f



Security problems in F-Secure Client Security?

Hello,

as I have been testing F-Secure Policy Manager/Console (PM) and F-Secure 
Client Security (CS) I have found three very serious problems:

In all cases the system envirionment has always been the same,
Windows 2000 with latest service pack und latest fixes.

A:
F-Secure's Policy Manager 5.61 and Client Security 5.54 can't 
communicate together as CS doesn't find the management server anymore 
after installation :(
This worked better with CS 5.50 and 5.52.

B:
The internet shield of CS can be bypassed, even when policy has been 
instructed to deny automatically and to forbid the client to use 
individual settings.
Imagine that in a sensitive production environment, a real horror :(

C:
Under certain circumstances clients cannot scan for viruses anymore
if the logged in user doesn't belong to the adminnistrator group.

My question to you all is:
Did you find same or similar problems, and if yes, did F-Secure agree 
that these are problems which may cause damage and whether you got any 
final solution from F-Secure?

I have sent several notes and diags to them, well I can say support has 
tried to help, but there didn't come any real solution.

Well, would be fine to get all your helpful feedback.

Michael
0
10/28/2004 1:32:16 PM
comp.security.firewalls 10672 articles. 0 followers. dfinc1988 (97) is leader. Post Follow

0 Replies
985 Views

Similar Articles

[PageSpeed] 22

Reply:

Similar Artilces:

How secure is the security from my security form?
Hey, I have a question about how secure the following will be.... I want to have a login form that posts to itself, so when it loads it checks if there is a username and password on the query list. If there is not, it asks for one. If there is, it checks to see if the information is valid. If it is not valid, it deletes the attributes and calls itself again. If it is valid it sets a particular session variable to be some value and redirects to the next page. Every page from there on in will check to see if the session variable is set and if not will redirect back to the login page. Are ...

Security
I've been doing some investigation into a little problem with privileges. And this is what I have found. If you want to access an Informix database via ODBC and your normal login and password are restricted then set up your odbc connection with no user name and password and you can do anything. This is what I did to prove it. 1. I created a new database called security. 2. I added two tables - opentab and securetab 3. I revoked all permissions on securetab from public 4. I granted connect to public. 5. From MS-Access I set up a new database 6. I used "link-tables" to add a new odbc connection with no username or password, and to link both tables. 7. I could SELECT, INSERT, UPDATE, and DELETE from both tables. 8. I then deleted both tables from my access database. and used control panel to remove the odbc connection. 9. I then repeated steps 5-7 but with a valid username and password. 10. I couldn't access the securetab. So, using a username and password is secure but not using a username and password gives full access. Can anybody spot anything wrong in my reasoning? BTW I have done this on IDS 9.4, running on AIX 5.2, and I was running Windows XP with MS-Access 2002 SP3, and Informix-Client SDK version 2.81 regards Malcolm mweallans@panacea.co.uk wrote: > I've been doing some investigation into a little problem with > privileges. And this is what I have found. > > If you want to acces...

Secure your digital information assets with Secure Auditor. Secure Windows with Secure Auditor
hey guys If you want to identify vulnerabilities in your windows than try this new tool Secure Auditor. It does Windows scanning, auditing, password cracking, event log viewing, port scanning, Windows hardware and software inventory management etc. Download this link and make your system hacking proof. http://www.download.com/Secure-Auditor/3000-2653-10826743.html?part=dl-SecureAud&subj=uo&tag=button Just install it and see the magic. No security hole and no false positive. By the way it also audit Oracle database, MSSQL databases and Cisco Routers. ...

Secure your digital information assets with Secure Auditor Secure Windows with Secure Auditor
hey guys! If you want to identify vulnerabilities in your windows than try this new tool Secure Auditor. It does Windows scanning, auditing, password cracking, event log viewing, port scanning, Windows hardware and software inventory management etc. Download this link and make your system hacking proof. http://www.download.com/Secure-Auditor/3000-2653-10826743.html?part=dl-SecureAud&subj=uo&tag=button Just install it and see the magic. No security hole and no false positive. By the way it also audit Oracle database, MSSQL databases and Cisco Routers. ...

