Quote:
If I remember correctly, kerio comments changes as well? It's either that or sygate, but I'm pretty sure kerio does it.
Not kerio, because kerio doesn't filter or touch incoming HTML data since it doesn't bother with pop up or ad blocking (thankfully)
Quote:
Another thing- to get by the ZA firewall, does it exploit the software? You say there are reports of it getting past the NIS firewall as well. Would this be a specific attack by the adware against ZA and NIS, or a technique in general that allows it to slip past all software firewalls?
Using API call checking (AFAIK) it knows when the designated popup window for ZA and NIS comes up to ask for permission of the software to connect to the internet. Upon seeing that it is up, it clicks the button and changes so quickly the user hardly notices.
Quote:
It sounds like the mythical jpeg virus that infects all picture viewers, which is "impossible". It would have to cater to all forms of software that open it, making it unrealistic. Does this spyware target ZA, and possibly NIS, or use a method that sneaks past the concept of a firewall?
Just like how debuggers of C and C++ use window tools to gather than names of loaded windows along with currently loaded strings, the creator of this must have done the same. By gather the window names according to the program as well as the proper strings, they could detect when those "allow program outbound, and remember" popups occured from the firewalls. That's ZA specific, but the way it got around NIS was by merely adding itself to the list which was vunerable to direct manipulation. No myth here :( It can't breach sygate or kerio AFAIK