Jump to content

Recommended Posts

Posted
Oh dear - doesn't look like we'll get anything anytime soon!

 

Thanks for showing him the Hyper-v issue - interesting that they know about it too. And thanks for going through all that testing on yours and everyone's behalf.

 

Don't know what else to say.

 

----Update------

 

Sophos Platinum Support have now been given my direct number as I was told they want to contact me to see the problem in manual/script installs. Worth a try - I'm staring at the phone now waiting!

 

What's interesting is that if we install SOPHOS "manually" by running the installers from the S:\Setups directory it appears to install OK - albeit the EXE's do not remove themselves from the list of running processes.

 

Could you share with me your manual installation method so we can see if we can replicate here?

Posted
What's interesting is that if we install SOPHOS "manually" by running the installers from the S:\Setups directory it appears to install OK - albeit the EXE's do not remove themselves from the list of running processes.

 

Could you share with me your manual installation method so we can see if we can replicate here?

 

 

I'll do my best. If we run SIMSInfrastructureSetup.exe (this is required for the Borland Engine components), SIMSapplicationsetup.exe, SimsManualSetup.exe & SimsAMPARKsetup.exe individually, they run fine. Sims won't run afterwards because they don't create a connect.ini or Sims.ini file (you either have to do these manually or copy from server) and then SIMS works.

 

If you run SIMSInst.exe however, this is what runs all the above applications and takes care of the connect.ini and Sims.ini files - this fails for us as the SimsInfrastructureSetup.exe as it thinks it needs to install AdobeReader X, but we have AdobeReader DC installed already - click next and it hangs.

 

We actually deploy SIMS.net with a GPS script which runs all the components above (apart from SIMSinst.exe as we get the script to sort out the connect.ini etc), but this again hangs at the infrastructuresetup.exe.

 

All these components are on our servers in a share called SimsSetups (which is the sims setups folder containing all the necessary release files).

 

Disable Intercept X - then all our install methods work as normal.

 

Bizarre!

  • Thanks 1
Posted

Thanks for the update Kenny.

 

My biggest concern now is the impending SIMS upgrade. As Sophos is stopping SIMSApplicationSetup from running then we can be pretty certain that the upgrade is going to fail which is going to be a right pain in the ar*e arrggghhh!

Posted
Thanks for the update Kenny.

 

My biggest concern now is the impending SIMS upgrade. As Sophos is stopping SIMSApplicationSetup from running then we can be pretty certain that the upgrade is going to fail which is going to be a right pain in the ar*e arrggghhh!

 

Right with you there - Will be chaos all over our borough.

Posted
I'll do my best. If we run SIMSInfrastructureSetup.exe (this is required for the Borland Engine components), SIMSapplicationsetup.exe, SimsManualSetup.exe & SimsAMPARKsetup.exe individually, they run fine. Sims won't run afterwards because they don't create a connect.ini or Sims.ini file (you either have to do these manually or copy from server) and then SIMS works.

 

If you run SIMSInst.exe however, this is what runs all the above applications and takes care of the connect.ini and Sims.ini files - this fails for us as the SimsInfrastructureSetup.exe as it thinks it needs to install AdobeReader X, but we have AdobeReader DC installed already - click next and it hangs.

 

We actually deploy SIMS.net with a GPS script which runs all the components above (apart from SIMSinst.exe as we get the script to sort out the connect.ini etc), but this again hangs at the infrastructuresetup.exe.

 

All these components are on our servers in a share called SimsSetups (which is the sims setups folder containing all the necessary release files).

 

Disable Intercept X - then all our install methods work as normal.

 

Bizarre!

 

Just comparing your method on a PC with and without hitmanpro running so I can send off process monitor logs to Sophos....

Posted (edited)

I've had a response from Capita just now...

 

 

Good morning Alex,

A root cause of the deployment issue has been found. Please review the below statement provided via: https://myaccount.capita-cs.co.uk/hot-topics/SIMS-Technical/

10/11/2017 - SIMS Installers blocked by Sophos Anti Virus

We’ve recently been made aware by some schools using a component of SOPHOS Endpoint Security, Intercept X 3.6.9, that is causing a problem installing SIMS via SOLUS 3 or manually running SIMSInst executable. The Intercept X component holds open the SIMS installation executable files preventing them from moving onto the next installer. Through internal testing, this is not a problem with our installers. Our installer files are digitally signed, and if you run the files manually(SIMSApplicationSetup.exe, SIMSManualSetup.exe, SIMSAMPARKSetup.exe), these install correctly. It is only being blocked when the SIMSInst.exe or SOLUS 3 deployment is trying to run these installers silently in the background. We would recommend raising an incident with SOPHOS support for further investigation.

Thank you and kind regards,

 

:doh:

 

Edit:

 

My response:

 

Good Morning,

 

Thanks for the update, unfortunately I don’t believe the statement holds true.

 

If you run the SIMSApplicationSetup, Ampark or Manual EXE manually (i.e. without SIMSinst or SOLUS) the EXE is still held open in the background and does not get closed even after the installation is complete.

 

Furthermore, this is likely to cause serious issues for the SIMS Upgrade as no doubt the same issue will occur when deploying the upgrade. Many schools will be using Sophos that simply haven’t spotted the issue yet as they haven’t had to roll out to a new machine. Surely Capita should be doing more to resolve the issue i.e. be in discussion with Sophos themselves etc?

