//flex table opened by JP

Click to See Complete Forum and Search --> : BID Update 2.1


socalgal
06-12-2000, 03:18 PM
Late posting, but here's the release description:
http://www.networkice.com/html/blackice_defender_update.html

What: This is BlackICE Defender release 2.1.

Why: This release provides the following fixes/changes:

Support for Windows 2000. BlackICE is now supported to run on Windows 2000 Pro.
Improved user interface and functions:
Configurable severity levels to trigger visual and (new) audible attack notification.

Configurable Attacks and Intruders tab columns; you can view all of the data previously hidden in attack-list.csv.

Visible menu.

Attacks and Intruders tabs now have indication of an attacker's or intruder's blocked state.

Copy to clipboard (via Ctrl-C) capability on Attacks and Intruders tabs.

Graphical LED lights that provide visual indication of network activity.

Auto-checking for new BlackICE updates
Auto-port blocking response. BlackICE will now do an automatic port block on certain critical attacks (e.g. Trojan horse attacks like Back Orifice)

New Detections:

FTP file exec exploit
FTP compress exec exploit
POP3 RETR argument very long
Empty fragment
ICMP flood
Twinge attack
Zero length
TCP option
TCP small segment size
TCP SYN with URG flag
TCP Invalid
Urgent offset
UDP short header
DNS BIND version request
DNS null
PrettyPark worm
ILOVEYOU virus
NetSphere HTTP activity
HTTP asp with \ appended
CGI finger.cgi
WebSpeed admin URL
UBB suspicious posting
SubSeven ICQ pager URL
Oracle batch file URL
sojourn.cgi argument contains %00
Index Server null.htw exploit
FrontPage extension backdoor URL
FrontPage htimage.exe URL
InfoSearch CGI exploit
Cart32 Clientlist URL
Cart32 ChangeAdminPassword URL
Listserv CGI exploit
HTTP URL contains %00
HTTP User Agent field overflow
SMB startup file
SMB autoexec.bat file
SOCKS login failed
SOCKS connect
SOCKS over SOCKS
SNTP malformed
RPC bad credentials
RPC suspicious credentials
RPC getport probe
rpc.sadmind overflow
Mstream agent activity
Mstream handler activity

Applicability: This update is applicable to all BlackICE Defender releases.

Content: BlackICE Defender Release 2.1

blackice.exe version 2.1
blackd.exe version 2.1
blackdll.dll version 2.1
blackdrv.vxd version 2.1 (for Win 95/98)
blackdrv.sys version 2.1 (for Win NT) 1

codybear
06-12-2000, 04:08 PM
thanks..I got it a couple days ago and knew you would soon post it..I was waiting for win 2000 support and it seems to work fine now..

socalgal
06-12-2000, 07:09 PM
Codybear, or other BID users, I'm at the BID message board now trying to find out why the this new ver blackdr.exe isn't running in Ctrl+Alt+Del, like the previous ver.

When I right click and hit Stop BlackIce Engine, the blackdr then shows as running; when I Start BlackIce Engine, the blackdr is gone.

This seems backwards to me...

Blackdr.exe is set to run at startup, according to msconfig. Any ideas?

Win98

Edit: Hmm.. well with ZA off and running a port scan at Steve Gibson's, BID is receiving and blocking hits... so it seems ok.

There's lots of talk at the BID Message Board about the 2.1u have a 10 minute delay of the engine starting after a system crash though. Seems you have to enter: 'startup.crashdelay=false' into sigs.ini

Anyway, check it out here: http://www.egroups.com/messages/bidissues/2496

You'll need Java enabled!

[This message has been edited by socalgal (edited 06-12-2000).]

codybear
06-12-2000, 08:14 PM
I am in windows 2000 and it works just fine for me..I had zone and the only reason I had it was because BID would not work in 2000...all is fine with 2000 and this version..I cannot help you there

socalgal
06-12-2000, 08:20 PM
It seems to be working just fine Codybear, per my Edit above.

