PDA

View Full Version : ZONE ALARM VULNERABILITY?



DATA
07-23-2001, 02:20 AM
HI,
well i had a fite over irc with a guy who says zone alarm doesnt warn u when u do port scan on upper ports-above 4**00 or so-those private ports not assigned by iana.
more ever if u do random scans he says that the zone alarm doesnt respond.
he also warned me against using zone alarm.
he also says that it doesnt always close the ports which u ask to close through it-but only appears to be closed.
i recommend u do a vanilla port scan if u use zone lab after u close the ports.all these sound like hoaxes to me at *st sight but u should try it out.may be its coz some * is trying to deface zonelabs.
i did a google search on zone labs
and found quiet a few interesting urls-
http://www.fichcast.net/safety/hacks.htm
there r many more sites which say zone alarm is easily breakable.
go ahead and bring the truth out...what ever it is.

Blacksheep
07-23-2001, 11:47 AM
Hi DATA,

I think some crackers are spreading a bunch of crap to sow the seeds of doubt and mistrust because they can't use their zombies/backdoors on ZA machines.

Since when does IANA assign ports? Would be news to me.

http://www.pcwebopaedia.com/TERM/I/IANA.html

ZA machine doesn't respond to remote host attackers (ping/port scans/hits) in stealth mode so attacker will think no computer exists at that IP.

ZA doesn't open ports. The prog you give permission to use Internet or act as a server may open ports. If you get a trojan/zombie/backdoor in your box, some change their names to something nice hoping you will be conned into giving firewall permission. BTW, if you use Eudora email client and don't like Eudora phoning home to ad server, block ad server IP. You won't know about this "phone home" if you're not running a sniffer. If you use proxy you can't block IPs.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Correction 7/27/0* by BS: If you use proxy you can't block IPs with ZA. A4Proxy will block IPs.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
I use ZA Pro. I've got lots of blocked hits, port scans on high ports etc., have scanned myself, and know of no exploits for ZA. If there are any, show me the proof.

There is one trojan, when in your box, that attempts to shut down firewalls and anti-virus but I ain't gonna post it here.

"Where's the beef?"...

[Edited by Blacksheep on 07-28-200* at 0*:06 AM]