Rocky Posted July 9, 2008 Share Posted July 9, 2008 Anyone heard this week about Windows Security Updates preventing net access? I've had to uninstall two updates from today, KB951376 and KB951748 in order to get back online. Anyone shed any light on this? Found it. blinking idiots MS. Microsoft DNS patch KB951748 incompatible with Zonealarm Quote Link to comment Share on other sites More sharing options...
Dannik Posted July 9, 2008 Share Posted July 9, 2008 One of the new security patches fixes a DNS exploit. It also makes Zone Alarm break. If you have Zone Alarm installed, set it's security to Medium for the internet zone, switch firewall applications, or uninstall MS08-037 (KB951748). I don't know if Zone Alarm is the only culprit, but it's the most widely reported one. The error is also, for the sake of clarity, at Check Point's end, not Microsoft. Quote Link to comment Share on other sites More sharing options...
Papa6 Posted July 9, 2008 Share Posted July 9, 2008 my next system might be a mac notebook. Quote Link to comment Share on other sites More sharing options...
McGhost Posted July 9, 2008 Share Posted July 9, 2008 my next system might be a mac notebook. lolololololololololol Quote Link to comment Share on other sites More sharing options...
Dannik Posted July 9, 2008 Share Posted July 9, 2008 Again, I'm compelled to point out that this isn't a problem with Microsoft. They pushed out a critical patch; hundreds of software vendors are doing the same. The problem here is Zone Alarm was poorly coded, and hasn't been patched yet. Quote Link to comment Share on other sites More sharing options...
Rocky Posted July 10, 2008 Author Share Posted July 10, 2008 I assumed, incorrectly it seems, that before pushing out updates MS checked them on systems running the latest versions of popular apps. Kind of surprised they don't appear to do that. Quote Link to comment Share on other sites More sharing options...
Dannik Posted July 10, 2008 Share Posted July 10, 2008 This was a huge critical flaw in every single DNS-using device across the world. I can forgive a company if they rush to prevent every single install of their operating systems from becoming a massive botnet, instead of taking their time to test literally millions of possible app combinations. Quote Link to comment Share on other sites More sharing options...
Rocky Posted July 10, 2008 Author Share Posted July 10, 2008 They certainly achieved the objective of preventing botnet overload. Quote Link to comment Share on other sites More sharing options...
Dannik Posted July 10, 2008 Share Posted July 10, 2008 Hey, at least they're trying! And yes, double entendre in full effect. Quote Link to comment Share on other sites More sharing options...
Dai-San Posted July 10, 2008 Share Posted July 10, 2008 (edited) I must admit, the industry respons to this DNS flaw has been quite well organised and pretty fast considering the scope of the problem. One thing I do find strange is why people are still using apps like Zonealarm. All ADSL Routers in the last god knows how many years have included Hardware NAT firewalls and this coupled with an average AV is enough to stop any infection if you follow the sensible rules of, If i aint expecting it, then I aint opening it Edited July 10, 2008 by Dai-San Quote Link to comment Share on other sites More sharing options...
Dannik Posted July 10, 2008 Share Posted July 10, 2008 There's one solid reason to use a stately software firewall even when you have a good NAT setup: Outbound. NAT protects from inbound attack vectors, but does nothing to protect against malware that may have stuck onto your system through apparently otherwise legitimate means. Quote Link to comment Share on other sites More sharing options...
Rocky Posted July 10, 2008 Author Share Posted July 10, 2008 One thing I do find strange is why people are still using apps like Zonealarm. All ADSL Routers.... Not everyone uses a router therefore a software firewall is required. Quote Link to comment Share on other sites More sharing options...
Dannik Posted July 11, 2008 Share Posted July 11, 2008 True. I have ADSL, and the only hardware provided was an ethernet/USB modem. Instead of purchasing a router, I simply use a hub (and really should get a switch instead) and all the computers on the network lease their own public IP, as my ISP lets me have up to five IPs leased at a given time. Thus, software firewalls on all boxes that need it. Even my Wii is software firewalled. Quote Link to comment Share on other sites More sharing options...
Tinker Posted July 11, 2008 Share Posted July 11, 2008 One thing I do find strange is why people are still using apps like Zonealarm. All ADSL Routers.... Not everyone uses a router therefore a software firewall is required. True, but I would always rely on my hardware now, rather than outside software. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.