Author Topic: AVAST 5 & 6 !! Security hole ...  (Read 14417 times)

0 Members and 1 Guest are viewing this topic.

AdrianH

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #30 on: March 19, 2011, 09:16:57 AM »
http://forum.avast.com/index.php?topic=73842.msg612920#msg612920   no explanation/response to this either.

Fact is the Windows installer can and does shut down Avast without any user input, the self defense and password protection should surely mean that the user is asked to allow this ?


Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: AVAST 5 & 6 !! Security hole ...
« Reply #31 on: March 19, 2011, 02:34:03 PM »
Which process does it shut down, exactly?
We're concerned about the avast service (AvastSvc.exe).

Thanks
Vlk
If at first you don't succeed, then skydiving's not for you.

privateofcourse

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #32 on: March 19, 2011, 02:59:04 PM »
http://forum.avast.com/index.php?topic=73842.msg612920#msg612920   no explanation/response to this either.

Fact is the Windows installer can and does shut down Avast without any user input, the self defense and password protection should surely mean that the user is asked to allow this ?

Again, I don't understand this. This is for a sysadmin to control, isn't it? If sysadmins don't want their users uninstalling stuff then this should be a policy. Are you saying that Avast is vulnerable because you can go to add remove or whatever an uninstall Avast thereby disabling services? Because if you are you are wrong because Avast prompts you when you uninstall it....so requires user interaction. Even in the scenario you posted, interaction is required.

--edit
To be fair though, I'm on XP Pro so this may be something else.
« Last Edit: March 19, 2011, 03:02:01 PM by Privateofcourse »

Pat_2

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #33 on: March 19, 2011, 04:24:03 PM »
I checked it with Win XP Pro, Vista Pro and Fam, Win 7 Starter, Win 7 32 and 64 bits.

Sorry, but you can't kill the 6.0.1000 Avast service on XP Pro via the task manager. I've got full admin rights and I still get an access denied message...and repeatedly trying to terminate the process just produces the same message. I tried to terminate the process with a few other tools as well but with the same result. I don't know how you managed this.
Same here--it can't be stopped in XP. There is no Services tab in the XP Task Manager and no way to make one show.

Hello Dch48,

True. I did it via services.msc. And killed it.

Pat

privateofcourse

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #34 on: March 19, 2011, 04:56:32 PM »
My my!  ;D So my initial incredulity was entirely appropriate  ;D
   

Pat_2

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #35 on: March 19, 2011, 06:47:14 PM »
Msg from Vlk (reply 25): quote-This is actually a valid concern, and we will fix this in the upcoming version of avast.-unquote

Hello,

Problem fixed with BETA 6.0.1035.
Thanks again to the Avast Team and particulary to Vlk.

Pat



Hermite15

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #36 on: March 19, 2011, 06:58:36 PM »
true, they finally did it... was requested more than a year ago lol... I never insisted cause I didn't care ::)

 >>>> so what happens now is that there's a password prompt to stop the AV, but not for the firewall ??? ;D

Pat_2

  • Guest
Re: AVAST 5 & 6 !! Security hole ...
« Reply #37 on: March 22, 2011, 10:22:42 AM »
Hi Logos,

">>>> so what happens now is that there's a password prompt to stop the AV, but not for the firewal"

I will take the Fifth on that one ...

Pat