Posted on 09-07-2008
Filed Under (General News) by jtrigsby

Microsoft released four patches - all rated important - as part of its regular Patch Tuesday update cycle, one of which left ZoneAlarm users locked out the internet. Tomorrow when my left ear recovers, I\’ll call the MS 866 number (866-PCSAFETY) and see if I can patch the MS problem w/o hosing my internet connection again. 3 hours of ATT tech (hahahaha) support later, after telling them I suspected the update, and that I ran ZA, I finally reached a person who told me about this conflict. The experiences of Reg reader Steve seem typical.

This flaw - along with cross-site scripting vulnerabilities in Outlook for Web Access that affect MS Exchange and information disclosure bugs in SQL Server - are all rated \”important\” by Redmond but \”critical\” by security watchers at the SANS Institute\’s Internet Storm centre. Symptoms: all network software reports you are connected but you\’re NOT. A vnunet. The most significant of the quartet fixes a flaw in Windows\’ implementations of the Domain Name System protocol.

Not sure who is to blame on this one but it has been a pain. ZoneLabs has issued a preliminary advisory detailing workarounds for ZoneAlarm users who have been locked out of their internet connections by Microsoft\’s latest round of bug fixes. \”The XP update dated 7/8/08 does not play well with systems running Zone Alarm. The Explorer vuln potentially creates a means for hackers to inject malware onto vulnerable systems running Windows Vista.

\”I wish I could give you the name of the file, but I uninstalled it, during the process (finally fixed it myself, btw) and told it not to tell me about it again. Microsoft\’s three other patches cover vulnerabilities in Exchange server and SQL Server and, on the desktop, bugs in Windows Explorer. Zone Alarm users locked out of the Internet by Microsoft weekly update. A final resort, which ZoneLabs does not recommend, is reducing the security level of ZoneAlarm to medium for the internet zone.

Successfully exploiting the flaw could allow hackers to spoof DNS replies, creating a means to redirect network traffic or to mount man-in-the-middle attacks. \”I have uninstalled Zone Alarm and everything now works fine. Microsoft locks Zone Alarm users out of the Internet. The first recommended action is to uninstall the hotfix via the Windows \’Add and Remove Programs\’ menu.

com Forum visitor confirmed that removing the Microsoft update solves the problem. ZoneLabs confirmed that the Microsoft patch cripples platforms including ZoneAlarm Free, ZoneAlarm Pro, ZoneAlarm AntiVirus, ZoneAlarm Anti-Spyware and ZoneAlarm Security Suite. POP3 does not connect; web pages do not display. The firm issued three possible solutions for the unknown percentage of the hundreds of thousands of users of its popular ZoneAlarm firewall who have fallen foul of the Patch Tuesday \’fixes\’.

\”Zone Alarm locked out by Microsoft update. \”ZoneAlarm has published a list of recommended workarounds to dealing for the glitch here. Multiple vendors are subject to the DNS-spoofing vulnerability, which stems from a fundamental weakness involving a lack of entropy in DNS queries rather than a specific security bug. mspx).

\”I woke up this morning to no internet at all and on calling my ISP\’s tech support I was told there was an issue with the latest patches and Zone Alarm,\” he reports. Zone Alarm issues work around for Microsoft lock-out.

    Read More | Trackback URL   

Related Posts

New Domain Ymail and Old Domain RocketMail?
I was talking with someone about Yahoo's much-heralded launch of two new email domains, Rocketmail (which is actually an old domain resurrected) and Ymail, and despite much back-and-forth about it, I still couldn't really see the point, and in fact
So What’s All The Hype About the Fisher Space Pen? Isn’t It Just A Pen?
I'm not really sure why the Fisher Space Pen is all the rage on the Internet today because the pen and the story of the pen have been all over the Internet since the INternet started sharing rumors and urban
Finding Coupons is Easy at Coupons.com
In addition to finding online coupon websites, you can also examine the websites of your favorite product manufacturers. 4% of coupon distribution last year but -- thanks to better consumer follow-through than with newspaper coupons -- 2. Weekend newspapers,
Google Hot Trends On Firing Line
(That statement said, "In this case, it appears that the html code for this query was posted on a popular internet bulletin board, which led to quite a few people searching to find out more about this symbol.
Can’t Wait To Land To Check Your Email? Fly JetBlue
You know, I've been "connected" now for almost 14 years. I got my first real email address in 1995 and I've flown millions of miles since then on lots of different airlines and frankly, I've enjoyed the "unconnected" state that
Cerina Vincent in It Waits This Weekend
There is a creature slowly stalking and hunting her. Terror strikes a young woman and her boyfriend when archeology students unwittingly unleash a demon from a cave. Watching a horror movie gives an opening into that scary
Bose Rocks It Again
Advanced control from Bose concert sound systemsInstantly make hundreds of refinements tailored to your specific instruments, mics and vocal range. However, Bose made no move to lower the luxury pricing of the QuietComfort, which is where the Audio-Technica ATH-ANC7
Nikki Catsouras on Primetime Tonight
Catsouras had no idea the next day would be the last time he'd ever see the daughter he called "Angel. What happens to your auto insurance premiums if someone is killed in an accident? Can you still get
Skydiving Grandma Beulah Lewis
In tandem parachuting, two skydivers are attached, and they dive together. Usually the other is an instructor and the "rider" is a novice learning how to skydive. The next thing you know, the earth will be rushing
Think You’re Good Looking? Better Check FaceStat.com First
The age old quest for beauty and the recent advent of the computer have now combined to calculate your facestat number on facestat.com, perhaps a real help toward self esteem improvement. Facestat.com is a web site that sells its services
Post a Comment
Name:
Email:
Website:
Comments: