Results 1 to 4 of 4

Thread: NTFS permissions for ZoneAlarm folders question

  1. #1
    bbuddha Guest

    Default NTFS permissions for ZoneAlarm folders question

    I have an important security question regarding ZoneAlarm.

    When installed in Windows XP, the ZoneAlarm version I have been using creates at least three folders that I know of:
    - C:\Program Files\Zone Labs\ZoneAlarm
    - C:\Windows\Internet Logs
    - C:\Windows\system32\ZoneLabs

    My question is, what kind of NTFS permissions can I set for these folders for maximum security, without breaking ZoneAlarm while logged in as a limited user?

    I have done auditing, and by default (as installed) only the Program Files\Zone Labs folder has secure NTFS permissions, where only admins and power users can write in the folder and limited users can only read (this is how it should be in the Windows XP security model). The other folders under the Windows folder, Internet Logs and system32\ZoneLabs have very insecure NTFS permissions by default, giving everyone full control and full write access. I guess I don't need to explain to anyone why this is insecure.

    I would like to change the permissions to these folders so that limited users cannot write there, and would like to hear from those more experienced with ZoneAlarm, whether that would cause problems, and possible suggestions on what kind of permissions would be safe to use there, without being blatantly insecure like the defaults.

    My current guess is that system32\ZoneLabs could be given permissions that enable admins/power users full control and users only read rights without causing any problems for ZA functionality, since ZoneAlarm doesn't seem to write anything in this folder and vsmon.exe will be loaded by the system/admin accounts that have full control anyway, so there should be no need for limited users to have write access.
    Internet Logs folder I think will be troublesome, because ZA keeps writing logs in there.

    So, any suggestions from the ZA experts? Thank you!

    Operating System:Windows XP Pro
    Software Version:5.x
    Product Name:ZoneAlarm (Free)

  2. #2
    Join Date
    Nov 2004
    Location
    localhost
    Posts
    17,289

    Default Re: NTFS permissions for ZoneAlarm folders question

    Hi!Never played with permission on retail versions of ZA but what you describe is already implemented by default in current retail installations of ZA.I.e. in "C:\Program Files\Zone Labs\ZoneAlarm" and "C:\Windows\system32\ZoneLabs" normal users have only read, execute and list content permissionsInternet Log has also particular permissions and read only properties on some files.Full permission is only given to adminitrators and system.On retailer versions of ZA, key ZA systems files and registry are also protected by the ZA OS firewall.No idea what would be the best permission settings for your ZA 5 free.
    Hope this helpsCheers,Fax

    Message Edited by fax on 06-06-2009 11:51 AM

    Click here for ZA Support
    Monday-Saturday 6am to 10pm Central time
    Closed Sundays and Holidays

  3. #3
    bbuddha Guest

    Default Re: NTFS permissions for ZoneAlarm folders question

    Thanks, it does help

    By "retail" version of ZA I suppose you mean the ZoneAlarm Pro and other commercial versions?

    In the free 5.x versions, only the Program Files\Zone Labs\ZoneAlarm folder has secure permissions, and the two other folders I listed give Full Control to Everyone (which is bad).

    I'm sure the ZA developers would know what permissions for those folders are as restrictive as possible but still allow ZA to function as it should on a limited user account, but the devs are very hard to get a hold of and I have not found this kind of information posted anywhere in the support sections of the ZA website.

    If no-one in this forum has that information, I guess I will simply experiment carefully.

  4. #4
    Join Date
    Nov 2004
    Location
    localhost
    Posts
    17,289

    Default Re: NTFS permissions for ZoneAlarm folders question

    Hi!yes, for ZA retail I mean the version that are sold currently. It could be also in ZA free 8 but I have not tested it.I don't think this information can be found here, you will have to experiment May be if it works in 8 it will work in 5?No ideaCheers,Fax

    Message Edited by fax on 06-06-2009 04:27 PM

    Click here for ZA Support
    Monday-Saturday 6am to 10pm Central time
    Closed Sundays and Holidays

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •