Login:
Password:

Windows DNS bug fix can impair firewalls, including ZoneAlarm

By Scott M. Fulton, III, BetaNews

July 9, 2008, 11:50 AM

BetaNews has confirmed through its own testing this morning that a critical patch, released yesterday by Microsoft as part of a worldwide DNS bug fix effort, can and does impact the functionality of software firewalls.

Multiple reports from users since yesterday afternoon have complained of systems incapable of contacting the Internet after having implemented patch KB951748. This patch makes a major change to the way the operating system handles DNS requests. Specifically, it implements a system that enables source port randomization -- a way to scramble the address from which a request is placed -- as a security measure to thwart malicious users from being able to craft false DNS responses, and thus "poison" the caches of DNS servers.

It is a very serious fix to what could have been a catastrophic exploit, and it's being implemented not just on Windows but on Linux, and within routers and other network equipment as well. It's a major cooperative effort, but one side effect for now, due to an apparent lack of cooperation among software vendors, is that some software firewalls may need to be disabled, throttled back, or turned off altogether while a fix is under way.

In BetaNews tests, we installed the latest commercial edition of ZoneAlarm Pro (version 7.0.470, not a beta) on a virtual Windows XP Professional SP3 virtual machine, which we verified as having perfect Internet connectivity after the install. We then installed patch KB951748 from Windows Update and rebooted the VM. No Internet utility or browser was able to connect to the Internet afterward. This while the VM was running on a Windows XP SP3 physical system without the patch installed, though with ZoneAlarm Pro and with fully working Internet connectivity. Not even the PING utility would work from the virtual system's command line.

Connectivity between the virtual system and other physical systems in the local network, however, was unimpaired by the patch.

The workaround is a simple one in this case: After changing ZoneAlarm Pro's default Internet Zone security setting from High to Medium, we were able to re-establish connectivity through Web browsers. However, PING in the command line still would not function, timing out on every legitimate instruction.

BetaNews does not recommend "resetting the ZoneAlarm database" as some sources have suggested.

Reports from ZoneAlarm users on the product's online forum include two from administrators who uninstalled Microsoft's patch, restoring connectivity to their systems, only to find that Automatic Updates automatically reinstalled the patch once connectivity was restored. One user reported the problem to his Cablevision customer service representative, who informed him it was receiving multiple reports from others, and that the problem was apparently "universal."

It isn't as if this problem wasn't anticipated. Yesterday, a statement from ZoneAlarm's parent company, CheckPoint Software Technologies, advised its business customers for other lines of products that those products already provided protection against any DNS problem, effectively advising them not to employ the patch, at least not right away.

"DNS cache poisoning threats, such as the one published today, strike at the very heart of the Internet in an effort to direct users to malicious sites," stated CheckPoint's vice president of network security products, Oded Gonda. "Check Point's VPN-1 and Connectra products thwart hackers' attempts to take advantage of this latest DNS cache poisoning technique by randomizing both the source port and request ID without a need to immediately patch multiple workstations in the organization."

The statement did not mention ZoneAlarm except for the company's usual boilerplate text at the end. BetaNews is attempting to contact CheckPoint for further comment regarding its plans for handling the personal firewall breakdown; although in a development which may or may not be related to this problem, our messages to our usual contacts are all bouncing back.


Update ribbon (small)

4:42 pm ET July 9, 2008 - An IT administrator working with one of the nation's largest insurance firms contacted BetaNews this afternoon, urging us to clarify our use of the term "critical" in our header paragraph. Microsoft listed the patch not as "critical" in its vocabulary, but rather "important."

This distinction is apparently very important in the assessment of damages that may result from not implementing the fix.

Add a Comment (57 Comments)

BetaNews reserves the right to remove any comment at any time for any reason. Please keep your responses appropriate and on topic. Foul language and personal attacks will not be tolerated.

Name (required):

E-mail (required):

Enter Your Comment:

By srinaustx

edited Jul 10, 2008 - 10:45 AM

Happy to say that the updated version of Zone Alarm Pro (with high firewall setting) seems to work fine with Microsoft's KB951748. Tried about 15 websites, including bank, several secure sites, and other favorites. No problems yet.....

Score: 0

By glockman99

posted Jul 11, 2008 - 12:48 PM

Well, I installed the update for Zone Alarm, and now I can't sign in to my Yahoo IM.

When will this nightmare end???

Score: 0

By srinaustx

edited Jul 10, 2008 - 10:15 AM

Just checked Zone Alarm's web site and found following:

http://download.zonealar...nternetAccessIssue.html

I'm going to install updated version of software (which they say should solve internet connection issue) and see if it works with installation of Microsoft's KB951748. I do not care to run firewall with medium setting either. If it doesn't work, I'll uninstall the MS patch, as I've had to do in past with other updates that screwed up. Fortunately, I don't have Automatic Updates activated since I want to know exactly what I'm installing. As most people, I don't trust Microsoft!

Score: 0

By bksgs1

posted Jul 10, 2008 - 9:35 AM

ZoneAlarm have posted the fix for this issue.
http://download.zonealar...nternetAccessIssue.html

Score: 0

By merlin666

edited Jul 10, 2008 - 10:24 AM

000

Score: 0

By xpower

edited Jul 10, 2008 - 7:37 AM

Pulling down the switch for Internet Zone to medium, bypasses the prob. Surely only recommended temporarily.. Cheers.

Score: 0

By ilev

posted Jul 10, 2008 - 2:26 AM

robmanic44

Hardware Firewall does not replace software firewall. you need both as hardware firewall blocks ports from your PC while software firewall blocks applications (Trojans, Bots...) as well.

Score: 0

By robmanic44

posted Jul 10, 2008 - 5:36 AM

That's why I use NOD32 and ThreatFire.

Score: 0

By DrestinBlack

edited Jul 10, 2008 - 12:51 AM

ZA appears to be the only software affected. The title is very misleading. So, ONE piece of software and this is an issue worthy of notice? Sounds like more random MS bashing.

Score: 0

By douchrti

posted Jul 9, 2008 - 9:54 PM

Im using BitDefender and I too have noticed a few sites I visit frequently hanging. Im using Vista on a lappie, but my wife has XP with BitDefender and has had no problems at all.

Score: 0

By sites.web.pt

posted Jul 9, 2008 - 9:49 PM

SOLUTION: ZoneAlarm Pro

Go to "Firewall", "Expert" tab, click "Add", give a name to the rule (any name),

Source - Modify »» add location > My computer
Destination > Any // Protocol > Any // Time > Any OK.

Score: 0

By PC_Tool

posted Jul 10, 2008 - 8:59 AM

...and you just turned off your firewall.

Cute.

Score: 0

By Strunke11

edited Jul 9, 2008 - 9:00 PM

I installed the patch, rebooted, and lost connectivity to the internet. PING did work correctly, unlike the article notes above? But through the browser, nothing would come up. I noticed ZoneAlarm had been set to High. The uninstall of th patch requires a reboot as well. 1. Go to Control Panel, 2. Run Add or Remove Programs 3. Check "Show Updates" 4 Sort by "Date Last Used" , you will see the KB951748 update listed near the bottom, 5. Highlight it and click "Remove". You will be prompted to restart.

Score: 0

By dstratton

posted Jul 9, 2008 - 7:45 PM

"This distinction is apparently very important in the assessment of damages that may result from not implementing the fix."

As soon as I read that smartass comment, I knew who wrote the article. Scott... can you stick to the facts and not constantly throw in nonsense? You should go work for Wired. I think BetaNews is a great site but this kind of stuff is just unneccessary.