Security programs 2005 - , Firewall programs 2005 -, Antivirus programs 2005 -, APPDEV DOT NET SECURITY, Linux Security and Firewall programs 2005 -, CiscoWorks ( CW ) Security programs 2005
Security programs 2005 - , Firewall programs 2005 -, Antivirus programs 2005 -, APPDEV DOT NET SECURITY, Linux Security and Firewall programs 2005 -, CiscoWorks ( CW ) Security programs 2005 - , ---------------------------------------------------------------------------- Security programs 2005 - Utimaco SafeGuard Advanced Security v4.30.0.335 Multi CD NR 17 543 Utimaco SafeGuard Advanced Security v4.30.0.335 Terminal Server Base Module Multi CD NR 17 544 Utimaco SafeGuard Advanced Security v4.30.0.335 Terminal Server Multi CD NR 17 545 Symantec Norton Internet Security 2005 CD NR 17 234 Symantec Client Security Corporate Edition v2.0 CD NR 15 321 Symantec Mail Security for Microsoft Exchange 4.0 CD NR 13 364 Steganos Internet Security 7 CD NR 16 968 McAfee Internet Security Suite V7.0 2005 CD NR 16 727 Security Service (c) McAfee CD NR 11 362 Symantec Norton Internet Security v3.0 For Mac OSX CD NR 12 698 Microsoft Windows XP SP2, With Advanced Security Technologies. CD NR 16 244 PANDA PLATINUM INTERNET SECURITY V8.05 SUB100 CD NR 16 096 Panda Platinum Internet SEcurity *Englsih-Spanish* 14 184 IBM Tivoli Security Manager v5.1 (c) IBM CD NR 15 750 Finjan Vital Securit...

Security programs 2005 - , Firewall programs 2005 -, Antivirus programs 2005 -, APPDEV DOT NET SECURITY, Linux Security and Firewall programs 2005 -, CiscoWorks ( CW ) Security programs 2005
Security programs 2005 - , Firewall programs 2005 -, Antivirus programs 2005 -, APPDEV DOT NET SECURITY, Linux Security and Firewall programs 2005 -, CiscoWorks ( CW ) Security programs 2005 - , ---------------------------------------------------------------------------- Security programs 2005 - Utimaco SafeGuard Advanced Security v4.30.0.335 Multi CD NR 17 543 Utimaco SafeGuard Advanced Security v4.30.0.335 Terminal Server Base Module Multi CD NR 17 544 Utimaco SafeGuard Advanced Security v4.30.0.335 Terminal Server Multi CD NR 17 545 Symantec Norton Internet Security 2005 CD NR 17 234 Symantec Client Security Corporate Edition v2.0 CD NR 15 321 Symantec Mail Security for Microsoft Exchange 4.0 CD NR 13 364 Steganos Internet Security 7 CD NR 16 968 McAfee Internet Security Suite V7.0 2005 CD NR 16 727 Security Service (c) McAfee CD NR 11 362 Symantec Norton Internet Security v3.0 For Mac OSX CD NR 12 698 Microsoft Windows XP SP2, With Advanced Security Technologies. CD NR 16 244 PANDA PLATINUM INTERNET SECURITY V8.05 SUB100 CD NR 16 096 Panda Platinum Internet SEcurity *Englsih-Spanish* 14 184 IBM Tivoli Security Manager v5.1 (c) IBM CD NR 15 750 Finjan Vital Securit...

Security programs 2005 - , Firewall programs 2005 -, Antivirus programs 2005 -, APPDEV DOT NET SECURITY, Linux Security and Firewall programs 2005 -, CiscoWorks ( CW ) Security programs 2005
Security programs 2005 - , Firewall programs 2005 -, Antivirus programs 2005 -, APPDEV DOT NET SECURITY, Linux Security and Firewall programs 2005 -, CiscoWorks ( CW ) Security programs 2005 - , ---------------------------------------------------------------------------- Security programs 2005 - Utimaco SafeGuard Advanced Security v4.30.0.335 Multi CD NR 17 543 Utimaco SafeGuard Advanced Security v4.30.0.335 Terminal Server Base Module Multi CD NR 17 544 Utimaco SafeGuard Advanced Security v4.30.0.335 ...

pgp programs 2005 -, Security programs 2005
pgp programs 2005 -, Security programs 2005 - , Firewall programs 2005 -, Antivirus programs 2005 -, APPDEV DOT NET SECURITY, Linux Security and Firewall programs 2005 -, CiscoWorks ( CW ) Security programs 2005 - , ---------------------------------------------------------------------------- pgp programs 2005 - PGP.CommandLine.for.Linux.v8.5.0 PGP.CommandLine.for.Solaris.v8.5.0 PGP.CommandLine.v8.5.0 (week 31/2004) PGP.Desktop.v8.1.for.Windows PGP.Personal.Desktop.v8.1.for.Macintosh (week 26/2004) PGP.Enterprise.v8.0.3 (week 49/20030 PGP.v8.0.3 (week 42/2003) 15/...

pgp programs 2005 -, Security programs 2005
pgp programs 2005 -, Security programs 2005 - , Firewall programs 2005 -, Antivirus programs 2005 -, APPDEV DOT NET SECURITY, Linux Security and Firewall programs 2005 -, CiscoWorks ( CW ) Security programs 2005 - , ---------------------------------------------------------------------------- pgp programs 2005 - PGP.CommandLine.for.Linux.v8.5.0 PGP.CommandLine.for.Solaris.v8.5.0 PGP.CommandLine.v8.5.0 (week 31/2004) PGP.Desktop.v8.1.for.Windows PGP.Personal.Desktop.v8.1.for.Macintosh (week 26/2004) PGP.Enterprise.v8.0.3 (week 49/20030 PGP.v8.0.3 (week 42/2003) 15/...

Security Wizard but Not Secure
Hello people. I have a database that: * was not secured originally * I applied the user-level security wizard to * has the Admin user demoted to the Users group * had the User's group with no permissions * the Admin user doesn't own any objects When I open this with my shortcut and new mdw file everything works as expected. When I open this with standard Access security.mdw, my database is still wide open. Any ideas what step I missed? Thanks <drink.the.koolaid@gmail.com> wrote in message news:1147781112.258494.175040@i39g2000cwa.googlegroups.com... > Hello people. >...

XP networking problem after uninstalling F-Secure Internet Security 2006 suite
Hello all Have a problem - after uninstalling F-Secure Internet Security 2006 I lost connection to the Internet. The ADSL connection comes up and everything seems ok but I cannot access the web (modem, cable etc are fine - checked with another computer). I can ping arbitrary IP but the same, given an address won't work. Modem shows no activity when ping is supposed to send query to DNS. Web browsing is also impossible, no matter if I use address or IP (modem shows no activity when trying this). And it makes no difference whether XP's firewall is swiched on or off. What coul...

a XP networking problem after uninstalling F-Secure Internet Security 2006 suite
Hello all Have a problem - after uninstalling F-Secure Internet Security 2006 I lost connection to the Internet. The ADSL connection comes up and everything seems ok but I cannot access the web (modem, cable etc are fine - checked with another computer). I can ping arbitrary IP but the same, given an address won't work. Modem shows no activity when ping is supposed to send query to DNS. Web browsing is also impossible, no matter if I use address or IP (modem shows no activity when trying this). And it makes no difference whether XP's firewall is swiched on or off. W...

Secure Auditor new release and Secure your database with Secure Auditor #2
Hi guys, Oracle DBA's life could become easier with the help of a new tool named Secure Auditor which is capable of performing enumeration, audit, penetration test and forensics on Oracle databases. It is the most cost effective tool in its domain as it includes 30 additional tools like Oracle event log viewer, Oracle access rights auditor, Oracle password Auditor, Oracle default password auditor, Oracle Sid tester, Oracle TNS password tester. Go and get your free copy from http://www.download.com/Secure-Auditor/3000-2653-10826743.html?part=dl-SecureAud&subj=uo&tag=button so you can start experiencing Secure Auditor right away! ...

Excellent website for IT Security (Security+)
Great website for IT Security Certification, http://certdream.googlepages.com Good luck. ...

Secure Auditor secure your windows
Hi folks, Go and get a copy of Secure Auditor which is a unified digital risk management solution and provides 30 tools in 1 package. It performs scan and audit on your windows based machine so that you will be able to identify the weakest link in your network. It helps in compliance, penetration test and forensics as well. So get passwords of every windows and Oracle machine on your network within seconds. Asset management, MSSQL audit, Oracle audit and more than all Cisco Router audit is handy with Secure Auditor. Just check out the link http://www.download.com/Secure-Auditor/3000-2653-1082...

security consultant breaks security ..
"John Schiefer .. admitted that he gained access without authorisation to hundreds of thousands of computers .. and that he remotely controlled these compromised machines through computer servers" "The malware .. would access private communications .. Schiefer and others would then use those communications to find out a users=92 account name(s), or usernames, and that user=92s password(s)" "Schiefer would then access accounts and make purchases unbeknowst to the true owner. Schiefer also admitted to giving those usernames and passwords to others" http://blogs.z...

Secure DNS actually is not so secure.
Dear all; I think all the secure DNS documents should make it explicite that secure DNS actually is not so secure. That is, if a zone shared by a client and a server (e.g. the root zone) is compromized, secure DNS is also compromized. You might think that CAs are much more secure than ISPs. But it is not. Thus, it is equally likely that some ISP between a server and a client is compromized ant some CA between a server and a client is compromized. It should be noted that, if secure DNS is relied upon for monetary transactions that its certificate has authority to perform $...

How to secure yourself from the Central Security Service
Hi: Here is how to secure yourself against the evil Central Security Service: 1. Make sure your computer does NOT have any NVRAM 2. Make sure your MAC addy is dynamic 3. Access the internet via a publicly-available wireless access point -- such as an internet cafe 4. Use a very powerful and sensitive wireless transmitter/receiver for the internet so that you can use the access point from at least 1/4 mile away. Now run along and have fun on the net w/out oppression from the worthless POS Central Security Service dirtbags. Best of luck GreenXenon wrote > Here...

system security or job security?
Dear Listers, Recently I had an interesting discussion with a SAS admin about the way to submit sas job on unix server and was told that submitting SAS job on unix server through ssh would lead to the security issue. So the only way that he allows users to submit SAS job on unix is through Eguide from local PC, which I am not fond of. My question is if his claim about security issue is correct or not. I am somewhat lost, since this is the first time that I am aware of this "security" issue after using SAS on unix through ssh for years. Any insight or comment? Thank you so much! -- ==...

[News] F/OSS Security Applications and the Linux Security Advantage
10 Free OSS Security Applications That You Can Trust ,----[ Quote ] | Many users of open source software point to the fact that their applications | and platforms are more secure than proprietary alternatives simply because | they aren't such obvious targets for malware distribution. As just one | example, the Standish Group recently completed a survey in which 70 percent | of respondents said Red Hat Linux is less vulnerable to security threats than | Windows. Still, it's good to protect yourself with top-notch security | applications, and LinuxPlanet has an excellent list of 7...

Best SAP Security Online Training | Online SAP Security Training | Training SAP Security Online
Biginfosys is a best online training Institute for SAP Security Online Trai= ning. We are providing Exclusive SAP Security Online Training our Faculty f= rom Top MNC's with highly skilled and certified domain expertise, will trai= n and guide you each and every topic related in SAP Security with Real Time= Applications. We are providing exclusive SAP FICO training materials Some of SAP Security topics Covered by our professional Trainers: * What is Security & Why? * Security audit & consideration? * Security layers 1. Data layer 2. Access security 3. Operat...

