Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 09-23-2014, 22:33
Kerlingen Kerlingen is offline
VIP
 
Join Date: Feb 2011
Posts: 324
Rept. Given: 0
Rept. Rcvd 276 Times in 98 Posts
Thanks Given: 0
Thanks Rcvd at 309 Times in 96 Posts
Kerlingen Reputation: 200-299 Kerlingen Reputation: 200-299 Kerlingen Reputation: 200-299
Firewall leak problem

I'm having a problem with a program that is able to bypass my firewall without asking for permission first. Well, not the program is the problem, but the fact that probably any malware could do it the same way.

First some basics:
The program comes as x86 and x64 version.
The program can be installed, but also runs as "portable" software.
The program does not need admin privileges to run or to bypass the firewall.
Every version is able to connect by HTTP port 80 to a webserver located on the internet.

Now the story:
I was running the program and used "check for updates" from the help menu. It told me "you're running the latest version". I was confused, since my firewall didn't pop up and ask me if I wish to allow internet access to the program.

Then I started my network monitor and did the update check again. I could clearly see a connection to port 80, HTTP protocol, requesting "/update.php" and a response from the server with the current version number.

Then I fired up my connection monitor, tried again and found out that the connection is made by the file "svchost.exe". I thought of some trojan using the same name, but it turned out that the real Windows service was the one which initiated the connection.

Since "svchost.exe" acts a proxy for many different services, I checked the process ID which had initiated the connection and ended up at "ProfSvc", the User Profile Service.

Since this is an essential Windows service which you cannot turn off and which you cannot deny network access to without crippling your system I'm now stuck.

Does anybody know how you can access the internet with the help from this service and how to prevent it?

Like I said before, a legitimate software is using this way to check for updates, it's not a trojan hourse or something like that.
Reply With Quote
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
iOS iBoot Source code leak - Probably termed as the biggest leak in the history foosaa Source Code 13 03-14-2018 01:02
Would you use a Firewall that had a cracked .dll? Rhodium General Discussion 18 03-03-2004 00:00
Best firewall? Your opinion FEARHQ General Discussion 8 11-10-2002 06:14


All times are GMT +8. The time now is 06:37.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )