Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PCAPdroid block Eset Endpoint Security virus signature updates. #442

Open
moakt3 opened this issue May 22, 2024 · 4 comments
Open

PCAPdroid block Eset Endpoint Security virus signature updates. #442

moakt3 opened this issue May 22, 2024 · 4 comments
Labels
question User is asking a question to be confirmed

Comments

@moakt3
Copy link

moakt3 commented May 22, 2024

Hi.
I have a problem with Eset Endpoint Security (enterprise antivirus for android) signatures updates. PCAPdroid fully block it even with outgoing rule for app. Disabling firewall not help. Only fully stop help. There is no even dns request in conection tab when try update.

PS: Eset online app activation and another netwotk services work fine with working PCAPdroid with firewall.

LineageOS 14.1 (Android 7.1.2)

Please help.

@emanuele-f
Copy link
Owner

Hello,
Based on your information it seems like the AV may be detecting that a VPN is active and refuse to run the update via it. You can try to:

  • exclude the AV app from the capture (VPN): in the PCAPdroid settings, add the AV app to the "VPN Exemptions"
  • alternatively, capture in root mode, however you won't be able to use the PCAPdroid firewall to block connections

@emanuele-f emanuele-f added the question User is asking a question label May 23, 2024
@moakt3
Copy link
Author

moakt3 commented May 23, 2024

Nope. I try two different firewall's with vpn filtering methods. Eset update work fine. Moreover i'm install Android 5 (OS from the box) and Eset update work fine with PCAPdroid. I think there is some incompatibility with PCAPdroid and LineageOS.

PS: I can't exclude Eset from firewalling because blocking some Eset app telemetry hosts.

@emanuele-f
Copy link
Owner

Have you tried with a fresh PCAPdroid install, e.g. flushing the app data? There could be some rule or setting which may affect the AV. I'm not aware of specific issues linked to LineageOS, but maybe you can try with another rom

@moakt3
Copy link
Author

moakt3 commented May 24, 2024

Many times. Eset always show "No internet connection".
All custom OS for my phone forked from LineageOS. I try AOKP. Results the same.

Eset for updates use 80 port. Maybe this is some conflict with PCAPdroid. All others Eset services use 443 port.

...or maybe this a problem with a dns resolving in PCAPdroid. There is no dns request at all when i try update Eset. All SSL/TLC connections hardcoded inside Eset and can connect without resolving. Just a guess, but ...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question User is asking a question to be confirmed
Projects
None yet
Development

No branches or pull requests

2 participants