Author Topic: Security leak?  (Read 13609 times)

0 Members and 1 Guest are viewing this topic.

Sparan

  • Guest
Security leak?
« on: March 17, 2005, 04:39:14 PM »
I'm not very techy so please bear with me but it seems that since I installed Avast, my firewall (Kerio) no longer does it's job! For example if I specifically try to block a program  like Ad-Aware in Kerio from going outbound, I can still update it and it doesn't show up in Kerio's logs!  Is this to do with the Web Shield/Web Scanner acting as a proxy and if so, what do I do to correct the situation as a firewall that does not control outbound traffic isn't very good.
I assume this matter must have been discussed before (I looked around but couldn't see anything) so I would appreciate a link or an explanation if someone would be so kind.

fredra

  • Guest
Re: Security leak?
« Reply #1 on: March 17, 2005, 05:36:21 PM »
Hi Sparan
I hope this helps...go here and read BZ's (kerio guru) explaination in #12 message.
http://www.wilderssecurity.com/showthread.php?t=69544
He gives some detail on what to setup in Kerio.
Also, there is some clarification by VLK, in the same thread.
Cheers  :)
« Last Edit: March 17, 2005, 05:39:07 PM by fredra »

artamangr

  • Guest
Re: Security leak?
« Reply #2 on: March 17, 2005, 06:10:40 PM »
Does that mean that webshield scans outgoing http streams as well?

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: Security leak?
« Reply #3 on: March 17, 2005, 06:17:30 PM »
To start, you should update to v4.6.623. This version only filters (intercepts) traffic coming from specific applications.
If at first you don't succeed, then skydiving's not for you.

lee16

  • Guest
Re: Security leak?
« Reply #4 on: March 17, 2005, 06:56:52 PM »
Quote
To start, you should update to v4.6.623. This version only filters (intercepts) traffic coming from specific applications.

Does this sort out the problem the webshield was having with Sygate?

--lee

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89051
  • No support PMs thanks
Re: Security leak?
« Reply #5 on: March 17, 2005, 07:31:19 PM »
Quote
To start, you should update to v4.6.623. This version only filters (intercepts) traffic coming from specific applications.

Does this sort out the problem the webshield was having with Sygate?

--lee

Until Sygate resolve the ablilty to monitor localhost proxy traffic, this issue has been know about for a very long time but it has yet to be resolved. So I doubt that this 4.6.623 release will make a blind bit of difference to the sygate security hole.

http://forums.sygate.com/vb/showthread.php?s=de402c841bcc0b077d6bc116bcba5f47&threadid=12947
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: Security leak?
« Reply #6 on: March 17, 2005, 07:37:48 PM »
Actually it does make a difference. With the exception of the programs on the approval list of avast, no WebShield scanning is now taking place and therefore Sygate sees everything as usual (outbound access to remote hosts).
If at first you don't succeed, then skydiving's not for you.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89051
  • No support PMs thanks
Re: Security leak?
« Reply #7 on: March 17, 2005, 10:27:59 PM »
Actually it does make a difference. With the exception of the programs on the approval list of avast, no WebShield scanning is now taking place and therefore Sygate sees everything as usual (outbound access to remote hosts).

That's good, thankfully it hasn't taken anywhere near as long as Sygate have taken to resolve the local proxy leak.

Is there any way to find out the programs on the approval list?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: Security leak?
« Reply #8 on: March 17, 2005, 10:36:07 PM »
Currently, just the mainstream browsers are on the list (including IE, mozilla, firefox, MyIE2 and Maxthon).
Some more info is here: http://forum.avast.com/index.php?topic=11997.msg101370#msg101370
If at first you don't succeed, then skydiving's not for you.

Jarmo P

  • Guest
Re: Security leak?
« Reply #9 on: March 17, 2005, 10:41:58 PM »
That is really good Vlk!
It really is not so bad when it remains just to trusted browsers and stuff that gets possible virus/trojan web traffic. Just what the web shield is for :)

stevejrc

  • Guest
Re: Security leak?
« Reply #10 on: March 17, 2005, 10:57:02 PM »
does this mean that sygate will work correctly now e.g. asking for access instead of letting everything through webshield ?   bit confused  ???

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: Security leak?
« Reply #11 on: March 17, 2005, 10:58:03 PM »
Yes stevejrc that's what I'm saying.
If at first you don't succeed, then skydiving's not for you.

stevejrc

  • Guest
Re: Security leak?
« Reply #12 on: March 17, 2005, 11:07:05 PM »
 ;D cool   have a budvar on me

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Security leak?
« Reply #13 on: March 18, 2005, 03:29:39 AM »
Yes stevejrc that's what I'm saying.

This is not working if you have a local proxy...
Maybe, as usual, I'm doing something wrong...  ::)
The best things in life are free.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Security leak?
« Reply #14 on: March 18, 2005, 03:32:12 AM »
Until Sygate resolve the ablilty to monitor localhost proxy traffic, this issue has been know about for a very long time but it has yet to be resolved. So I doubt that this 4.6.623 release will make a blind bit of difference to the sygate security hole. http://forums.sygate.com/vb/showthread.php?s=de402c841bcc0b077d6bc116bcba5f47&threadid=12947

David, do you know if any other firewall does this job?
I mean, neither Kerio not Sygate seems to filter the outbound HTTP traffic if you're using a local proxy filter...
Does ZA do this job? Will the applications ask for connection even using a local proxy (this one allowed to connect)?
The best things in life are free.