Author Topic: AVAST 5 & 6 !! Security hole ...  (Read 14435 times)

0 Members and 1 Guest are viewing this topic.

Pat_2

  • Guest
AVAST 5 & 6 !! Security hole ...
« on: March 14, 2011, 04:28:52 PM »
Hi Everybody,

Version 5.1.889 as well as the 6.0.1000 seems to carry a "security hole" !
Indeed, it is possible to "kill/terminate/abort" the service "avast! Antivirus" (process: AvastSvc.exe) without any problem ! And this, even if the interface is totally password protected !
This leaves the system with NO protection !
Moreover, once this service/inactive or stopped process (cross by the Avast orange ball), if you try to reactivate the "protections" thru a right click, the access to the control module is denied (wrong  password) !

Pat

Nesivos

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #1 on: March 14, 2011, 04:41:56 PM »
By default setup you can not kill/terminate/abort AvastSvc.exe.

If you would care to explain the steps that you used to kill/terminate/about AvastSvc.exe someone may be able to help you.


Pat_2

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #2 on: March 14, 2011, 05:02:07 PM »
Hi Nesivos,

In fact, thru Task manager >> Services, you can gain access to avast ! Antivirus (belonging to AvastSvc.exe) and stop it !
But you can't kill AvastSvc.exe from Task manager >> Process : Access denied !

So I don't really need help on this, but I (as well as everyboby, I guess) would like to get fixed.
I don't want anybody nor "anything" to mess with the security settings.

Pat
« Last Edit: March 14, 2011, 05:37:32 PM by Pat_2 »

Nesivos

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #3 on: March 14, 2011, 05:47:57 PM »
Hi Nesivos,

In fact, thru Task manager >> Services, you can gain access to avast ! Antivirus (belonging to AvastSvc.exe) and stop it !
But you can't kill AvastSvc.exe from Task manager >> Process : Access denied !

So I don't really need help on this, but I (as well as everyboby, I guess) would like to get fixed.
I don't want anybody nor "anything" to mess with the security settings.

Pat


As far as I know.

You still haven't explained how you were able to kill AvastSvc.exe.

Once you have explained how you did it then we can help you.


sded

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #4 on: March 14, 2011, 06:18:13 PM »
You can stop the Avast! Antivirus service from Task Manager just like you can stop the shields from the GUI.  But you need an authenticated admin to answer the popup below in the affirmative in either case.  I could also restart the service from Task Manager.  After answering "no", I got the second popup next time I tried.  You can also kill the GUI, but it does not affect the operation of Avast!

Pat_2

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #5 on: March 14, 2011, 06:33:44 PM »
Hi sded,

As far as I'm concerned, I don't get that "unable to stop service" windows even after x numbers of trials, with V 6, but I do at the second shoot with V 5. And I did experienced this on different configurations and Win versions. Which means : random problem/behavior !

So, what should be the normal behavior, is to get that "unable ..." msg in the first place, cause the system protection MUST be only controlled thru the Avast GUI. And like you said, even if the user kills the GUI, it does'nt affect the whole security process.

Pat

Pat_2

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #6 on: March 14, 2011, 06:41:12 PM »
Hello Nesivos,

Like I said in my msg, I killed it using task manager ... and since the "avast ! Antivirus" is linked to "AvastSvc.exe", the service goes into a "stopped" state.
And once again, I don't need help on it, but this to be fixed !

Pat
 

sded

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #7 on: March 14, 2011, 06:57:41 PM »
Do you get the first popup and answer it yes?  Does the result change if you answer it no and keep trying?

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11850
    • AVAST Software
Re: AVAST 5 & 6 !! Security hole ...
« Reply #8 on: March 14, 2011, 09:31:44 PM »
What operating system do you use?

Pat_2

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #9 on: March 15, 2011, 12:25:51 PM »
Hi sded,
Yes, with V 6 I do get the first one and answered YES.
Even answering NO, and keep trying doesn't change anything at all; I can stop it at every shoot if answer is YES.

Pat


Pat_2

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #10 on: March 15, 2011, 12:27:41 PM »
Hi Igor,

I checked it with Win XP Pro, Vista Pro and Fam, Win 7 Starter, Win 7 32 and 64 bits.

Pat


Pat_2

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #11 on: March 17, 2011, 10:47:40 AM »
Hi Everybody,

Here is the comment from Avast French international forum zone :
 
Quote - tout le monde est au courant depuis longtemps donc ils ne sont pas spécialement en train d'étudier le problème en passant tu peux volontairement arrêter les services mais pas tuer le processus directement, tu me diras l'effet est le même mais bon c'est vrai qu'ils n'ont pas jugé utile de protéger les services. De toutes manières le mot de passe est une barrière futile faite pour rassurer et empêcher les gosses de faire des conneries. Un adulte averti n'aura aucun mal à passer outre, même pour accéder à l'interface seulement. Un posteur l'avait démontré il y a plus d'un an. Avast le reconnait et ils s'en foutent lol. – unquote.
 
Gee ! What to think about it ? It's hard to believe this is true !
In fact what's coming out of that post is : known problem, unsolved because Services protection is considered as useless, and Avast team doesn't care !
 
Hope to read your point of view.
 
Pat

Offline lukas.hasik

  • Avast team
  • Advanced Poster
  • *
  • Posts: 931
  • Product manager of Avast Security for Windows
Re: AVAST 5 & 6 !! Security hole ...
« Reply #12 on: March 17, 2011, 01:52:06 PM »
Hi sded,
Yes, with V 6 I do get the first one and answered YES.
Even answering NO, and keep trying doesn't change anything at all; I can stop it at every shoot if answer is YES.

Pat

it's expected behavior, imho. If you answer Yes then it's obvious that you want to stop the service. And theYes/No dialog has to be clicked by a human (it's not possible to automate the click).
Quality is also a feature.

privateofcourse

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #13 on: March 18, 2011, 02:00:05 AM »
You've got to laugh or you'd cry!  ::) This seems akin to folk that run a leak test to test their firewall and then declare that the firewall is rubbish after allowing the process access to the Internet when prompted by the firewall ;D If you have admin rights and stop the process then what do you expect?  ??? Sounds pretty much like like scaremongering to me.

DBone

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #14 on: March 18, 2011, 02:04:17 AM »
This thread reminds me of a hillbilly looking down the barrel of a loaded gun to see why its jammed.