Score: 0

By RCS

posted Jul 10, 2008 - 8:55 AM

Are you a moron? Microsoft classifies it's bugfixes carefully, and companies actually do base policies around them. A patch that is classified as 'critical' is more likely to get placed into production before Q/A is complete, due to the nature of the fix. It's an important distinction, but one that you're obviously incapable of comprehending.

Score: 0

By RustedKnight

edited Jul 9, 2008 - 3:14 PM

I'm a zone alarm user and I'll be glad when the problem is fixed. I found I had to add every single domain, including my ISP, the ftp addresses where I upload domains, etc. to an "ok" list of approved sites in zone alarm before I could access them. Once I did that I had no problem but i wasn't about to do it for every domain I might visit in an evening. For now, I have shut down zone alarm and am relying on my router firewall.

Score: 0

By banjoistic

edited Jul 9, 2008 - 4:30 PM

After I installed the patch and rebooted yesterday, my AVG firewall was turned off, but I turned it back on, and it's been fine ever since.

Score: 0

By statm1

posted Jul 9, 2008 - 6:06 PM

Windows Live Onecare's firewall works fine with this patch..

Score: 0

By GS5

posted Jul 9, 2008 - 5:39 PM

Solution: Disable and uninstall all firewalls. LOL

Score: 0

By robmanic44

posted Jul 9, 2008 - 5:16 PM

The cost of hardware firewalls has dropped to point that there is no reason to use a software firewall. If you are currently using a hardware firewall, don't run a software firewall. Not only is it redundant, but it can screw up your system.

Score: 0

By fs2k155

posted Jul 9, 2008 - 6:14 PM

Can you suggest a good hardware firewall to use next time I'm trying to get connected through WiFi at a hotel? I need something small, secure, and costs about the same as a software firewall.

Thanks.

Score: 0

By robmanic44

posted Jul 10, 2008 - 5:26 AM

I currently use a NetGear GS108, but there are some new LinkSys systems that are selling as low as $34.00. The instructions are simple and easy to follow.

Score: 0

By fs2k155

posted Jul 15, 2008 - 7:44 PM

You didn't understand what I was asking. I'm looking for something that does a hardware firewall with the wireless connection typically found in hotel Internet access. I don't need a cheap switch. I hope you don't think that cheap switch is giving you a hardware firewall.

I guess I was being a little sarcastic, but was hoping that someone might know of something. There really isn't a device that fits the bill - that I know of - which is why software firewalls are still necessary for people like me who travel frequently for business and need to be both protected and connected wherever we go.

Score: 0

By Galway

posted Jul 9, 2008 - 5:59 PM

yea right ..

Score: 0

By Pixelsmack

posted Jul 9, 2008 - 5:26 PM

Well convenience is one reason to run software firewalls. Vista's for example dynamically opens and closes the needed ports applications want when run and closed.

All without the user having to do anything. This is nice. As unlike hardware routers of which most require you to permanently open a port if an app needs access.

Score: 0

By scorp508

posted Jul 9, 2008 - 5:00 PM

The title of this article is very misleading. The problem is the DNS protocol itself, not some one-off thing Microsoft did. The list of companies with fixes for differen Operating Systems out on the same day for this is very long.

Score: 0

By jmott001

edited Jul 9, 2008 - 1:01 PM

I am running two XP Pro machines with Zonealarm. One is set to automatic updates and the other is not. The machine with auto updates stopped working with the Windows patch. The other machine is still working correctly!

Score: 0

By andyno

edited Jul 9, 2008 - 4:32 PM

just got tired of ZoneAlarm and all the crap coming from it, after many years as a paying customer, moved to Online Armour for my Windows machines, patched up 3 pc on XPsp3 and no problem at all. ZA "was" the best.

Score: 0

By SethEden

posted Jul 9, 2008 - 4:34 PM

Gee Thanks Foxfyre, that's really comforting!

I trust the Windows built in Firewall about as far as I can throw the entire Microsoft campus!

