ZoneAlarm users, don't take today's MS updates!

Maybe you have your “Internet Zone” slider set to medium?
http://download.zonealarm.com/bin/free/pressReleases/2008/LossOfInternetAccessIssue.html


It is set on high … click image below to enlarge.


Holy cr*p, I completely take back my previous post !! I did some more research on this patch issue, and now I realize the grand situation of this thing …

Instead of not installing the patch, update or uninstall any software that doesn’t cope well with the multiple patches (like ZoneAlarm). Install the patch and update all else.

I completely take back my original comments:

Castlecops post :

Quote
Windows update KB951748 should not be installed. It will break your Internet connection. If you have it already installed, uninstalling it fixes the problem.

I have spent the day troubleshooting over 20 PCs and have found all installations to have the install date of 9 July 2008, which in my part of the world is tomorrow. I think that as of tomorrow it should work. If not then MS broke something again, but we are used to that.

How to fix it? Go to Start> Control Panel> Add/Remove Programs. Make sure to put the tick mark in the “Show updates” box in the upper right-hand corner of the screen. Scroll down to the Windows Updates and look for (KB951748), highlight it and press remove. You will need to immediately do a reboot and when your machine has restarted your Internet connection will function again!

http://www.castlecops.com/a6916-MS_KB951748_breaks_ZoneAlarm.html

Really bad mistake on Microsoft’s part … Incompatibility based on date Huh

For more information on this DNS issue (apparently, this is really major; more details on August Black Hat conference):

http://blogs.zdnet.com/security/?p=1460
http://blogs.zdnet.com/security/?p=1468
http://blogs.zdnet.com/security/?p=1471

http://www.doxpara.com/ → This is the guy who discovered the issue, Dan Kaminsky, and you can check whether or not you are protected (with the DNS patches)

http://www.matasano.com/log/1093/patch-your-non-djbdns-server-now-dan-was-right-i-was-wrong/
http://blog.trailofbits.com/2008/07/09/dan-kaminsky-disqualified-from-most-overhyped-bug-pwnie/
http://securosis.com/2008/07/09/more-on-the-dns-vulnerability/
http://securosis.com/2008/07/08/dan-kaminsky-discovers-fundamental-issue-in-dns-massive-multivendor-patch-released/
http://www.veracode.com/blog/?p=120
http://www.veracode.com/blog/?p=119
(Heck, check out the entire blog, http://www.veracode.com/blog/ , for entire following to the issue.)

Here is the actual US-CERT (United States Computer Emergency Readiness Team, part of international organization)::
http://www.kb.cert.org/vuls/id/800113