Going surfing? It’s dangerous out there – wear layers.
like a modern-day example.
180Solutions). Those who follow
ZoneAlarm events will remember the court case 180Solutions brought against us
just a couple years back for protecting our customers from installing their
application. They eventually dropped the complaint after we refused to back
down (http://download.zonealarm.com/bin/free/pressReleases/2006/pr_1.html), but
that didn’t stop Zango from continuing their tricky tactics.
It all starts with a
secret crush
what any breathing human would consider a titillating, intriguing message: “1
secret crush invitation.” Oh, and a
little red heart. Gentlemen, ladies –
how many of you will take notice and click through? Could you use a little company? Perhaps the
next Mr. or Mrs right?
company you’re going to get out of the deal is a sneaky little piece of adware
that downloads to your computer and watches you. (Fortinet, who discovered the exploit, has
the details nicely recorded here: http://www.fortiguardcenter.com/advisory/FGA-2007-16.html.)
Social engineering
ends in heartbreak
way that hackers get you to willingly download crap to your PC. This crap can by anything from bothersome
adware that slows your PC and flashes banner ads, to programs that record
anything you type such as credit card numbers.
program that just all-out takes control of your PC to attack your friends and
family, attack the government, send illegal porn, and other very bad
things. Estimates say that about 25% of
us have at least one of these types of program on our PC.
Get protection –
layers of protection
us, and the Internet-at-large. In the
above Zango case, I believe its incumbent upon Facebook to qualify the widgets
that are offered through their service. And it’s incumbent upon companies that are creating really cool, open
services like Facebook and widgets to consider security implications along with
all the fun.
a lot of layers of security. This way,
even if a threat gets by one or even several layers, there will always be
another layer (or several) to catch it.
of ways. Here’s how:
ZoneAlarm ForceField
you surf the Web. (It’s currently in
beta as a free download.)
it found a Zango URL variant that was dangerous (below) through its spy site blocking:
Next, it found a variant of the Zango executable as it
downloaded to the PC through its dangerous download detection (below).
ZoneAlarm Internet
Security Suite
protect you and your PC from everything that gets thrown at it. It caught Zango variants with three of its
layers:
source through its spy site blocking feature (below).
Next, its antivirus caught
and eliminated the variant as soon as it was downloaded to the PC (below).
The final layer was ZoneAlarm’s program control, which
catches malicious applications through a behavioral approach (below).
– JordyB






Someone got so smart and corrupt damage Windows\internet logs\IAMDB.RDB
windows\internet logs\backup.RDB
Vsmon.exe was unable to read it.
They damage zonealarm soo bad.
Jim, there are proper forums for reporting such problems. Please don’t send complaints to blogs.
Hello!
We have discovered that ZA brokes named pipes communication on Vista (not on XP), even when the IPC is between processes on the same machine. This causes that many programs that use named pipes for IPC between, for example a service and a desktop application are broken.
Is that a known bug or it is a desition of the ZA designers?
I have been using your free firewall for a number of years now and avidly follow your blog. Thanks for the advice. I had heard about Zango buy had forgotten.
By the way, what do you think of the following guy and his free downloads: http://www.software-street.com/software/?int=AAMO
They have that same Zango as on bebo.com
yeeah
those guys one step ahead from antivirus or security firm…..
Interesting article. I personally use Zone Alarm free version (and checkpoint at work) for a few years now. I even recommend my readers of my blog to install Zone Alarm, and never turn it off, in order to protect their computers. http://publicarticles.info/blog/?p=5