View Full Version : SecSuitePro 2009: Deny user accounts to interact with firewall - how?
J-Pro
09-06-2008, 10:14 PM
Good afternoon!
I have Outpost Security Suite Pro 2009 (6.5.2358.316.0607) installed on Windows XP Professional x64 SP2.
I have one administrator account and some user accounts. When I'm logged in, but not active, any user can log in and interact with firewall(it asks him about actions, shows to him malware scan results, even if malware found in directory of admonistrator's account, etc.). How to prevent it?
I've already set a password for changing Outpost settings, but it helped for 50%. Users stll can delete malware(administrator's cookies), allow once/block once, etc. How to make Outpost to NOT show anything to User system account in Windows XP?
Thank you very much in advance!
Manny Carvalho
09-07-2008, 04:40 AM
You could try using the background mode [settings > general > operation settings] which doesn't give access to the user interface. The service runs in the background using the policy set in settings > firewall. You probably want block most or block all [no popups, just blocks everything you don't allow by a rule] if you are confident in your configuration.
J-Pro
09-07-2008, 08:12 AM
Unfortunately, I have some app's which still asks for access or some actions. I'm a developer, so every day there are a lot of "new actions" on my computer.
Is "background mode" the one and only solution?
Because just now I had strange thing: I was logged in and had Inactive, but logged in user. And trying to switch my media player classic in full screen mode, I've got it hanged up. But after I switched to this inactive user, there was a question from Outpost about should it allow MPC to switch to fullscreen mode.
I think it's not right and there SHOULD be a possibility to fully hide firewall activity from User accounts. Just because they're users, they don't know what button they need to push. It's not secure when user decides applications behaviour...
Manny Carvalho
09-07-2008, 08:46 AM
I don't know of any other. Dialog in a user account belongs to that user. and needs to be answered by that user. I understand that you are one person using multiple accounts
That fullscreen detection can be disabled so it's not a bother but so new action in inactive users will be a problem.
I can't think of a better way since i don't operate like this maybe some others will come with an idea for you. You can contact Agnitum directly and see what they say: http://www.agnitum.com/support/contact.php
J-Pro
09-10-2008, 03:30 AM
Thanks for your reply, dear Manny Carvalho. I've used your link to get support and they answered that I can just turn off all possible alerts by doing this(post here for those who will be interested in similar problem solution):
For Outpost Firewall Pro 2008 and Outpost Security Suite Pro 2008:
1. Disable Host Protection to prevent popup prompts for user reaction every time an application component or critical system object is changed and an application performs some system activity (click Settings > Host Protection and clear the Enable Host Protection check box).
2. Disable real-time protection on the Anti-Malware (Anti-Spyware) page of product settings.
3. Disable Mail scanner and Attachment filter on the Mail Scanner page.
4. Disable Blocking private data transfer on the ID Block page.
5. Switch off the Rules Wizard mode and select Allow Most.
6. Disable logging (clear the Log debugging information check box on the Logs page).
7. Disable rules update and ImproveNet on the ImproveNet page.
8. For Outpost Security Suite Pro 2008 disable the Anti-Spam component.
(full KB article is here: KB Article about how to set up Outpost on Windows Server (http://www.agnitum.com/support/kb/article.php?id=1000037&lang=en#3))
Manny Carvalho
09-10-2008, 04:36 AM
Yes, with just about everything turned off or allowed there will be no prompts. That will work but it's really minimal security. It's blocking only things that you specifically blocked with a rule. It's almost better to uninstall the thing and just deal with Windows firewall.
vBulletin® v3.8.4, Copyright ©2000-2010, Jelsoft Enterprises Ltd.