zonealarm security issue?

Miscellaneous Forums/General Discussion/zonealarm security issue?

From time to time I run an apache server on my machines, just to transfer some files between the machines. I unplug the modem from the LAN router, so it´s pretty secure. Normally, from win98 to win98 this is working as expected: 10 MBits rate and before I can load the start page on the client machine I have to give Apache on the server the zonealarm permission in a popup.

Now I used to run apache on XP, client still on a 98se. Not only do I get only 0.4MBit/s troughput, BUT, and this is really scaring me, the client browser has the page loaded BEFORE I say "yes" in the servers zonealarm alert!!!

It is not a cache thing, the page was altered before. Hate to say it but it really seems Data is transmitted no matter if there is Zonealarm asking for an OK.


After all those years of good and reliable work with ZA (on win98 there were no problems like this) I probaby have to switch my firewall... :.(

Any Ideas what´s going on here??

No offense but:
A. your still using Windows98
B. Your using Zonealarm

Those are you two problems ;-P

This doesn´t help. I think I can use Win98 whenever I want. And I don´t surf the web with Win98. RIght now I can confirm 100% that WIn98 is way more stabile than Win XP home!!!
And I think I made clear that the Problem arises on XP, and NOT on Win98. Please read carefully.

I had about 50 crashes in one week and had to remove the Accu pack several times to be able to reboot a frozen XP on this Notebook. XP is crap, but people are forced to install it. Now go, create a new textfile, then rename it to "test.asf" and see how a multibillon $ company handles this "dilemma" on your computer (notabene after hundreds of updates and patches)... It´s not only crap, it´s total bs IMHO.

:P

I´m pretty close to the point of replacing XP by Unbuntu and throw XP out of the window. Microsoft have a new Bureau in my city (mainly for tax reasons), so I should go there and "give it back due to uselessness".


Point B - what´s wrong with Zonealarm then? You surely know something, from what you write.

ZA can be a bit flaky on win93SE - I know, I use both. I find it difficult to believe ZA is letting data pass without confirmation, though. It's always seemed to work for me. I have no experience of running an apache server, though.

Thanks for your answer. On 98se it worked properly. It´s on XP where is acts strangely. I will try to reproduce this behaviour. Apache is just a webserver app that has to ask for server permission like all apps with zonealarm.

It may however have happened somebody added a tunnel to my zonealarm installation, although ZA is one of the few firewalls that explicitely watches its files and prevents modification!

There may be a basic threat with all online updates (of any app): A bad person only has to DNS-spoof you and you will download a firewall update from their IP, instead of the real firewalls server. DNS is when you resolve an URL using an external DNS server that will return an IP that will be used to download the update. There was a security issue with DNS servers some time ago, but basicly it´s only a matter of power to force the DNS server owner to send fake IPs. This would surely be an option for a common product like ZA, for gestapo-like secret services of this new hightech millennium. I´m only thinking of the possibilities...

ZA + netgear router == no internet

ZA + networking (gaming or otherwise) on your OWN LAN == pain in the a..e

I have a subscription to ZA, didn't stop me uninstalling it at 4am this morn. Life is so mutch sweeter..... ZA is a tempormental at the least..., despite configuring numerous blah

go here http://www.personalfirewall.comodo.com/ they have a good firewall, ZA isnt the best one TBH kills two of my computers here if installed.

ZA + networking (gaming or otherwise) on your OWN LAN == pain in the a..e

That's my main beef with ZA atm, even if I set all the PCs on my LAN to have each other's IP as a trusted zone, hosting/joining still barely works unless I just kill the net connection and turn it off on each....

I really don't have much an idea on what's going up, I assume you've already done all the usual stuff upon installing ZA such as making sure WinXP is using it as the firewall program (rather than it's crap built-in one, introduced in SP2), and have the Zone Securities set to Med/High (based on preference) in the Firewall->Main tab, other than that, no clue here, unless there really is a hole open in the firewall.
(albeit it probably doesn't help that the version I'm using v6.5, been too lazy to upgrade to 7)

Get Kerio. It's free and doesn't stink in the same ways as ZA.

