The Gold Road Chapter – which includes the Scribing system – and Update 42 is now available to test on the PTS! You can read the latest patch notes here: https://forums.elderscrollsonline.com/en/discussion/656454/
Maintenance for the week of April 22:
• [COMPLETE] PC/Mac: NA and EU megaservers for patch maintenance – April 22, 4:00AM EDT (08:00 UTC) - 9:00AM EDT (13:00 UTC)
• Xbox: NA and EU megaservers for patch maintenance – April 24, 6:00AM EDT (10:00 UTC) - 12:00PM EDT (16:00 UTC)
• PlayStation®: NA and EU megaservers for patch maintenance – April 24, 6:00AM EDT (10:00 UTC) - 12:00PM EDT (16:00 UTC)

Any one know why this is flagged as a trojan in my firewall?

makasouleater420
06/27/2019
07:18:17 1 TCP A Network Trojan was Detected 64.246.134.42
80 192.168.1.250
62124 1:2008438
ET TROJAN Possible Windows executable sent when remote host claims to send a Text File

This is 100 percent ESO launcher. I unblock that one, it makes it through that update part starting to download eso,but it ends up flagging another, and another thing in my firewall. I was gonna give this another try, but I dont really want to spend hours letting eso through my firewall lol. Any one got any idea why ESO is flagged so many times under the rules created by these people?

Install ETOpen Emerging Threats rules ETOpen is a free open source set of Suricata rules whose coverage is more limited than ETPro.

The Snort Community Ruleset is a GPLv2 Talos-certified ruleset that is distributed free of charge without any Snort Subscriber License restrictions.

Those 2 rule sets are what is flagging ESO. I suppose not to many people have this problem, since they just use a basic firewall from like ausu which doesnt use a attack prevention system like suricata or snort, but you would think a billion dollar corporation would figure out how to not get flagged as a trojan by suricata. World of warcraft does not get flagged, either does steam.

My only guess is they use this garbage, and dont have their own.

Akamai | The Intelligent Edge Platform | akamai.com‎

My firewall flags that alot, and seems to be used by alot of ads, and other nefarious people. Also why is a billion dollar corporation like ESO using DSL/Cable haha.

ISP / Organization INOC Data Centers
IP Connection Type Cable/DSL [internet speed test]
IP Location Waterford, New York, 12188, United States
IP Continent North America
IP Country United States (US)
IP State New York (NY)
IP City Waterford
IP Postcode 12188
IP Latitude 42.8100 / 42°48′36″ N
IP Longitude -73.6995 / 73°41′58″ W
IP Timezone America/New_York
IP Local Time Thu, 27 Jun 2019 07:27:42 -0400
Edited by makasouleater420 on June 27, 2019 11:35AM
  • RinaldoGandolphi
    RinaldoGandolphi
    ✭✭✭✭✭
    ✭✭✭✭
    As someone who manages quite a few commercial PfSense Netgate appliances as well as multiple Snort Cisco Talos Business Subscription based plans, and also run Emerging Threats Open Rules and IP lists for many years. I can tell you those rules are correct, but the usage isn't.

    Cisco Talos, Emerging Threats, and Snort Open rules are designed to be used in a business/corporate environment. They are not really meant or designed for home use. It is flagging ESO because in a corporate or business environment an IT administrator would want to know if someone is using their network in a manner that isn't consistent with company policy. So playing ESO for example would violate most corporate/government policy on network use, thus would be classified as network abuse which falls under the classification of a trojan. So Emerging Threats is correct.

    Unless you have very very specific requirements such as running a business from your home, hosting specific services to the internet such as web and mail servers, VPN tunnels, etc running Snort on a home network really isn't necessary. I know a few of my colleagues and myself that run Netgate devices at home, but we don't use the Snort functions simply because they are not necessary for our use case. Netgate standard Firewall and rules is more than sufficient and keeps people out.

    By default in IPv4, NAT blocks all incoming network requests from the WAN that don't have an entry in the state table from a device behind it(LAN), so if your not forwarding any ports, no IP can connect to a computer behind a NAT firewall unless a system on your LAN has specifically initiated an outbound connection to that IP. Most IPv6 capable routers now have some similar functionality, its not quite NAT, but in the case of my internet gateway is an IPv6 firewall that acts as a statefull firewall much like IPv4 devices NAT.

    If you are happy with Snort and think you need it, then continue to use it. I am not here to discouraging you from using something that you are happy with. I was just trying to give some insight.

    another option to consider is Comodo Firewall. Its free and VERY robust, but it is not for the faint of heart. Its default config is pretty lax, but dig into its settings it has a plethora of options that may end up being a better fit.

    For example, for unknown programs you can run them a virtualized secure container where they can't may any changes to your system ot access your data, if you end up trusting the program you cna move it out of the virtualized box, if you end up not trusting it, you can dump the virtual box and no changes are made to your system. Its pretty extensive, and for the security mind with it being free it may be something you want to use or even supplement your Snort with.

    https://personalfirewall.comodo.com/

    Good day

    Rinaldo
    Rinaldo Gandolphi-Breton Sorcerer Daggerfall Covenant
    Juste Gandolphi Dark Elf Templar Daggerfall Covenant
    Richter Gandolphi - Dark Elf Dragonknight Daggerfall Covenant
    Mathias Gandolphi - Breton Nightblade Daggerfall Covenant
    RinaldoGandolphi - High Elf Sorcerer Aldmeri Dominion
    Officer Fire and Ice
    Co-GM - MVP



    Sorcerer's - The ONLY class in the game that is punished for using its class defining skill (Bolt Escape)

    "Here in his shrine, that they have forgotten. Here do we toil, that we might remember. By night we reclaim, what by day was stolen. Far from ourselves, he grows ever near to us. Our eyes once were blinded, now through him do we see. Our hands once were idle, now through them does he speak. And when the world shall listen, and when the world shall see, and when the world remembers, that world will cease to be. - Miraak

  • makasouleater420
    As someone who manages quite a few commercial PfSense Netgate appliances as well as multiple Snort Cisco Talos Business Subscription based plans, and also run Emerging Threats Open Rules and IP lists for many years. I can tell you those rules are correct, but the usage isn't.

    Cisco Talos, Emerging Threats, and Snort Open rules are designed to be used in a business/corporate environment. They are not really meant or designed for home use. It is flagging ESO because in a corporate or business environment an IT administrator would want to know if someone is using their network in a manner that isn't consistent with company policy. So playing ESO for example would violate most corporate/government policy on network use, thus would be classified as network abuse which falls under the classification of a trojan. So Emerging Threats is correct.

    Unless you have very very specific requirements such as running a business from your home, hosting specific services to the internet such as web and mail servers, VPN tunnels, etc running Snort on a home network really isn't necessary. I know a few of my colleagues and myself that run Netgate devices at home, but we don't use the Snort functions simply because they are not necessary for our use case. Netgate standard Firewall and rules is more than sufficient and keeps people out.

    By default in IPv4, NAT blocks all incoming network requests from the WAN that don't have an entry in the state table from a device behind it(LAN), so if your not forwarding any ports, no IP can connect to a computer behind a NAT firewall unless a system on your LAN has specifically initiated an outbound connection to that IP. Most IPv6 capable routers now have some similar functionality, its not quite NAT, but in the case of my internet gateway is an IPv6 firewall that acts as a statefull firewall much like IPv4 devices NAT.

    If you are happy with Snort and think you need it, then continue to use it. I am not here to discouraging you from using something that you are happy with. I was just trying to give some insight.

    another option to consider is Comodo Firewall. Its free and VERY robust, but it is not for the faint of heart. Its default config is pretty lax, but dig into its settings it has a plethora of options that may end up being a better fit.

    For example, for unknown programs you can run them a virtualized secure container where they can't may any changes to your system ot access your data, if you end up trusting the program you cna move it out of the virtualized box, if you end up not trusting it, you can dump the virtual box and no changes are made to your system. Its pretty extensive, and for the security mind with it being free it may be something you want to use or even supplement your Snort with.

    https://personalfirewall.comodo.com/

    Good day

    Rinaldo



    This is the corporate one not Trojans ,you think a Trojan, and corporate policy violations are the same?
    06/27/2019
    07:18:17 1 TCP Potential Corporate Privacy Violation 64.246.134.42
    80 192.168.1.250
    62124 1:2018959
    ET POLICY PE EXE or DLL Windows file download HTTP


    A Trojan horse, or Trojan, is a type of malicious code or software that looks legitimate but can take control of your computer.

    That is what a Trojan is, and that does not fit that classification.

    It slightly explains it, saying something about a text file but getting a exe, which prolly has to do with the patcher and it using it for what it needs to download. None of which expalins why ESO cant figure out how to not get flagged as a trojan, and a trojan is not a corporate policy violation.

    As i said Steam, WOW, Ryzom, GOG, and a bunch of others dont get flagged as trojans.

    I never gave you any information about why I used pfsense, or suricata, so why would you even assume you know what i wanted it for, then give me suggestions like that. Clearly if you think a network trojan and a corporate policy violation are the same, I dont think you should be giving advice to any one.

