Re: help with SyGate needed

From: curious (heyimjustcurious_at_yahoo.com)
Date: 01/31/04


Date: 31 Jan 2004 08:02:43 -0800


"Jarmo P" <a@nospam.b.invalid> wrote in message news:<bve4r4$3f1$1@phys-news1.kolumbus.fi>...

 <snip>

> A few things.
<snip>
 
> Sygate firewall definately needs to disable 'Act as Server' option for
> Generic Host for Win ... = svchost.exe. It is a security risk !!!
>
> You should do it also to many other programs that popup, except messengers
> and other server rights needing programs that you need for those things.
> Safe is to disable that for all.

> Thing is, SPF gives them server rights by default, so you have to go and
> disable them all afterwards. Manually like I tell you below for svchost:

 <snip>

 Thanks for the instruction.

My problem is to differentiate which ones are the one I need and which
ones are not. Here is application Lists:

.....Internet Explorer\iexplore.exe
.....Messenger\msmsgs.exe: ???This thing likes to boradcast..
.....Microsoft Office\Office10\WINWORD.EXE
.....Spybot – Search & Destroy\SpybotSD.exe

The followings are inside WINNT folder:

..explorer.exe
..hh.exe
..System32\certsrv.exe
..System32\dfssvc.exe
..System32\DNS.EXE
..System32\DRIVERS\ndisuio.exe: I will BLOCK since I have no wireless
..SYSTEM32\dwwin.exe
..System32\inetsrv\inetinfo.exe
..System32\ismserv.exe
..System32\llssrv.exe
..System32\LSASS.EXE
..System32\lserver.exe
..System32\mqsvc.exe
..System32\msdtc.exe
..System32\mstask.exe
..System32\ntfrs.exe
..System32\NTOSKRNL.EXE
..System32\services.exe
..System32\snmp.exe
..System32\svchost.exe; I will disable as you suggested.
..System32\tcpsvcs.exe
..System32\telnet.exe
..System32\termsrv.exe
..System32\Windows Media|Server\NSCM.exe
..System32\Windows Media|Server\NSPMON.exe
..System32\Windows Media|Server\NSUM.exe
..System32\WINS.exe
 
 
> Sygate allows too much, it is a fine firewall, but for a newbie needs some
> configuration.
 
> About them trojan warnings, if you have open ports, the scan tells you about
> them, but no need to worry, they are propably just possible exploits, not
> meaning you have any. The site should have the explanation changed.

I did trojan scaningand it's clean.



Relevant Pages

  • Re: PAE-CE84 Router Failure
    ... >>> I found I was unable to gain access to the internal web ... >>> server to check the router's settings, ... I have easily accessed my *new* router using!FTPc, ...
    (comp.sys.acorn.networking)
  • RE: Dovecot versus Postfix
    ... <SNIP> ... It says "Replace mail.example.com with your mail server ... configure the default gateway and Domain name server as well as the ... user accounts. ...
    (Ubuntu)
  • Hows the serenity! (was Re: Processing Ideas Needed:)
    ... tasks being "stateless" and the ACMS transaction monitor maintaining a fully ... pre-authorized and statefull connection to the client. ... response, but if server and client were cooperating on a row-by-row basis, ... [snip, snip, snip, snap, snip snippety snip] ...
    (comp.os.vms)
  • Brad Pelinis machine...
    ... with many different competing registrars. ... Whois Server: whois.godaddy.com ... Boynton Beach, Florida 33426 ...
    (comp.sys.mac.advocacy)
  • Re: Windows update error 0x8007041D
    ... Sometimes this happens when the server is busy and you could retry later. ... If it continues and as NOD32 is not the case then check in the Event Viewer to ... Mila <snip> ... | After installing SP2 I went to "Windows Update" and it said I needed ...
    (microsoft.public.windowsxp.help_and_support)