<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>PunkBuster service try to connnect to verisign.com? in Security</title>
<link>http://www.dslreports.com/forum/r19760368</link>
<description></description>
<language>en</language>
<pubDate>Wed, 11 Nov 2009 00:31:39 EDT</pubDate>
<lastBuildDate>Wed, 11 Nov 2009 00:31:39 EDT</lastBuildDate>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19808206</link>
<description><![CDATA[<A HREF="/useremail/u/577198"><b>MAT777</b></A> : I know you guys appear to dislike old thread bump but I think it is good for everybody to know the end of this story. If I shouldn't have bump it, please tell so I won't do it again in the future.<br><br>I received the answer from evenbalance:<br><br>"Note #2: PnkBstrA shouldn't even be contacting the internet, so something is definitely not right.<br><br>Please start pbsvc.exe and run through the uninstall process. After that, run it again and run through the install process. Make sure it uninstalls/installs correctly. Reboot the computer and then try playing again. Vista users need to start it explicitly with admin rights.<br><br>Please make sure you allow the service files in security software like virus scanners and/or firewalls. You will need to allow/unblock the services PnkBstrA.exe and PnkBstrB.exe from your "C:\Windows\system32\" folder. In case of doubt, manually add both to your firewall's allow list. After the installation process you will only find PnkBstrA, so just make sure this process file is not blocked. Then try playing on a PB enabled server, in case of a kick, check if PnkBstrB was created and unblock it too."<br><br>So my firewall is bugged or a virus has infected the pb service. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19808206</guid>
<pubDate>Tue, 15 Jan 2008 18:25:27 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19762599</link>
<description><![CDATA[<A HREF="/useremail/u/577198"><b>MAT777</b></A> : https, ok, I got it now. Thanks for all this information.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19762599</guid>
<pubDate>Tue, 08 Jan 2008 16:01:02 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19762545</link>
<description><![CDATA[<A HREF="/useremail/u/340145"><b>Steve</b></A> : <div class="bquote"><small>said by  MAT777 <A HREF="/useremail/u/577198"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>But for example, when I visit my bank site, what check the ssl certificate? Firefox? </div> Your web browser checks the cert: it insures that the Common Name on the certificate matches the URL in the address line, that the cert has a chain of signing from the trusted root certs, that the cert has not expired, and that the cert has not been added to a revocation list (there are other housekeeping checks too).<br><br><b>All</b> online banking uses SSL: if you see <b>https</b> in the URL, it's using an SSL certificate.<br><br>Steve<br><small>--<br>Stephen J. Friedl | Unix Wizard | Microsoft Security MVP | Tustin, California USA | <A HREF="http://www.unixwiz.net">my web site</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19762545</guid>
<pubDate>Tue, 08 Jan 2008 15:52:51 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19762474</link>
<description><![CDATA[<A HREF="/useremail/u/577198"><b>MAT777</b></A> : But for example, when I visit my bank site, what check the ssl certificate? Firefox? <br><br>Maybe my bank don't use this, do you have an example of a site that use a ssl certificate?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19762474</guid>
<pubDate>Tue, 08 Jan 2008 15:44:10 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19762274</link>
<description><![CDATA[<A HREF="/useremail/u/340145"><b>Steve</b></A> : <div class="bquote"><small>said by  MAT777 <A HREF="/useremail/u/577198"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>What the SSL cert is useful for? Why you'd get a cert? </div> An SSL cert is an attestation of identity: if I have an SSL cert for my my website, then if the cert passes validity you can be sure that it really is my website.<br><br>You care about this when you visit your bank, insuring that they are who the URL claims them to be (I personally can't get an SSL certificate for <b>wellsfargo.com</b>).<br><br>Additionally, an application such as punkbuster may well need to phone home to get updates and the like: it needs to be sure that when it <u>thinks</u> it's hitting the made-up URL <b>update.punkbuster.com</b>, that it really is connecting to that site.<br><br>It's not out of the question to imagine somebody trying to subvert Punkbuster by setting up a fake update site and messing with local DNS, in an attempt to get the software to get a bogus update. But when the fake site is unable to produces a root-CA-signed <b>update.punkbuster.com</b> certificate, then the application knows it's not talking to the real deal.<br><br>But please note that an attestation to <b>identity</b> is not the same as an attestation to <b>safety</b> - I could set up <b>www.FreeSpywareWithPorn.com</b>, get a valid cert, and offer exactly what I claim. Just because the site is what it claims to be doesn't mean that it's safe.<br><br>Steve<br><small>--<br>Stephen J. Friedl | Unix Wizard | Microsoft Security MVP | Tustin, California USA | <A HREF="http://www.unixwiz.net">my web site</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19762274</guid>