Thanks http://sysopt.earthweb.com/forum/smile.gif

BBA
06-12-2000, 08:27 PM
Maybe I'll give it a shot on my next server build.

Dave_H
06-12-2000, 08:50 PM
I suspected the new version of BI of causing my system to suddenly reboot all by itself because it never happened until after updating to 2.1.u. I e-mailed network-ice about it, but they have yet to respond. Reading the BI discussion forum, I see people refering to these versions as "beta u", beta q, beta t, etc. Whats up with that? I actually applied for the beta program with them a few months ago but was planning on doing it with my test system, not this one!
(This one runs so sweet, thats why I'm PO about the reboots). I just checked back on there site and they just put up the previous version for download, something they have never offered before. I'll be switching back to see if the reboots stop.
Dave

Edit- I forgot, but I first thought that maybe it was an incompatibility between BI and my ATI rage fury because whith the BI box up on the screen, my cursor blinks like heck. I have changed ATI drivers but no joy.
Also have compleatly removed and reinstalled BI. -Edit

[This message has been edited by Dave_H (edited 06-12-2000).]

socalgal
06-12-2000, 09:33 PM
Dave, check to see if you need an Uninstaller to get rid of it.. I'm not sure but I recall reading *something* about that.

Is this on your W2K system?

It sounded to me like they are betas too - so why are they calling it a release?

I don't know... BID still seems to me a pretty good program - I like it; but they don't do a good job of explaining things. We more or less have to find out/troubleshoot on our own. Their tech support via email isn't anything to write home about, either, unfortunately.

Dave_H
06-12-2000, 10:07 PM
Whoops http://sysopt.earthweb.com/forum/smile.gif
Sorry Socalgal. This is on a Win-98(se) system. I used the utility availible at thier site to compleatly remove BI before I reinstalled it. The utility is called "biremove.exe". I also installed ver 2.1.u on a second Win-98(se) system that also has an ATI card on it. I get the same cursor problems there with the BI box open, but havent got an unwanted re-start yet, it's only been 1 day on that one.
Here is something from my "blackd-old.log" (opens with notepad)
EX::Sun, 11 Jun 2000 18:26:08: Detected previous shutdown problem, but not waiting
Yes I'd also call an unwanted reboot a "shutdown problem" http://sysopt.earthweb.com/forum/frown.gif
I may leave this version in a few days and see what I can do about it, thankfully I made a drive image a few days before the update.
I see that a bunch of people are having problems with this version, but will assume that for most it is working fine. I have allways been real happy with BI and think that a mistake was made in releasing this version too early.
Hope everyone else has better luck than me. http://sysopt.earthweb.com/forum/smile.gif
Dave

socalgal
06-12-2000, 10:20 PM
Edited...

I just installed 2.1u earlier this evening, so I'll keep my fingers crossed. Thank goodness for scanreg /restore - another hopeful option too.

I hope things get resolved without too many hassles for you, Dave. http://sysopt.earthweb.com/forum/smile.gif


[This message has been edited by socalgal (edited 06-13-2000).]

tonym
06-13-2000, 09:38 PM
Socalgal,

I just got thru d/l-ing the 2.1u of BID.

Kewl. It works great so far! I like the ability to re-adjust the size of the report window to see in greater detail the SOBs that are trying to ravage and plunder my hardware!!!


Thanks for the heads-up!!!


Tony

Dave_H
06-14-2000, 01:24 AM
If anyone else has problems with this "beta" version like I have been having, there are a couple more options rather than reverting back to versions 1.9.25 or 1.9.33.
1) Install a new driver into 2.1.u http://www.egroups.com/message/bidissues/2557
You have to sign up as a member at egroup to get it there. (or mail me).
2) Try the next beta version 2.1.w http://www.egroups.com/message/bidissues/2558
All the beta versions are now availible to anyone with a license for BI.
I'll be trying the W version myself.
Dave