    Also why are you explaining basic firewall rules to me like i didnt already know that haha. I mean seriously, you dont think i got pfsense installed, and running suricata, with out knowing this do you? The main reason I use it, is because all routers are garbage, and cant handle even downloading off of steam with a 150 mbps plus off of steam with out skipping. I wanted a 5ghz 8700k router with 12 gbs of ram. Suricata blocks all sorts of things that are fun to watch, not just corporate policy things, pfsense also lets me block all countries but the USA which is helpful for when I run game servers. None of which has anything to do with why ESO launcher gets flagged as a trojan.


    "By default in IPv4, NAT blocks all incoming network requests from the WAN that don't have an entry in the state table from a device behind it(LAN), so if your not forwarding any ports, no IP can connect to a computer behind a NAT firewall unless a system on your LAN has specifically initiated an outbound connection to that IP. Most IPv6 capable routers now have some similar functionality, its not quite NAT, but in the case of my internet gateway is an IPv6 firewall that acts as a statefull firewall much like IPv4 devices NAT."

    So I am gonna assume like you do, why are you calling me a ***? Also what does ipv6 have to do with anything, all routers are ipv6 capable. There is not going to be a modern router that cant use ipv6.

    I asked a simple question, why does ESO get flagged as a trojan. You gave me a bunch of nonsense that has nothing to do with anything other than your personal opinion.

    It would be like me asking what are the single core speed numbers of a 9600k at 5ghz, and you going NO ONE NEEDS 5 GHZ use ryzen its better haha.

    Here is another corporate violation from lord of the rings, not a network trojan.

    06/27/2019
    12:15:18 1 TCP Potential Corporate Privacy Violation 64.246.134.41
    80 192.168.1.250
    56433 1:2018959
    ET POLICY PE EXE or DLL Windows file download HTTP

    Edited by makasouleater420 on June 27, 2019 4:18PM
  • makasouleater420
    There is another MMo that doesnt flag it as a trojan, and this is a horrid russian company to lol, Lord of the rings online. Something is wrong with elder scrolls online 100 percent.

    World of warcraft
    Lord of the rings online
    Ryzom
    All steam games
    Heroes of the storm
    Minecraft
    starbound
    xbox one downloads

    All do not get flagged as Trojans, just elder scrolls online. Not even worth downloading this. If they cant even figure out how to not get their downloader flagged as a network trojan, cant imagine them being able to stop hackers, botters, cheaters and the rest of the bad ***. Especially when a low player based game, owned by the most courpt mmo company in the world day break games managed to do it lol.

    Then add in the fact I couldnt even get ESO to not just keep getting reblocked even with allowing the ip, and unblocking the network trojan, it would download about 100mbs and stop, and throw more flags. No other mmo, or game site does this to the firewall.
    Edited by makasouleater420 on June 27, 2019 4:24PM
  • Nestor
    Nestor
    ✭✭✭✭✭
    ✭✭✭✭✭
    I have 1000s of hours with this game over the last 5 years, no Trojans on my machine.

    Most people run some kind of firewall and this game and do not have any issue.

    But I guess your Enterprise Firewall being used in an enviorment it is not designed for throwing up false flags is cause for alarm.

    No one has reported ESO as being a trojan before, and Google only shows you as reporting this as a trojan.

    @RinaldoGandolphi knows his stuff. You can ignore it or heed it, but don't call him names or insult him because he does not agree with you
    Enjoy the game, life is what you really want to be worried about.

    PakKat "Everything was going well, until I died"
    Gary Gravestink "I am glad you died, I needed the help"

  • makasouleater420
    Nestor wrote: »
    I have 1000s of hours with this game over the last 5 years, no Trojans on my machine.

    Most people run some kind of firewall and this game and do not have any issue.

    But I guess your Enterprise Firewall being used in an enviorment it is not designed for throwing up false flags is cause for alarm.

    No one has reported ESO as being a trojan before, and Google only shows you as reporting this as a trojan.

    @RinaldoGandolphi knows his stuff. You can ignore it or heed it, but don't call him names or insult him because he does not agree with you

    I never said i thought it was a actual trojan, it is a flase flag 100 percent, thats not the point. The point is they first use a 3rd party for their servers, and second they are so *** poor, they cant figure out how to not get it flagged as a trojan, when no other major mmo does. Even minor mmos dont.

    When did i call him names, he called me ***. As for him knowing his stuff i doubt that, he told me a trojan flag in a fw is the same thing as a corporate violation then told me to go get a new firewall lol. Why are you defending him anyways haha, he didnt ask you to I am sure he is a big boy and can respond if he wanted to. Unlike you I dont believe any one unless they have numbers and facts.You just apparently think highly of him and let that blind you to reality, even if he was wrong you would defend him.