<pubDate>Tue, 08 Jan 2008 15:11:26 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19761638</link>
<description><![CDATA[<A HREF="/useremail/u/577198"><b>MAT777</b></A> : <div class="bquote"><small>said by  Steve <A HREF="/useremail/u/340145"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>Let's say that I get an SSL cert for <b>www.unixwiz.net</b> from Verisign, <br><br> </div>If I want to understand the whole thing, I need to understand:<br>What the SSL cert is useful for? Why you'd get a cert?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19761638</guid>
<pubDate>Tue, 08 Jan 2008 13:34:39 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19761136</link>
<description><![CDATA[<A HREF="/useremail/u/340145"><b>Steve</b></A> : <div class="bquote"><small>said by  MAT777 <A HREF="/useremail/u/577198"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Do you know why pb has to check for a ssl certificate validity? </div>This is almost certainly automatic behavior by the Windows libraries, not volitional activity by punkbuster.<br><br>A CRL &mdash; Certificate Revocation List &mdash; is used to insure that certificates are still valid and have not been revoked.<br><br>When a client (which could be a browser or an application) connects to an SSL-protected resource, it verifies that the cert is valid by following the signing chain down from the roots. The result of this process is a yes/no that the cert is in fact valid.<br><br>But there is also a list of revoked certs; ones that were in fact signed (and will pass signing verification), but should nevertheless be considered invalid.<br><br>Let's say that I get an SSL cert for <b>www.unixwiz.net</b> from Verisign, but I foolishly allow a bad guy to get my private key and passphrase. That means he can use that cert on a fake www.unixwiz.net website. Oh snap!<br><br>So I'll <b>revoke</b> my certificate, which gets it put on the list maintained by crl.verisign.com. So when the Win32 secure-socket libraries verify a cert, it checks the root signing chain <b>and</b> to see if that cert is on the revocation list.<br><br>So it's unlikely that Punkbuster is doing anything but calling a Win32-provided library to set up a secure connection, and the library is doing all the heavy lifting.<br><br>Steve<br><small>--<br>Stephen J. Friedl | Unix Wizard | Microsoft Security MVP | Tustin, California USA | <A HREF="http://www.unixwiz.net">my web site</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19761136</guid>
<pubDate>Tue, 08 Jan 2008 12:18:42 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19760873</link>
<description><![CDATA[<A HREF="/useremail/u/577198"><b>MAT777</b></A> : So if I understand well, maybe pb is checking if the exe has not been hacked(forged?) on that site? That's how pb detect cheating? Looking at the amount of cheaters, this doesn't appear to work well  :D<br><br>Is this the same certificate windowsxp ask you sometimes when you install driver?<br><br>Nice information btw, when I read this: "A few years ago they implemented a change to their service such that if a mis-typed address could not be found in their database, you would be redirected to their own search engine." <br>I think they prove they it could be a spyware. I'm waiting for evenbalance to know if it is a normal activity or if my pb exe was infected by a virus.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19760873</guid>
<pubDate>Tue, 08 Jan 2008 11:35:19 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19760793</link>
<description><![CDATA[<A HREF="/useremail/u/707666"><b>jimkyle</b></A> : Verisign was originally known as Network Solutions Inc., and was the original issuer of almost all URL names. It's still the registrar for *.com domains; if you have a dot-com domain registered anywhere else, your registrar is simply acting as Verisign's agent.<br><br>However the company's hat is not pure white. A few years ago they implemented a change to their service such that if a mis-typed address could not be found in their database, you would be redirected to their own search engine. This caused a firestorm of controversy and they undid their change. However many of us still do not trust the firm completely; the feeling was (and is) that any violation of the standards indicates that future violations may occur.<br><br>The reason any program would contact them to verify that a certificate is valid is that the program is "signed" by its maker to assure that it has not been forged. Some operating systems refuse to allow an unsigned program to install or run, but the only way to verify a program signature is to check it out with the original provider -- in this case Verisign.<br><small>--<br>Jim Kyle</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19760793</guid>
