home *** CD-ROM | disk | FTP | other *** search
- -----------------------------------------------------------------------
- -----------------------------------------------------------------------
- -- BlackICE Defender (EVALUATION) --
- -----------------------------------------------------------------------
- -----------------------------------------------------------------------
-
- Release Notes for Network ICE BlackICE Defender Rel 2.1.ck (EVALUATION)
- . blackice.exe version 2.1.32
- . blackd.exe version 2.1.32
- . blackdll.dll version 2.1.34
- . blackdrv.vxd version 2.1.35 (for Win 95/98)
- . blackdrv.sys version 2.1.34 (for Win NT/2000)
-
- These Release Notes contain important information about your evaluation
- copy of BlackICE Defender. The following topics will be covered:
-
- . System Requirements
- . What is BlackICE Defender 2.1.ck?
- . Known Issues and Limitations
- . General Information
- . On-line Documentation
- . Support
-
-
- -----------------------------------------------------------------------
- -- System Requirements ------------------------------------------------
- -----------------------------------------------------------------------
-
- Hardware: Pentium class computer.
-
- OS: Windows 95 (retail(single user), OSR1, OSR2, OSR2.1,
- and OSR2.5)
- Windows 98 (retail, SP1, Second Edition)
- Windows NT 4 Workstation (SP4, SP5, SP6, SP6a)
- Windows 2000 Pro
- Windows Millennium
-
- Memory: Minimum of 16 MB.
-
- Disk Space: A minimum of 6.5 MB. This includes 2.5 MB allocated for
- logging trace files.
-
- Other: System must be using COMCTL32.DLL version 4.72 or newer;
- COMCTL32.DLL is available at:
- http://msdn.microsoft.com/downloads/sdks/platform/redist.asp
-
-
- -----------------------------------------------------------------------
- -- What is BlackICE Defender 2.1.ck? ----------------------------------
- -----------------------------------------------------------------------
-
- . BlackICE Defender 2.1.ck is a 30-day evaluation version of BlackICE
- that is a fully operational intrusion detection and protection tool;
- it will give your computer the ability to detect and block intrusions
- into your computer system.
-
- . Network ICE DOES NOT provide phone or e-mail support for this
- evaluation version.
-
- . If you find this evaluation version useful, purchase your copy of
- BlackICE Defender using the BUY button on the information tab.
-
-
- -----------------------------------------------------------------------
- -- Known Issues and Limitations ---------------------------------------
- -----------------------------------------------------------------------
-
- KNOWN ISSUES
-
- . If you update from 1.8.6.x to 1.9.14 (or newer) and later uninstall
- BlackICE, on Win 98, a Windows registry entry in the
-
- HKLM/Software/Microsoft/Windows/CurrentVersion/Run
- (note: HKLM = HKEY_LOCAL_MACHINE)
-
- key to load blackd.exe (specifically the LoadBlackD entry) will
- remain. On Win 95, the Windows registry entry in
-
- HKLM/Software/Microsoft/Windows/CurrentVersion/RunServices
-
- may remain as well.
-
- Work-around: Uninstall 1.8.6.x prior to installing 1.9.14 or newer.
- At worst, you can uninstall BlackICE cleanly using the utility
- located at:
-
- http://www.networkice.com/Download/updatebiremove.htm
-
- . Certain intermediate adapter drivers may cause BlackICE to crash.
-
- Work-around: Configure BlackICE to ignore that adapter by adding a
- line in blackice.ini, then restarting your system. This web page
- explains how to do this:
-
- http://www.networkice.com/Advice/Support/KB/q000023/default.htm
-
- . For Win NT 4: Under certain situations, the floppy drive is
- inaccessible when BlackICE is installed.
-
- Work-around: Add the following line to blackice.ini:
-
- starting.i=101
-
- After saving and closing blackice.ini, stop and start the blackice
- service in the service list.
-
- . If you are using a dialup modem to access the Internet and you are
- having difficulties connecting with BlackICE Defender running, then
- try the following:
-
- 1. Add the following line to blackice.ini:
-
- restart.whenDeviceChg = false
-
- 2. Save and close blackice.ini.
- 3. Done.
-
-
- LIMITATIONS
-
- . Under certain situations, you may see the RED slash across the
- BlackICE system tray icon. This may happen under certain conditions,
- to include:
-
- .. You invoked BlackICE Engine/Stop BlackICE Engine.
-
- .. The BlackICE engine is in startup delay. BlackiCE has determined
- that for some reason, the system was abruptly or unexpectedly
- shutdown in a prior computer session. If you do not wish the
- BlackICE engine to go into startup delay, add the following line
- to sigs.ini (note that an entry for that parameter might already
- exist there; in this case modify the entry):
-
- startup.crashdelay = false
-
- If this is the case, you will not be able to start the engine from
- the user interface because the engine is actually running but in
- delayed mode. To recover from this, run the batch program stopblackd.bat,
- wait a minute and then start the engine from the menu.
-
- .. BlackICE has detected a network device insertion event and is
- re-starting to accommodate the new device. In this case the red
- slash is temporary and will disappear after a few seconds. One example,
- if you access the Internet via a dialup modem, then it is very likely
- that you will see the red slash appear everytime you connect to the
- Internet. If you don't want this to occur, then consider adding the
- following line to the blackice.ini file:
-
- restart.whenDeviceChg = false
-
- The side effect of adding this line is BlackICE may, under certain
- conditions, detect your computer as an intruder.
-
- .. Your system has become busy to the point where the BlackICE user
- interface is temporarily unable to communicate with the BlackICE
- engine. If this is the case, you will see the red slash for only a
- short period of time with no lapse in system protection from the
- BlackICE engine.
-
- .. The BlackICE engine has terminated unexpectedly. If this happens,
- contact support-L1@networkice.com and provide the necessary
- information as recommended in the SUPPORT section of this document.
-
- . On some notebook computers, configured to go into standby/sleep when
- there is lack of computer activity (e.g. disk, keyboard, and mouse
- activity), BlackICE Defender may prevent going into standby because of
- BlackICE Defender's own disk activity.
-
- . If you are having difficulties performing SCANDISK or DEFRAG, stop
- the BlackICE engine. When your computer is busy receiving network
- traffic, so is BlackICE (busy, that is). As such, BlackICE is also
- busy logging information to your disk. SCANDISK or DEFRAG may not
- finish when your disk drive is in use.
-
- . BlackICE will prevent certain PDA's to synchronize. If this happens,
- stop the BlackICE engine.
-
- . Versions older than 2.5 of Cookie Crusher are incompatible with
- BlackICE. Removing the Cookie Crusher fixes the problem.
-
- . The parameter "adapters.enabledxxx = false" was originally intended
- to force BlackICE to ignore traffic from the specified adapter. At
- present it will only prevent BlackICE from opening the specified
- adapter, and will continue to monitor traffic and protect against
- intrusions from that adapter.
-
-
- -----------------------------------------------------------------------
- -- General Information ------------------------------------------------
- -----------------------------------------------------------------------
-
- . Packet/Evidence Files
-
- BlackICE generates packet and evidence logs (log*.enc and evd*.enc
- respectively). To view these files, you will need a utility that
- can read and decode them. This URL lists such utilities:
-
- http://www.robertgraham.com/pubs/sniffing-faq.html#software-windows
-
- . What to do about attacks
-
- These Web pages provides information on what to do about attacks:
-
- What can I use for evidence?
- http://www.networkice.com/Advice/Support/KB/q000016/default.htm
-
- What's the format of attack-list.csv
- http://www.networkice.com/Advice/Support/KB/q000018/default.htm
-
- I've been attacked, now what?
- http://www.networkice.com/Advice/Support/KB/q000033/default.htm
-
- Oh my gosh, I'm being hacked!
- http://www.networkice.com/Advice/Support/KB/q000040/default.htm
-
- . This page lists Internet sites you can use to scan your host. These
- sites won't work if you computer is behind a proxy.
-
- http://www.networkice.com/Advice/Support/KB/q000026/default.htm
-
-
- -----------------------------------------------------------------------
- -- On-line Documentation ----------------------------------------------
- -----------------------------------------------------------------------
-
- A BlackICE User's Guide in Adobe Acrobat Reader 3.0 (.pdf) format is
- available at our website. Simply go to the following web page:
-
- http://www.networkice.com/html/documentation_support_.html
-
- At that page, when you click on the BlackICE Defender documentation
- hyperlink, your browser will download the documentation and display it
- via another browser window or via the Adobe Acrobat Reader directly.
- This means that you need to have Adobe Acrobat Reader installed on your
- computer. If not, the web page listed above has a link to Adobe Acrobat
- Reader download page. Download and install the reader.
-
- If you want to have a local copy of the BlackICE Defender documentation,
- you simply need to right-click on the BlackICE Defender link and opt to
- save the document to your computer's local hard disk drive.
-
-
- -----------------------------------------------------------------------
- -- Support ------------------------------------------------------------
- -----------------------------------------------------------------------
-
- BlackICE Defender 2.1.ce is an evaluation version only; as such,
- it does not include e-mail or telephone technical support.
-
- If you have have questions regarding BlackICE, you may find answers by
- visiting our on-line resources at:
-
- General : http://www.networkice.com/html/support.html
- Knowledgebase: http://advice.networkice.com/Advice/Support/KB/default.htm
- BlackICE FAQ : http://www.networkice.com/html/blackice_faq.html
-