Kerio killed both of my windows installations

Thanks for the responses everybody. Now I took some time and made some test. First, shocking:

I was selecting ALL programs in ZA and said "remove entries", so ZA would have to ask for every app, as if it was newly installed. It warned me some of them may be system processes that requires access to prevent my PC from crashing (?...), I said yes, remove all. First they were all gone. Then I cicked a few tabs in ZA, came back to the programs tab and SHOCK! there were 4 new entries, added without any query. Most scary was Generic Host was added with full permissions except internet server rights. I never gave these permissions.
I was under the impression there are two guis, the real one and a filtered one.

I then unpugged the web, uninstalled ZA, then installed again FROM A MAGAZINE COVERDISK. I turned ZA autoupdate off and disallowed it to connect to its home server without notice.
I think this is really a good idea if you´re afraid of DNS-Spoofing, as mentioned before: use distributions of coverdisks, not your "personal download". I think for a firewall this is important.

Now I have disallowed the generic host to access the internet zone, both as a client and as a server. Although ZA warned again, everything seems to work. I also stopped the process "generic host: dns service" using sysinternals Process explorer (must have), now there is no more traffic caused by the dubious "generic host".

There is still this problem with apache: I CAN load a page on the other machine BEFORE i give apache the server permission, although this works only for the first page, for some really strange reason. It IS scary and I definitifely will try other firewalls.

unfortunately the low bandwith from apache to the other machine (0.4 Mbit, instead of 10.0 as usual with my lan) doesn´t seem to be caused by ZA, since ending ZA won´t fix it. Any Ideas what to do?

This doesn´t help. I think I can use Win98 whenever I want. And I don´t surf the web with Win98. RIght now I can confirm 100% that WIn98 is way more stabile than Win XP home!!!

Regardless, win98 is about as supported as the commadore these days....

I´m pretty close to the point of replacing XP by Unbuntu and throw XP out of the window.

Perhaps you should seriously consider that! I ran a Win2000 Server a few years back and had nothing but problems with it (specially with apache which is a free program). It seems the industry knows that for apache, you run linux/unix. After a few years of just fighting this windows box I bought new rigs (dual processor rigs) and threw Debian on them. No problems anymore....

Windows is nice for an ASP hosted site using IIS, but even then the security holes are huge and many.. The crashes can get constant, and the headaches get to be expensive in terms of buying tylonol..

Suggestion would be to dump windows, dump zone alarm, get ubantu or debian, or red hat, get a router, and be done with it once and for all :-)

Thanks for your reply. If I´m going to run a real webserver, as a host for other people then I surely won´t run apache on XP home, rather a dedicated linux distro. But right now I only use it to swap files in the LAN. I don´t want to use Shared Folders or so, because they require to open even more doors and holes.

It is working, unfort. only with 0.4 MBit/s, which obviously sucks.

yeah, that bandwidth really sucks..

Why not just use an FTP Server? Or a software VPN Tunnel?

I think I'll use an usb stick or sdcard. No installation fuss etc. Having apache with php and mysql on my machine is still usefull for offline webpage design.

PLEASE NOTE - WARNING!

I just opened msie and it went to a german microsoft homepage, Zonealarm didn't ask me if I want to allow this. It just added a permission in the msie entry for local and web client services!!!

Now, this isn't exactly what I call a firewall!

Sure it is

If you are not able to set the automatic to manuall, its your failure.
The default is to check against ZA online database for apps and set it accordingly.

Dislike that, don't use it.


But above that: had to deinstall zone alarm as well here on XP Pro ... it somehow has some serious problem and tends to lock a whole core without actually doing something.

I use Grisofts Firewall. I bout the Antivirus + Firewall solution that also works in Vista. imho I think that Grisofts Firewall + AVG is the best combination. No Pc Slowdowns, no lockups. It's simple and easy to use and keeps the idiots out.

Quote:
"If you are not able to set the automatic to manuall"

Of course I am. They were in Ask Mode, and then suddently in Allow -mode, without my permission, like magic you know.

Sure blame it on me :o)