Eudora stops downloading mail becase of F-Secure Internet Security
Hi All, my Eudora (6.2.5.6 - sponsored mode) has stopped downloading mail since I installed the F-Secure Internet Security 2006 package. When donloading, the program stays for a while at "Logging into POP Server". There is no visible traffic. The following two error messages come up: "<...>, Logging into POP server, CAPA [..:.:.. :M] SSL negotiation failed. Certificate bad. Destination host does not match host name in certificate. But ignoring this Certificate because Certificate ist trusted. Cause: (1814)" "<...>,Logging into POP Server,CAPA ..:..:.. ..M] Error reading from network. Cause: Connection aborted due to timeout or other failure (10053)" This happenes to all personalities I tried. The personalities worked before, when using Symantec Internet Security (wich was removed before f-Secure got installed) For a quick trial I deinstalled F-Secure and tried Eudora. It worked fine (except of the missing protection of course). Then I installed F-Secure again and the problem came up again. Sending of mail is ok - no problem at all. What can I do to solve the problem? With best regards from Osnabrueck, Uwe -- Sachkunde kann eine lebhafte Diskussion nur behindern Uwe Stoeckel <my_mail@gmx.com> wrote: > my Eudora (6.2.5.6 - sponsored mode) has stopped downloading mail > since I installed the F-Secure Internet Security 2006 package. > When donloading, the pr...

US-AL-Huntsville: SAP Security Admin, SAP R/3 Security, BW Security; C-P (45285332409)
US-AL-Huntsville: SAP Security Admin, SAP R/3 Security, BW Security; C-P (45285332409) ====================================================================================== Position: SAP Security Admin Reference: SMC01136 Location: Huntsville AL Duration: C-P 7+yrs of related experience including detailed knowledge of SAP R/3 Security. Experience with design, development, testing, implementation and on-going maintenance of MIS security systems. SAP R/3 & BW Security Please send your current resume in ...

US-AL-Huntsville: SAP Security Admin, SAP R/3 Security, BW Security; C-P (45285032409)
US-AL-Huntsville: SAP Security Admin, SAP R/3 Security, BW Security; C-P (45285032409) ====================================================================================== Position: SAP Security Admin Reference: SMC01136 Location: Huntsville AL Duration: C-P 7+yrs of related experience including detailed knowledge of SAP R/3 Security. Experience with design, development, testing, implementation and on-going maintenance of MIS security systems. SAP R/3 & BW Security Please send your current resume in confidence to <staffing@eurosoft-inc.com> ..45285032409. ...

Web resources about - Security problems in F-Secure Client Security? - comp.security.firewalls

Krebs on Security
The House Financial Services Committee is slated to hold a hearing this Friday on the impact of cyber heists against small- to mid-sized businesses. ...

Security Middle East - Latest news from the Middle East.
Security Middle East is a news portal for the entire security industry, focussed specifically on latest security news from the Middle East. Security ...

Information Security News, IT Security News & Expert Insights: SecurityWeek.Com
IT Security News and Information Security News, Cyber Security, Network Security, Enterprise Security Threats, Cybercrime News and more. Information ...

Security (finance) - Wikipedia, the free encyclopedia
equity securities, e.g., common stocks ; and, The company or other entity issuing the security is called the issuer . A country's regulatory ...

Donald Trump cancels Chicago campaign rally over security concerns
Thousands of protesters force Republican presidential candidate Donald Trump to cancel a campaign rally in Chicago over security concerns.

Why cloud security should be a part of software development
... way naïve. The extension of which is that, if you’re giving your data to someone else, how can you be sure it’s safe? This is why cloud security ...

Protesters shut down the Trump rally in Chicago and WaPo's headline is "Skirmishes erupt after Trump ...
As if the action started with Trump. He canceled, and then "skirmishes" happened. The active agents, the protesters, don't even appear. They ...

EODM's Jesse Hughes suggests Bataclan security may have known about the Paris attacks; Bataclan calls ...
The EODM frontman has been outspoken in the wake of the Paris attacks, but his latest statements have been decried as "defamatory" and "insane" ...

Security tackles man running toward Trump at Ohio rally
Chicago Tribune Security tackles man running toward Trump at Ohio rally Chicago Tribune A man attempts to rush the stage at a Donald Trump ...

Trump calls off rally for security
There were isolated physical confrontations between some members of the crowd after the event was canceled.

Resources last updated: 3/13/2016 6:20:28 AM