~Seth
http://www.SethEden.com

Score: 0

By foxfyre

posted Jul 9, 2008 - 4:26 PM

If its any consolation, it doesn't bother the built in XP firewall...

;-)

Score: 0

By PC_Tool

posted Jul 10, 2008 - 8:58 AM

Gee, isn't that a software firewall? ;)

Score: 0

By highbeam

edited Jul 9, 2008 - 3:53 PM

I am using Comodo Fireall Pro and encountered the same problem. I spent quite a bit of time last night verifying my connection to the local network and then establishing that I could access the web, but only by inserting an IP address into the address bar. I finally restored the system to its configuration prior to the XP update. I cancelled subsequent download notifications for the same update. I'll wait until there is more information on the problem.

Score: 0

By FerdBurfle

edited Jul 9, 2008 - 3:45 PM

That's why my NEXT computer's gonna be a MAC!

(MAC's ALWAYS make perfect snese!)

Score: 0

By internetworld7

posted Jul 9, 2008 - 8:22 PM

Smart man. Thanks to the Mac, my computer is now impenetrable to attacks.

Score: 0

By PC_Tool

edited Jul 10, 2008 - 8:58 AM

Thanks to the Mac, my computer is now impenetrable to attacks.

Yeah genius.

Because we all know there's never been malware or viruses on the Mac OS X platform...

Look at the links above. Those are called facts. Now, look at your post...which includes none.

Fanboy much?

Score: 0

By cescam66

posted Jul 9, 2008 - 7:19 PM

ok your point?

Score: 0

By GS5

posted Jul 9, 2008 - 5:43 PM

And that's supposed to make you impervious to attacks??? Dude that makes so "snese".

Score: 0

By foxfyre

posted Jul 9, 2008 - 4:15 PM

"by FerdBurfle

edited Jul 9, 2008 - 3:45 PM

That's why my NEXT computer's gonna be a MAC!

(MAC's ALWAYS make perfect snese!)"

And yet even after editing your post, it still makes no "snese".

Score: 0

By preinterpost

posted Jul 9, 2008 - 3:52 PM

Yeah, sounds like you need one.

Score: 0

By BigPoppa

edited Jul 9, 2008 - 3:34 PM

I had this problem this morning with one of my clients, but I immediately thought of zone alarm being part of the problem. I set the internet zone from HIGH to MEDIUM and internet came back up right away. I was not aware of this particular computer having automatic updates enabled, but now that Im reading this article it makes perfect snese!

Score: 0

By Soozy

posted Jul 9, 2008 - 2:30 PM

The rumor I heard was that Zone Alarm wasn't privy to secret meetings help between MS and other firewall companies.
Therefore they had no warning of this update.

Score: 0

By glockman99

edited Jul 9, 2008 - 2:29 PM

THANK GOD for system restore! My computer downloaded those updates this morning, and hardly anything would work after that. (I also have Zone Alarm...Maybe it's time to dump that, and go back to Ad-Aware?). I have turned OFF my automatic updates, as after my first system restore, the update "sheild" popped-up again, and not being a computer wizard, I ran the update again, and again, nothing worked, so I did a 2nd system restore. Now, all is well again.

Score: 0

By dougau

edited Jul 9, 2008 - 2:11 PM

I'm running McAfee security center and noticed that some websites would hang and some wouldn't load at all after the update but clearing the cache and running a reg scan seemed to help, at least with some sites. I figured it had something to do with the update as the problem appeared in both Firefox and Ie7 with the same sites right after I installed it. At least now I know why and will look at McAfee for a fix.

Score: 0

By Hall9000

edited Jul 9, 2008 - 1:55 PM

Well, now I know why I had to do a system restore. Still, I see some blaming ZoneAlarm. Maybe Zone is part of the problem BUT since so many people do use Zone how come M$ didn't find out how it reacted before sending the damn patch? I mean, they must have at least ONE TEST COMPUTER with ZoneAlarm installed on it as a test bench?