    The fact remains, eso is so *** poor they get flagged as a trojan when no one else does, uses third party cloud services instead of ruinning their own.

    Edited by makasouleater420 on June 27, 2019 5:43PM
  • SirAndy
    SirAndy
    ✭✭✭✭✭
    ✭✭✭✭✭
    EXE or DLL Windows file download HTTP

    Whoever designed the ESO launcher and its update mechanisms needs to fired and blacklisted to never ever get a job in the industry ever again.

    It has been a mess since day one, downloading way too much data for small updates because patch data is bundled in chunks and they never figured out how to do small incremental or targeted updates. If even just a single byte changes in a data chunk, the whole block has to be downloaded again.

    And don't get me started about sending binary data (that isn't base64 encoded) through a http port. Seems like a good idea to the intern fresh out of school "Hey, don't most people have port 80 open? Lets just use that!". Probably the same person who designed the launcher.
    headbang.gif

  • Nestor
    Nestor
    ✭✭✭✭✭
    ✭✭✭✭✭
    And I thought everyone knew to only use the Launcher on Patch days....

    Ok, maybe you did not, so, here is your announcement. Make a shortcut to the ESO64.EXE and use that for the game. Do not use the Launcher except if you have to patch the game, or change servers. Note, if you have Steam, disable the auto login and have Steam running before you do this.

    Most everyone uses a shortcut to the exe to launch the game. I am sure those false flags are related to the Patch Manifest errors that propagate out from that thing.
    Edited by Nestor on June 27, 2019 6:32PM
    Enjoy the game, life is what you really want to be worried about.

    PakKat "Everything was going well, until I died"
    Gary Gravestink "I am glad you died, I needed the help"

  • RinaldoGandolphi
    RinaldoGandolphi
    ✭✭✭✭✭
    ✭✭✭✭
    @Nestor Thank you, I appreciate your kind words. Hope you have been well since I haven't been around much lately.

    @makasouleater420

    Take it easy there buddy. I was just trying to give you insight, nothing more nothing less. I never called you anything.

    I was explaining basic firewall rules to you because I wasn't sure what your competency level was. Since we don't know each other personally there is no way I can know how proficient you are in something over a brief post on an internet forum. I have known people in the past that have ran Snort setups at home that have no clue about it because it was sold to them by someone else peddling a product they didn't need. It seems that isn't the case for you, so good.

    As for your classification of "Trojan" that depends. Corporate Privacy Violations and Trojans are often very closely related and often go hand-in-hand in a business environment. Mining bitcoins itself isn't nefarious for example, but using company resources without their knowledge to mine bitcoins ends up becoming a trojan.(cryptojacking)

    Any abuse or misuse of a company or an organizations bandwidth, network, or hardware without approval could be classified as a trojan, policy violation, and many times both. Playing games on a company network unauthorized is just as bad as cryptojacking, both use resources in an unauthorized manner.

    Also as an FYI, but 216 of the Snort GPL Community Open Ruleset were written by me or I collaborated with others in the Snort community to help create them. Also, up until last year I was a big contributor to the Emerging threats Open Rule set and Snort GPL, and have collaborated with those communities for years.

    Since I am in a position to know, the ET TROJAN/ET Network Trojan Detected rules are like "catch-all rules" for network related activities that don't quite fit the classic Trojan or Corporate Policy Violation specific rules. Since there is no specific rules for ESO, it has network activity that "could maybe" be a Trojan or unwanted, but it doesn't mean it is. It could easily just be something the company doesn't want running on its network that isn't nefarious in itself such as computer games. Those rules are meant to be tuned or suppressed on a case by case basis depending on the needs of the company or organization. These detections can be akin to Symantec's WS.Reputation1 detection, or ML.Attribute.HighConfidence. These detections themselves are not necessarily bad, but they may do things a company wouldn't want whereas a home user would be ok with.

    As I said, Snort was designed for business and corporate use, and most of the Open Source rules are written by IT Professionals like myself, and used in numerous business and enterprise daily. If you look at them from that viewpoint, its easier to understand why they fire on certain things.

    Emerging Threats is correct to classify ESO under the catch all ET Trojan rules because the rules are written with a focus on enterprise security, and network monitoring. If an employee was playing ESO on company time, company equipment, and using company network resources, any IT manger worth his salt would want to know about it, hence those rules. If you join their mailing lists, they will tell you the same thing I am telling you. If you want a specific rule for ESO so you can suppress it, then write the rule yourself, submit it to ET and see if they approve it. Otherwise, just suppress the rule.