<pubDate>Tue, 08 Jan 2008 11:22:00 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19760543</link>
<description><![CDATA[<A HREF="/useremail/u/601391"><b>Mats</b></A> : No they arent..<br><br>I could never give you an explanation that you would understand.. Hopefully someone will come in soon who can..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19760543</guid>
<pubDate>Tue, 08 Jan 2008 10:40:14 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19760518</link>
<description><![CDATA[<A HREF="/useremail/u/577198"><b>MAT777</b></A> : <div class="bquote"><small>said by  Mats <A HREF="/useremail/u/601391"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  MAT777 <A HREF="/useremail/u/577198"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>Ok, and what is verisign <br><br> </div>&raquo;<A HREF="http://en.wikipedia.org/wiki/VeriSign" >en.wikipedia.org/wiki/VeriSign</A><br> </div>Yes I have read this before coming here. <br><br>"VeriSign also provides a variety of security and telecom services"<br><br>This is kind of vast to know what they do. Are they a ad/spyware compagny under the cover of ssl certificate?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19760518</guid>
<pubDate>Tue, 08 Jan 2008 10:35:45 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19760496</link>
<description><![CDATA[<A HREF="/useremail/u/577198"><b>MAT777</b></A> : <div class="bquote"><small>said by  NetFixer <A HREF="/useremail/u/1030204"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Th IP address you posted is one of several crl.verisign.com addresses which are used to check SSL certificate validity.<br> </div>Do you know why pb has to check for a ssl certificate validity?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19760496</guid>
<pubDate>Tue, 08 Jan 2008 10:33:29 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19760497</link>
<description><![CDATA[<A HREF="/useremail/u/601391"><b>Mats</b></A> : <div class="bquote"><small>said by  MAT777 <A HREF="/useremail/u/577198"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Ok, and what is verisign <br><br> </div>&raquo;<A HREF="http://en.wikipedia.org/wiki/VeriSign" >en.wikipedia.org/wiki/VeriSign</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19760497</guid>
<pubDate>Tue, 08 Jan 2008 10:33:29 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19760487</link>
<description><![CDATA[<A HREF="/useremail/u/1030204"><b>NetFixer</b></A> : Th IP address you posted is one of several crl.verisign.com addresses which are used to check SSL certificate validity.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19760487</guid>
<pubDate>Tue, 08 Jan 2008 10:31:06 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19760458</link>
<description><![CDATA[<A HREF="/useremail/u/577198"><b>MAT777</b></A> : <div class="bquote"><small>said by  Mats <A HREF="/useremail/u/601391"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  MAT777 <A HREF="/useremail/u/577198"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>Maybe pb always connected to verisign in the past and I didn't notice it because I allowed pb to accces the net. And when it got updated, my firewall detected it.<br> </div>This is correct..<br><br>Your firewall detected the change to punkbuster program..<br> </div>Ok, and what is verisign and what pb has to do with it? You have an idear?<br><br>btw, I sent a ticket to evenbalance to know if this is a normal activity for pb or not. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19760458</guid>
<pubDate>Tue, 08 Jan 2008 10:27:00 EDT</pubDate>
</item>

<item>
<title>Re: PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19760395</link>
<description><![CDATA[<A HREF="/useremail/u/601391"><b>Mats</b></A> : <div class="bquote"><small>said by  MAT777 <A HREF="/useremail/u/577198"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Maybe pb always connected to verisign in the past and I didn't notice it because I allowed pb to accces the net. And when it got updated, my firewall detected it.<br> </div>This is correct..<br><br>Your firewall detected the change to punkbuster program..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19760395</guid>
<pubDate>Tue, 08 Jan 2008 10:18:45 EDT</pubDate>
</item>

<item>
<title>PunkBuster service try to connnect to verisign.com?</title>
<link>http://www.dslreports.com/forum/remark,19760368</link>
<description><![CDATA[<A HREF="/useremail/u/577198"><b>MAT777</b></A> : My firewall has detected a change in PnkBstA.exe. And now, It try to connect to this ip: 199.7.54.190. The domain of this IP is &raquo;<A HREF="http://www.verisign.com/" >www.verisign.com/</A>.<br><br>Is verisign a spyware/ads site? <br><br>Maybe pb always connected to verisign in the past and I didn't notice it because I allowed pb to accces the net. And when it got updated, my firewall detected it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19760368</guid>
<pubDate>Tue, 08 Jan 2008 10:14:54 EDT</pubDate>
</item>

</channel>
</rss>
