Users of the ZoneAlarm suite will need to patch it before applying Tuesday's Windows DNS patch.
A Windows patch designed to fix a security hole in the Internet's DNS resolution system left a swathe of customers without 'net access this Tuesday.
The issue was caused by a bizzare incompatibility between the patched Windows system files and the popular – if a little Fisher-Price – ZoneAlarm personal firewall package. Any users running ZoneAlarm and installing Microsoft's MS08-037 patch, released as part of the regular Patch Tuesday update cycle, will have found themselves cut off from the 'net after rebooting their systems.
According to
CNet a
patch has been created by CheckPoint Software, the company behind ZoneAlarm, which restores connectivity in affected systems. There's only one
teeny little snag – you have to download it.
Workarounds to ensure that you can grab the patch – aside from downloading it somewhere else – include switching ZoneAlarm from 'high' to 'medium' security, uninstalling the MS08-37 patch and then reinstalling again after updating ZoneAlarm, or temporarily switching to the built-in Windows firewall until the update is applied.
The Microsoft patch that prompted this issue, which only affects ZoneAlarm installations, was part of a massive effort on behalf of a large number of networking companies addressing a security flaw in the domain name resolution system used to turn friendly domain names into IP addresses. Before the hole was plugged, it was theoretically possible for a malicious individual to point browsers to fake websites without ever needing to compromise their PC and router. Thanks to the companies involved, including Microsoft, this issue has been resolved – albeit not without a few hiccoughs along the way.
Any ZoneAlarm users had a few issues since Tuesday and only now finding out why? Perhaps you're
still having issues – in which case you won't be able to read this? Does the fault for this problem lie with Microsoft for not testing the patch with a popular firewall package, or with CheckPoint for doing something weird with the Windows system files that no other firewall vendor does? Share your thoughts over in
the forums.
Darkedge,
Checkpoint has a compatibility issue that does not make it rubbish. On what issues do you base your statement? I am curious as I changed to ZoneAlarm after actually paying for Norton, that is a really annoying piece of software. It took away all the control from me and decided what was best for me, for example what emails were safe regardless of what I told it. I ended uninstallig it.
Ah, the problem here is that nortons firewall is even worse than zonealarm. Which i did not think was possible.
as I'm concerned zonealarm is the best firewall for the money windows firewall is useless in comparisan and zone
alarm was on top of the problem. I downloaded the update to fix my firewall then installed KB951748 and everything worked fine.
I've just been telling everyone to do what the zone alarm site says which is stick the security in ZA to medium. Problem solved
moving the za to medium is a workaround not a fix! and it reduces your internet protection. download the update
from za and install it over your present za program no clean install required
Glad Zone Labs has a fix out already.
Finally, I did a search on another comp and found the cause and dl'd the latest ZA.
Thing is, in all my years with XP, or any windows, I've been lucky and never had a patch or update or service pack give me any problem whatsoever; so that was not something that came to mind when trying to diagnose the problem, especially since I had completely forgotten about installing that little patch a couple days ago.
Agreed. I was pulling out my hair trying to find out what happened to my parent's computer. Never before have I been able to ping a website (bit-tech, incidentially ) but not be able to load the site in Firefox. :(
Mostly figured someone had mucked about with the settings of Windows again, but I didn't think about ZA. Makes me glad I couldn't get it to work with XP 64. :D