Endpoint Protection

 View Only
  • 1.  Traffic has been blocked from this application:

    Posted Jun 24, 2011 01:05 PM

    I'm still seeing this frequently in RU6 MP3 clients, where an elert is generated, but the offending application is not identified. I seem to rememember this was a bug in earlier versions that was supposedly fixed.  Deleting the rule does not resolve the issue.

    Does anyone have a status on this? Is it still a bug, if so is there a planned fix? If not a bug, is there a fix?

    Thank you.



  • 2.  RE: Traffic has been blocked from this application:

    Posted Jun 24, 2011 01:56 PM

     HI Justin_g ,

                    Can you take screenshot of the alert . Also check in all the logs .



  • 3.  RE: Traffic has been blocked from this application:

    Posted Jun 24, 2011 02:32 PM

    Sure, this is a partial screen-cap of the .mht alert. It is scrolled all the way over, so the text is not obscured:



  • 4.  RE: Traffic has been blocked from this application:

    Posted Jun 24, 2011 05:00 PM


  • 5.  RE: Traffic has been blocked from this application:

    Posted Jun 24, 2011 11:51 PM

    Hi ,

     Please do not delete the rule . It is a DDOS (Denial Of Service ) . Do not delete the rule .

    It is not necessary it has to be a single application . This DDOS can try to get the details from the TCP and UDP packets . Using those details it can change the password to default password . There no source address for this DDOS .

     

    This is what i suggest , Run the SEP_support_tool.exe and collect the logs . Download from

    ftp://ftp.symantec.com/public/english_us_canada/products/symantec_endpoint_protection/SEPDIAG/

    Select SEP_support_tool.exe 

    Run the tool and collect the logs.

    Upload the file and i will check it . You cannot view by notepad because the file extension is different .

    It is not txt but it is SDBZ . THere is a viewer in the same Folder "SEPDIAG" download the Viewer .

    Check the logs and If you find any program or application .

    send it to Security Response Team.

    Use This KB article : http://www.symantec.com/docs/TECH147870

    This article will tell you , What do send , how to send it and whom to send it .