Search:  

 
 
   News
newer
story category DNS Fix Knocks Zone Alarm Users Offline
New Zone Alarm patch should cure what ails you...
(old news - 08:37AM Thursday Jul 10 2008)
tags: security · trouble · software
Tipped by winchester73 See Profile
Users of the Zone Alarm firewall this week experienced an unexpected surprise when they installed the latest Microsoft OS patch and subsequently lost connectivity to the Internet. According to posts in our security forum, KB951748 (a DNS design flaw fix I referenced yesterday) randomizes the source port for udp queries, while the firewall continued to expect DNS queries only from one udp port. Zone Alarm has subsequently fixed the problem, with the latest updates for all versions available here.

Related:
  1. Monday Morning Links
  2. Monday Morning Links
  3. Friday Evening Links
  4. Wednesday Evening Links
  5. Firefox Add-On Simulates Great Firewall Of China
  6. Zone Alarm Pro Free Just For Today
  7. Microsoft Discontinuing OneCare
  8. Using PS3's To Forge Site Certificates
Forums » DNS Fix Knocks Zone Alarm Users Offline
view: topics flat text 
Post a:

Matt
You can't fix stupid
Premium
join:2003-07-20
Jamestown, NC

People still use this?

People still use ZA? Wow. The early versions were great, but it quickly became bloated, and like the Norton/Symantec products, caused more problems than it prevented.
zenafu

join:2007-06-12
Brooklyn, NY

Re: People still use this?

I was surprised too, 'people still use this app?' I said outloud just now. But apparently, yep. I used to use it back when I was on Win '98 and it was light and very effective but from what I hear it's pretty bloated now.
Madtown

join:2008-04-26
Madera, CA

Re: People still use this?

I used ZA up until Tuesday afternoon, well last night I decided to switch over to Comodo and try that out for a while.

joe123com

@in-addr.arpa

Re: People still use this?

Free version is not bloated. Works fine. Microsoft is the problem. Get linux. Industrial strength firewall, easy easy to configure - most DSL transceivers (modems) have this firewall installed (IP Tables). Tivo works real good too, right? Linux inside!!
VerizonCynic

join:2006-10-25
Lakewood, CA
works fine for me. free version only. the patch worked fine

spewak
Kiss It, Kiss It Real Good
Premium
join:2001-08-07
Elk Grove, CA
·SureWest Internet
·FrontierNet Intern..

Well, yes. I do anyhow. It did prevent me from getting online until I turned off the firewall and was able to go to the website and promptly download the updated version.
Familiarity breeds contempt I guess.
--
The weekend is here, grab a can of beer!
voipdabbler

join:2006-04-27
Kalispell, MT

LOL, yes. I run 2 software-based firewalls (one is ZA), plus the router and a good anti-virus program that is set to scan my full system daily. You can never be too careful using the Internet. View it as a big door to a room containing your most valuable possessions. Put good locks + multiple deadbolts on it. Then keep in mind that you're still not safe.

KaziSmith
Premium
join:2001-06-29
Dallas, TX

Re: People still use this?

Well, using your analogy, you can put as many deadbolts as you like on a "door" but the lock is only as good as the frame and door holding the two in place. The door/frame can fail with the lock being in perfect condition.

But as you stated,

said by voipdabbler See Profile :

Then keep in mind that you're still not safe.
B
Premium,MVM
join:2000-10-28

The early versions are STILL great. I continue to use ZoneAlarm Free 2.6.362 all day, every day, on multiple XP computers. Never a problem. Different software, service packs, different VPNs, sleeping laptops, roaming networks; it just works.

-- B
--
In a realm outside causality and function

Cudni
La Merma - La Guerrilla
Premium,MVM
join:2003-12-20
Someshire
·BTOpenworld

Zone Alarm has subsequently fixed the problem

and yet looking at thread, the carnage continues with people removing the MS update, removing ZA, reducing security in ZA

Cudni
--
"Mercifully, he hit him with the soft end of the pistol."
Help yourself so God can help you.
Microsoft MVP, 2006 - 2008

moopenguin32

join:2003-11-02
Raleigh, NC

No problems aside from this

I've been using it for about a month with no problems (aside from this which was quickly fixed). I tried Comodo, but it would prompt me for the silliest things, like saving a file from Firefox or IE.

Aside from this issue, I never experienced any problems nor has it slowed down my system.

evilghost
Premium
join:2003-11-22
Springville, AL

edit:
July 10th, @11:15AM

Update the rule?

If the issue is caused by DNS source-port randomization why not simply create a rule to allow egress UDP with SRC PORT 'any' to UDP dport 53, or is ZA so luser friendly that this cannot be done?

DataDoc
Waiting for Godot
Premium
join:2000-05-14
Greenville, NC

Re: Update the rule?

95% of users don't know what you just said.
ebubman

join:2002-01-17
Enola, PA
·Vonage
·Comcast

Re: Update the rule?

said by DataDoc See Profile :

95% of users don't know what you just said.
LOL. agree. have been a computer user since way back in the days of the prototypical ibm pc xt & at & i don't have a clue what he/she said.......bub

XBL2009
------

join:2001-01-03
Chicago, IL
·AT&T Midwest

said by evilghost See Profile :

If the issue is caused by DNS source-port randomization why not simply create a rule to allow egress UDP with SRC PORT 'any' to UDP dport 53, or is ZA so luser friendly that this cannot be done?
That can be done quite easily.

caffeinator
Coming soon to a cup near you..
Premium
join:2005-01-16
Spokane, WA
·WebBand


edit:
July 11th, @06:37AM

Yup, I've had that nearly that same rule for my 8signs for a long time now. Both Windows (XPpro, win2k) boxes use it, and the rest are Linux and don't need it.

I updated using the MS patch, and thanks to 8signs and some common sense..everything is just peachy.

I liked ZA back in v. 2.6 I think it was..then I learned how to use rules-based FW's and never looked back.

Simple is good.

beatsnpieces

join:2007-12-17

A pain in the arse!

We got flooded with calls here at the Cogeco Cable call centre yesterday due to this. Seems everyone with ZoneAlarm was affected but changing the security level slider to medium fixed it for everyone I spoke to. I'm glad to hear they got a patch out already.
--
2.66 Core2 Quad | Asus P5W-DH Deluxe | Creative X-Fi Xtreme Gamer | BFGTech GeForce 8800Ultra 768 | 2GB Corsair 800Mhz DDR2 | ThermalTake Tough Power 850W | ThermalTake V1 'Butterfly' Heatpipe | ThermalTake Tsunami chassis | 150GB WD Raptor X |
gower2352

join:2005-06-08
Weston, WV

zone alarm free rocks

Every computer that I have put Zone Alarm on has ran great with no problems. I do wish the updates weren't so big as they were never as big as they are now. They used to be like 10-15 MB and now they are like 45 mb.

Anonymous1

@tdbank.ca

Zonealarm works fine.

It bugged up because it noticed some windows files didn't pass crc check anymore (which is probably good, because if it wasn't MS that did it, it would of meant they were compromised).

They released a fix withing 36 hours, thats not too shabby.

I'll keep using Zonealarm.
demoniacs

join:2007-07-17


edit:
July 10th, @07:03PM

OMG

i put the blame on those jokers who wants to destroy the world by their programs/softwares or whatever the hell they use that we still need to buy AV and FW (or atleast download those to be safe).

great work jokers.
--
Study hard. Play harder. Girls hardest!
rhexis

join:2002-05-18
Gilbertsville, PA

za

zone alarm is worthless and all it does is slow down your box.
Forums » DNS Fix Knocks Zone Alarm Users Offline


Friday, 09-Jan 01:28:46 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2009 dslreports.com.