    Im not here to argue with you, and I did not insinuate or call you anything. As my friends on the ET/Snort mailing list would say, this discussion has probably ran its course. The tone is counter productive and not really any need to continue with it.

    Take care.



    Rinaldo Gandolphi-Breton Sorcerer Daggerfall Covenant
    Juste Gandolphi Dark Elf Templar Daggerfall Covenant
    Richter Gandolphi - Dark Elf Dragonknight Daggerfall Covenant
    Mathias Gandolphi - Breton Nightblade Daggerfall Covenant
    RinaldoGandolphi - High Elf Sorcerer Aldmeri Dominion
    Officer Fire and Ice
    Co-GM - MVP



    Sorcerer's - The ONLY class in the game that is punished for using its class defining skill (Bolt Escape)

    "Here in his shrine, that they have forgotten. Here do we toil, that we might remember. By night we reclaim, what by day was stolen. Far from ourselves, he grows ever near to us. Our eyes once were blinded, now through him do we see. Our hands once were idle, now through them does he speak. And when the world shall listen, and when the world shall see, and when the world remembers, that world will cease to be. - Miraak

  • RinaldoGandolphi
    RinaldoGandolphi
    ✭✭✭✭✭
    ✭✭✭✭
    SirAndy wrote: »
    EXE or DLL Windows file download HTTP

    Whoever designed the ESO launcher and its update mechanisms needs to fired and blacklisted to never ever get a job in the industry ever again.

    It has been a mess since day one, downloading way too much data for small updates because patch data is bundled in chunks and they never figured out how to do small incremental or targeted updates. If even just a single byte changes in a data chunk, the whole block has to be downloaded again.

    And don't get me started about sending binary data (that isn't base64 encoded) through a http port. Seems like a good idea to the intern fresh out of school "Hey, don't most people have port 80 open? Lets just use that!". Probably the same person who designed the launcher.
    headbang.gif

    Agreed, the Launcher has always been a complete mess. Funny how many things change yet still remain the same.
    Rinaldo Gandolphi-Breton Sorcerer Daggerfall Covenant
    Juste Gandolphi Dark Elf Templar Daggerfall Covenant
    Richter Gandolphi - Dark Elf Dragonknight Daggerfall Covenant
    Mathias Gandolphi - Breton Nightblade Daggerfall Covenant
    RinaldoGandolphi - High Elf Sorcerer Aldmeri Dominion
    Officer Fire and Ice
    Co-GM - MVP



    Sorcerer's - The ONLY class in the game that is punished for using its class defining skill (Bolt Escape)

    "Here in his shrine, that they have forgotten. Here do we toil, that we might remember. By night we reclaim, what by day was stolen. Far from ourselves, he grows ever near to us. Our eyes once were blinded, now through him do we see. Our hands once were idle, now through them does he speak. And when the world shall listen, and when the world shall see, and when the world remembers, that world will cease to be. - Miraak

  • Cathexis
    Cathexis
    ✭✭✭✭✭
    SirAndy wrote: »
    EXE or DLL Windows file download HTTP

    Whoever designed the ESO launcher and its update mechanisms needs to fired and blacklisted to never ever get a job in the industry ever again.

    It has been a mess since day one, downloading way too much data for small updates because patch data is bundled in chunks and they never figured out how to do small incremental or targeted updates. If even just a single byte changes in a data chunk, the whole block has to be downloaded again.

    And don't get me started about sending binary data (that isn't base64 encoded) through a http port. Seems like a good idea to the intern fresh out of school "Hey, don't most people have port 80 open? Lets just use that!". Probably the same person who designed the launcher.
    headbang.gif

    Agreed, the Launcher has always been a complete mess. Funny how many things change yet still remain the same.

    Ya back up your game because at this point, you will never get another copy from the server.

    "100gb download you say? .5mbps/s should be no problem." -ESO Launcher
    The Tomb of FPS Alteration Magic - Everything You Need to Know About FPS
    https://forums.elderscrollsonline.com/en/discussion/520903/tomb-of-fps-alteration-magic-everything-you-need-to-know-about-fps
    Praise Malacath.
  • aeowulf
    aeowulf
    ✭✭✭✭✭
    Lotro gets flagged on ubiquiti IDS/IPS, ESO I don’t recall seeing. Different products, different results. If you run anything like this at home you should be happy with tuning it yourself or removing the product.
    Edited by aeowulf on October 27, 2019 9:47AM
Sign In or Register to comment.