[Full-Disclosure] Unsecure file permission of ZoneAlarm pro.

From: bipin gautam (visitbipin_at_yahoo.com)
Date: 08/20/04

  • Next message: 3APA3A: "[Full-Disclosure] Fwd: Re: FullDisclosure: Security aspects of time synchronization infrastructure"
    To: full-disclosure@lists.netsys.com
    Date: Thu, 19 Aug 2004 19:50:50 -0700 (PDT)
    
    

    Hello list,

    Zone Alarm stores its config. files in
    %windir%\Internet Logs\* . But strangely,

    ZoneAlarm sets the folder/file permission (NTFS) of
    %windir%\Internet Logs\* to,

    EVERYONE: Full

    after its first started.

    Even If you try to change the permission to...

    Administrator (s): full
    system: full
    users: read and execute
    [these are the default permissions]

    Strangely, the permission again changes back to...
    EVERYONE: Full each time

    ZoneAlarm Pro (ZAP) is started. I've tested these in
    zap 4.x and 5.x

            This could prove harmful if we have a malicious
    program/user running with

    even with a user privilege on the system.

    Well a malicious program could modify those config
    file in a way ZAP will stop

    functioning. This is what ZoneLabs had to say...

    ---snip-------
    >anyone could open any ZoneAlarm file
    > (assuming it isn't locked), edit it with a hexeditor
    and
    > cause it to stop functioning. This type of
    modification
    > wouldn't be classified as an attack, as you have
    simply
    > modified the file and caused it to not function as
    expected.
    > This is true of any executable or other binary.
    >
    ---/snip-------
    yap, true... but shouldn’t ZAP have some protection
    against such attacks? instead

    of leaving the permission to " EVERYONE: Full " I
    wonder if a program could bypass

    ZAP filters using "safePrograms*.xml"
    [...experimenting]

    anyone wanna take this thing to a new level, please go
    on...

    Regards,

    Bipin Gautam
    http://www.geocities.com/visitbipin/

                    
    _______________________________
    Do you Yahoo!?
    Win 1 of 4,000 free domain names from Yahoo! Enter now.
    http://promotions.yahoo.com/goldrush

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: 3APA3A: "[Full-Disclosure] Fwd: Re: FullDisclosure: Security aspects of time synchronization infrastructure"

    Relevant Pages

    • Re: Dead Beef
      ... FORMAT4.DSCB as your target it will ask permission of the operator and if granted, you will have access to the full volume (at which point you can use TTR control cards to get at the needed record to zap). ... For IBM-MAIN subscribe / signoff / archive access instructions, send email to listserv@xxxxxxxxxxx with the message: GET IBM-MAIN INFO Search the archives at http://bama.ua.edu/archives/ibm-main.html. ...
      (bit.listserv.ibm-main)
    • Re: ZAP / WAOL.exe conflict?
      ... > fine EXCEPT the PC locks up when WAOL.exe tries to access the internet - ZAP ... > asks to give permission, ... the pop-up window and to check off that you approve of this program ...
      (comp.security.firewalls)
    • Re: [PATCH 2.6.16-rc1-git4] accessfs: a permission managing filesystem
      ... >> Accessfs is a permission managing filesystem. ... One module allows granting capabilities based ... +individually configure which user/program can bind to protected ports ... +config ACCESS_FS ...
      (Linux-Kernel)
    • Re: [SLE] SUSE Firewall not like ZoneAlarm...
      ... every incoming connection from the net, it asks me for permission. ... How do I know which applications it forbids and which it allows? ... it reminds me very much in the functionality of ZoneAlarm. ... Daniel Bauer photographer Basel Switzerland ...
      (SuSE)
    • Re: [SLE] SUSE Firewall not like ZoneAlarm...
      ... or every incoming connection from the net, it asks me for permission. ... But SUSE Firewall never asks me anything. ... Please note that Linux had a firewall long before there was ever a Zone ... Constructing "ZoneAlarm for Linux"? ...
      (SuSE)