Security Basics mailing list archives

Re: Remotely manage Zone Alarm


From: "Thomas Graf" <TGRAF () swmail sw org>
Date: Thu, 04 Sep 2003 16:44:43 -0500

Kill the zonealarm process with pstools from sysinternals
http://www.sysinternals.com/ntw2k/freeware/pstools.shtml.  I tested
it with the free zonealarm so I am not sure if it will work with the pro
version.  Use pslist to list the processes from his computer and use
pskill to kill the vsmon and zoneal~1 processes.  

Thomas Graf


Cesar Diaz <cesadiz () yahoo com> 09/04/03 08:36AM >>>


We have a user that works remotely.  Since he works outside our 
firewall he has Zone Alarm Pro on his machine.
 
This week he is in the office.  Our logs show he is trying to access 
things he shouldn't be and doing things he shouldn't be.  For internal

political reasons HR wants some more proof that it's not accidental.  I

can't access his c$ share to look at Zone Alarm logs or remotely access

his event logs because of the Zone Alarm
 
Is there a way to centrally manage Zone Alarm settings or is this user

completely shielded while inside our network?
 
Cesar


---------------------------------------------------------------------------
Attend Black Hat Briefings & Training Federal, September 29-30
(Training), 
October 1-2 (Briefings) in Tysons Corner, VA; the world's premier 
technical IT security event.  Modeled after the famous Black Hat event
in 
Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors. 

Symantec is the Diamond sponsor.  Early-bird registration ends
September 6.Visit us: www.blackhat.com 
----------------------------------------------------------------------------


---------------------------------------------------------------------------
Attend Black Hat Briefings & Training Federal, September 29-30 (Training), 
October 1-2 (Briefings) in Tysons Corner, VA; the world's premier 
technical IT security event.  Modeled after the famous Black Hat event in 
Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.  
Symantec is the Diamond sponsor.  Early-bird registration ends September 6.Visit us: www.blackhat.com
----------------------------------------------------------------------------


Current thread: