within ZAP's Control Center that is affected. We can call up the ZAP Control Center, but then we're stuck with the open window.

I have since reverted the machine to ZAFree as it was only running the 15-day trial of ZAP. I have a couple new builds to do today so I will experiment with ZAP on them and the mouse settings and let you know.


_________________
image Bill, AFE7Ret
Freedom is NOT Free!

image
Back to top
View users profile Send private message
Hoov

Zone Alarm Host
Zone Alarm Host
PIRT Handler

Joined: Jun 21, 2002
Posts: 4613
Location: USA
1st Responders Phishing Squad Premium RootKit Detection Hosts Rootkit Responders Team F@H

PostPosted: Fri Sep 01, 2006 2:53 am    Post subject:
Reply with quote

ZoneAlarm protects itself from the kind of activity you are trying to do. Even if you can do other things remotely. I will try and find out if there is a way to do ZA remotely now.


_________________
For ZoneAlarm help http://www.donhoover.net
Back to top
View users profile Send private message Send email Visit posters website
Bill_Bright

General
General
Premium Member

Joined: Jan 16, 2004
Posts: 9046
Location: Nebraska, USA
MVP Premium

PostPosted: Fri Sep 01, 2006 4:18 am    Post subject:
Reply with quote

I understand that, but then that also means there's a security problem if I can get around that by doing the back and forth trick!

I did get a response over at the ZL forum and a suggestion to set an expert rule on the RA program to "allow application interaction". I will try that when I get a chance.


_________________
image Bill, AFE7Ret
Freedom is NOT Free!

image
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Zone Alarm All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer