Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Can Zonealarm be hacked ?

Thread Tools
 
Search this Thread
 
Old 27 January 2002, 04:54 PM
  #1  
babber
Scooby Regular
Thread Starter
 
babber's Avatar
 
Join Date: Feb 2001
Posts: 4,370
Likes: 0
Received 0 Likes on 0 Posts
Wink

I keep getting a silly smiling face coming up on my PC by the Zonealarm icon. Anyone know what thats all about ?

I'm sure something is up with my PC, as it so slow over the past few days. Is it possible to open a port without me knowing ? How would I check that out ?

Is it time for a new O/S load?

Cheers Phill C
Old 27 January 2002, 04:56 PM
  #2  
HHxx
Scooby Regular
 
HHxx's Avatar
 
Join Date: Nov 2001
Posts: 2,576
Likes: 0
Received 0 Likes on 0 Posts
Wink

Open up ZA, goto Programs tab and see the application with the Face.
Old 27 January 2002, 05:13 PM
  #3  
babber
Scooby Regular
Thread Starter
 
babber's Avatar
 
Join Date: Feb 2001
Posts: 4,370
Likes: 0
Received 0 Likes on 0 Posts
Angry

Looked nothing there

Cheers Phill C
Old 27 January 2002, 05:27 PM
  #4  
106rallye
Scooby Regular
 
106rallye's Avatar
 
Join Date: Aug 2001
Posts: 722
Likes: 0
Received 0 Likes on 0 Posts
Post

Are you sure its not adsubtract? that looks a bit like a smily face. It has been given away with zone alarm pro recently I think?
Have a look here http://www.adsubtract.com
Cheers

Andy
Old 27 January 2002, 06:04 PM
  #5  
babber
Scooby Regular
Thread Starter
 
babber's Avatar
 
Join Date: Feb 2001
Posts: 4,370
Likes: 0
Received 0 Likes on 0 Posts
Wink

Was it part of the Zonealarm pro install file ?

I'll have a look once I get home.

Cheers Phill C
Old 27 January 2002, 06:06 PM
  #6  
jbryant
Scooby Regular
 
jbryant's Avatar
 
Join Date: Feb 2000
Posts: 1,082
Likes: 0
Received 0 Likes on 0 Posts
Post

If it's on your systray, then double click on the icon to bring up ZoneAlarm, and then look on Alerts tab. You'll probably see that ZoneAlarm has prevented someone from accessing your PC (Message along the lines of 'ZoneAlarm has prevented *** type of access from **.**.**.** IP address')

Sounds as though it may just be doing its job. Main thing to be wary of is when an application asks for server access. Make sure you trust the software and that you want this app to have incoming AND outgoing access to the net before agreeing. Otherwise if it is a trojan then you're letting it have access to your PC.

Joolz
Old 27 January 2002, 09:24 PM
  #7  
babber
Scooby Regular
Thread Starter
 
babber's Avatar
 
Join Date: Feb 2001
Posts: 4,370
Likes: 0
Received 0 Likes on 0 Posts
Post

Something else I've noticed over the past few days is when Zonealarm stops Explorer connecting to the internet, it was reporting a 127.0.0.1 IP, which is TCP IP Stack isn't it ?

Just done it again and it was a 192.168.x.x IP address, my router. What the **** ????

I really worried, what should I do.

Cheers Phill C

PS No meation of that other program in zone alarm.
Old 27 January 2002, 09:30 PM
  #8  
babber
Scooby Regular
Thread Starter
 
babber's Avatar
 
Join Date: Feb 2001
Posts: 4,370
Likes: 0
Received 0 Likes on 0 Posts
Wink

An how would I know I had a trojan, Norton (updated 23/1) said system is fine.

Should I scan my ports ?

Cheers Phill C

PS Will try grc.com
Old 27 January 2002, 09:38 PM
  #9  
mega_stream
Scooby Regular
 
mega_stream's Avatar
 
Join Date: May 2001
Location: Scotland
Posts: 4,580
Likes: 0
Received 0 Likes on 0 Posts
Question

What OS r u running
Old 27 January 2002, 09:42 PM
  #10  
babber
Scooby Regular
Thread Starter
 
babber's Avatar
 
Join Date: Feb 2001
Posts: 4,370
Likes: 0
Received 0 Likes on 0 Posts
Wink

98SE

Just been chatting to my mate about Linux, might give it a try Pissed off with windows!!!

Cheers Phill C
Old 27 January 2002, 09:53 PM
  #11  
babber
Scooby Regular
Thread Starter
 
babber's Avatar
 
Join Date: Feb 2001
Posts: 4,370
Likes: 0
Received 0 Likes on 0 Posts
Wink

Forgot to say when the 127.0.0.1 IP address was shown, it always used a differnt port to the last time!!!Started at 10?? and went up by one each time I connected

And what is all this Qmanager and update ****e all about ??

Getting really drama'ed up now

Cheers Phill C

PD edited cause I have my thorn goggles on and am ranting



[Edited by babber - 1/27/2002 10:04:41 PM]
Old 27 January 2002, 10:34 PM
  #12  
stevem2k
Scooby Regular
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Post

127.0.0.1 is loopback, so no stress there :-)

Bin the zonealarm and get a proper firewall, especially if you have a 24/7 connection ( cable/dsl ).

Qmanager is M$ guff that reports when Internet Exploder crashes, Update is critical update notification, both from the Beast of Redmond(tm).

Steve

[Edited by stevem2k - 1/27/2002 10:36:28 PM]
Old 27 January 2002, 10:41 PM
  #13  
babber
Scooby Regular
Thread Starter
 
babber's Avatar
 
Join Date: Feb 2001
Posts: 4,370
Likes: 0
Received 0 Likes on 0 Posts
Wink

Yes a Unix firewall is what I need I think, got a router with so say firewall protection.... Not that great. Saw a site somewhere that gave away a OS that booted from a floppy, on something like a pentium 133, two network cards, that was it, great. Sure you telnet into the box

But why do a IP stack loopback one minute then connect through the router IP the next

Cheers Phill C

PS at the end of the day a major ISP can get it's server hacked, so not surprised mine has been.
Old 27 January 2002, 10:48 PM
  #14  
stevem2k
Scooby Regular
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Post

got a spare bunch of crap bits floating about ? www.smoothwall.org. It's the dogs.

Nice interface, stable 2.2 kernel, IDS, built in squid proxy, even VPN's. Running in 30mins.

Don't worry about hacking attempts, I get somewhere between 20 and 100 real attempts per day.

Steve



[Edited by stevem2k - 1/27/2002 10:50:06 PM]
Old 27 January 2002, 10:50 PM
  #15  
babber
Scooby Regular
Thread Starter
 
babber's Avatar
 
Join Date: Feb 2001
Posts: 4,370
Likes: 0
Received 0 Likes on 0 Posts
Wink

stevem2k,

Fair play you've lost me. I'll take a look, thanks mate

Cheers Phill C
Old 27 January 2002, 10:54 PM
  #16  
babber
Scooby Regular
Thread Starter
 
babber's Avatar
 
Join Date: Feb 2001
Posts: 4,370
Likes: 0
Received 0 Likes on 0 Posts
Thumbs down

I always get ICMP ping requests and other scans / attempts on a daily basis, just that the little smiling face is getting on my ****.... I can't capture the picture and post, as it isn't there at the moment.

Another thing is I'm testing another type CM for a Broadband operator, and could do without this ****....

Cheers Phill C


Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
BigGT3Fan
Computer & Technology Related
4
14 March 2002 11:11 AM
BigGT3Fan
Non Scooby Related
8
06 September 2001 08:25 PM
davefromevonet
Non Scooby Related
5
10 April 2001 11:04 AM
whizzer
Non Scooby Related
12
08 November 2000 08:09 AM



Quick Reply: Can Zonealarm be hacked ?



All times are GMT +1. The time now is 04:18 AM.