PDA

View Full Version : Cyberhawk flags an alert but does not name the offending process



hake
06-22-2007, 10:23 AM
Cyberhawk flags an alert but does not name the offending process. This has only occurred, so far, when terminating Sun ONE Studio version 4 Community Edition. This is a Java IDE used with Sun Java JDK 1.4.2.8.

Since the name of the process causing Cyberhawk to raise the alert is not shown, I am unable to allow or deny in an informed way. This also prevents me from making the decision permanent so I have the annoyance of having the alert each time I close this Sun Java IDE which BTW does not trigger alerts while actually in use.

Because of the lack of information in the alert, I am unable to tell if there is a serious named issue affecting the security of the machine. Indeed, the alert gives almost no useful information at all to help me understand what is going on.

djames
06-22-2007, 03:14 PM
Is this true for the logs as well?

hake
06-22-2007, 10:36 PM
Yes. The event is logged but no information is given about the process which is associated with the event.

The log entry wording is as follows: -
Listen for network connection (ALLOWED)
Triggered on 22/06/2007 at 22:19:42
hake was logged in at the time

The process appears to be called runide.exe, a component of Sun ONE Studio 4 Community Edition. According to Outpost, it is communicating with UDP protocol, the remote host IP address being that of the local machine, in this case 192.168.7.11

After shutting down Outpost, the behaviour still occurs.

djames
06-22-2007, 10:47 PM
Thanks. This is good info. I will try and get this set up here, and repeat what you see.