Re: Kerio personal firewall 2.1b3 - VXD drivers problem

From: Pat (p_mcq@ZUGZWANGhotmail.com)
Date: 02/10/02


From: Pat <p_mcq@ZUGZWANGhotmail.com>
Date: Sun, 10 Feb 2002 14:46:27 -0800

On Sun, 10 Feb 2002 22:19:01 +0100, Libor Striz <poutnik-x@x-atlas.cz>
wrote:

>Is there a way to set the rules of KPF 2.1b3
>allowing using VXD driver for apps ?
Here is what I found when trying to figure it out myself, you will
have to use regedit or whichever registry editor you prefer and follow
the path to find the value you need to set........

This has been reported in the Kerio Yahoo group you can disable this
feature if you want with this registry entry.

HKLM\System\CurrentControlSet\Services\VxD\fwdrv and set

"KernelModuleAuth" value to 00 00 00 00

(01 00 00 00 is the default if you wish to enable it again)

You need to reboot afterwards

Figured I should give the explanation of why it is checking these VxDs
so you know what you are disabling

said by Stanislav Kolar:

"btw kernel module authentication is new experimental feature
(designed against trojan trying bypass firewall using kernel module).
You can disable it if you have some problem..."