Score: 0

By Stratman4300

edited Jul 9, 2008 - 1:28 PM

I understand the need, as this has been a glaring problem with DNS for a long time.

I would have thought that Microsoft at least would have issued a statement about this update to warn of potential problems, but then again A LOT of their updates have been known to break things. So, i suppose this shouldn't come as a surprise.

Running linux here, and running firehol IP tables firewall and i haven't experienced any issues thus far.

Thanks!!
--
Ando
http://www.andostechcorner.blogspot.com

Score: 0

By cescam66

posted Jul 9, 2008 - 7:21 PM

well why is it that my computer has not been "broken" after an update?? because i know what i'm doing and what i'm installing YOU ****!

Score: 0

By Gungistoker

posted Jul 9, 2008 - 6:52 PM

Another 'Wednesday morning quarterback'.

Score: 0

By SethEden

edited Jul 9, 2008 - 12:52 PM

Thanks for this news, I wondered why my system wouldn't connect this morning. Now I know!

Cheers
~SethEden
http://Blog.SethEden.com

Score: 0

By PC_Tool

edited Jul 9, 2008 - 12:34 PM

Windows DNS bug fix can impair firewalls, including ZoneAlarm

Firewalls. (plural)

Including. (as well as...)

...and yet the only firewall mentioned in the entire article is ZoneAlarm.

You imply this affects multiple products in the headline and then focus only on one, neglecting to even bring up any other products that might support the claim in the headline that this apparently affects more than one firewall.

Now, I know better than to assume you are trying to do something as lame as create a sensational headline just to gather hits. That would just be silly. So, what is it? Did you forget about the other ones? Which are they?

Score: 0

By SMFulton3

posted Jul 9, 2008 - 2:27 PM

Okay, some fair questions asked.

No sensationalism here; in fact, I'm actually trying to be fair. The side-effect of implementing this patch impairs the effectiveness of firewalls, plural. That's because it changes the way DNS works. That's not the fault of ZoneAlarm; it's not my intention to say there's any defect in ZoneAlarm. There isn't, as far as I'm concerned. What I'm saying is that the nature of the problem and the nature of the solution can have a detrimental effect on firewalls, and I cite ZoneAlarm as an example.

Had the headline been, "Windows DNS bug can impair ZoneAlarm," then the complaint would have been that we're unfairly picking on ZoneAlarm. And frankly, it would have been a legitimate complaint.

-SF3

Score: 0

By jpm18

edited Jul 9, 2008 - 4:24 PM

After implementing this patch, one of my two computers running CA (Computer Associates) firewall was fine, the other reported that the firewall was not installed. It took some searching, but there was a fix on the CA website. So it's not only ZoneAlarm that's affected and your headline was just fine!

Score: 0

By preinterpost

posted Jul 9, 2008 - 12:41 PM

On the other hand it's been quite boring the last few days so why not give it a try...

The Obama post last week was excellent (if only foxy would realize that some people have other things to do than read multi-page comments...)

Score: 0

By foxfyre

posted Jul 9, 2008 - 4:13 PM

Then I would suggest using your time to do them instead of spending your time here to whine about it

Score: 0

By preinterpost

posted Jul 9, 2008 - 6:30 PM

Have you no compassion and mercy..? ;-)

Score: 0

By mjm01010101

posted Jul 9, 2008 - 12:31 PM

How many times have various issues with ZA's firewalls come up after MS updates? A hell of a lot.

Score: 0

By Tarun.

posted Jul 9, 2008 - 12:14 PM

ZoneAlarm has gone downhill since v3. Some of the top firewalls recommended on the Matousec website do not have these issues.

Score: 0

By AdaD

edited Jul 9, 2008 - 12:46 PM

This patch loaded automatically this morning, and I had the problem connecting to the internet through ZA. I did a System Restore and it returned internet connectivity. I certainly wish I had known about this problem before I let the patch install.

Score: 0