View Full Version : Security Alert when I visit this forum
wes000
03-26-2005, 05:45 PM
I had a question as to why whenever I visit this forum my Norton's Internet security is triggered. It is a HTTP_ActivePerl_Overflow attack. This only happens when I visit this site. Never happens anywhere else. IP address is
0.0.0.0. I am using XP home with SP2
PrntRhd
03-26-2005, 05:52 PM
I did a search on the issue, came up with this:
"Google search gives lots of information on this. Basicly,
it all comes down to Norton firewall giving false
positives. One response i came across said that if you
are not using ActivePerl, just remove the signture from
norton."
Also this:
http://text.dslreports.com/forum/remark,9787922
I moved this out of After Hours to Guide Feedback.
Jiggy
03-26-2005, 09:14 PM
Hi wes000,
Im still having the same problem - Link (http://www.pcguide.com/vb/showthread.php?t=36154).
PrntRhd
03-26-2005, 10:31 PM
From Symantec site:
http://securityresponse.symantec.com/avcenter/nis_ids/sigs/http_activeperl_overflow.html
Versions affected:
Activestate ActivePerl Version 5.6.1.629 and earlier on Windows
False Positive
This signature may not indicate malicious intent if ActivePerl versions other than those listed above are used or ActivePerl is not used at all. In this case, you can exclude this signature from monitoring
:)
It appears only Norton Internet Security triggers this false alert.
Jiggy
03-27-2005, 07:48 AM
Have a look see at this it Recommends an upgrade Link (http://www3.ca.com/securityadvisor/vulninfo/Vuln.aspx?ID=4282), hope it helps.
wes000
03-27-2005, 08:31 AM
thanks I will give it a try and see what I come up with.
Jiggy
03-27-2005, 10:41 AM
I just followed this and it stops the alerts, im on Nortons Firewall 03 - Link (http://service1.symantec.com/SUPPORT/nip.nsf/46f26a2d6dafb0a788256bc7005c3fa3/411097f67002bed688256c440075ebfd?OpenDocument&prod=&ver=&pcode=&src=&miniver=&tpre=&prev=&dtype=), exclude this HTTP_ActivePerl_Overflow, hope it helps.
vBulletin v3.6.1, Copyright ©2000-2010, Jelsoft Enterprises Ltd.