 

We have already logged a call with Sophos.

 

I look forward to your response etc.

Edited by MrMat
  • Thanks 1
Posted
I've had a response from Capita just now...

 

 

Good morning Alex,

A root cause of the deployment issue has been found. Please review the below statement provided via: https://myaccount.capita-cs.co.uk/hot-topics/SIMS-Technical/

10/11/2017 - SIMS Installers blocked by Sophos Anti Virus

We’ve recently been made aware by some schools using a component of SOPHOS Endpoint Security, Intercept X 3.6.9, that is causing a problem installing SIMS via SOLUS 3 or manually running SIMSInst executable. The Intercept X component holds open the SIMS installation executable files preventing them from moving onto the next installer. Through internal testing, this is not a problem with our installers. Our installer files are digitally signed, and if you run the files manually(SIMSApplicationSetup.exe, SIMSManualSetup.exe, SIMSAMPARKSetup.exe), these install correctly. It is only being blocked when the SIMSInst.exe or SOLUS 3 deployment is trying to run these installers silently in the background. We would recommend raising an incident with SOPHOS support for further investigation.

Thank you and kind regards,

 

:doh:

 

I'll sent that to SOPHOS!

  • Thanks 1
Posted
That comment from CAPITA seems to hold true "It is only being blocked when the SIMSInst.exe or SOLUS 3 deployment is trying to run these installers silently in the background". Our deployment script runs the install components individually but silently and with InterceptX enabled, it fails. Running each component manually, they install fine.
Posted
That comment from CAPITA seems to hold true "It is only being blocked when the SIMSInst.exe or SOLUS 3 deployment is trying to run these installers silently in the background". Our deployment script runs the install components individually but silently and with InterceptX enabled, it fails. Running each component manually, they install fine.

 

They do install fine but (for us at least), the actual installer remains open in the background.

 

I've just been checking in Task Manager - Details. You can see the installer still running.

Posted
They do install fine but (for us at least), the actual installer remains open in the background.

 

I've just been checking in Task Manager - Details. You can see the installer still running.

 

Yes, we get that too.

Posted
Yes, we get that too.

 

I suppose it doesn't really cause an issue but i thought it was worth highlighting to Capita incase they were missing something. :)

Posted
I think sending them anything is worthy at the moment for them to get all angles on what's happening. It's bizarre why these install files get blocked/kept open!
Posted
I think sending them anything is worthy at the moment for them to get all angles on what's happening. It's bizarre why these install files get blocked/kept open!

 

Image8.jpg

 

Is this the point at which it all goes wrong?

Posted
[ATTACH=CONFIG]46186[/ATTACH]

 

Is this the point at which it all goes wrong?

 

That's the one. Creates those G*^&.tmp files too and they all stay open.

Posted

Another response from Capita:

 

Thank you for your feedback.You are correct. When running the update manually it will install the SIMS application successfully, however, the SIMSApplicationSetup.exe will continue to hang after the install completed. Having tested, we can confirm that the above behaviour is observed on instances where Sophos/Indirect x are present. No fault with the installers themselves have been found.

 

:ohwell:

 

Now they're desperately trying to close my call. I think Capita just want to wash their hands of the issue. Technically it is Sophos issue but you'd think they'd want to take some ownership (even a little bit) to ensure it gets resolved before the upgrade comes out because A; to help us out as we are paying customers afterall and B; it's going to become a much bigger issue if its not fixed before people start deploying the upgrade.

Posted

Another response from SOPHOS:

 

Thank you for your time and patience on the case. I have collected all required information and escalated the case to the Global Escalations team. I have re organized files from your FTP drive to ensure it is easily accessible by them.Please do collect SDU Logs from machines where testing was carried out by you yesterday under the folder "New test performed with PML only collected" to ensure the GES Team has all they need to get this to development.

 

My very sincere apologies as I ma certainly not in a position to provide you a quick solution in case this can be solved by development changes only. I do not mean to disappoint you but trying to set the right expectations as change in product may require more time than a regular patch. However, I leave it to the GES Team to decide what is best in this case. Please wait for an response from GES or me and we will get back to you with an update either requesting more information or with a workaround if possible.

 

 

Not sure why they keep requesting the SDU Logs - I'm doing my testing side by side on the same two identical computers every time!

 

My call has been open for over a week now!

Posted

Another one:

 

Thank you for your response. Currently the case is with the Global Escalations team since I have escalated. However I will be diligently following up to gather updates from them and either of us should be able to contact you once we have an update on the case.

 

There is already a pre planned release of newer version of HitmanPro (Intercept X) which brings about minor changes with product which possibly may fix this issue a swell. this is not or certainty and hence we do not have specific information as of now. However will keep you updated on the case progress once I receive an update.

 

Thanks and regards,

 

Adithyan Thangaraj

Sophos Technical Support

https://www.sophos.com/en-us/support/contact-support.aspx

Posted

In the case i've got open they seemed to suggest that it should be possible to add an exclusion:

 

"Hitman pro did detect this but did not stop the application. From Sophos Central Dashboard go to Global Settings

Under General Click on Exploit Mitigation Exclusions...."

 

Although I know that doesn't work so bounced it back to the engineer within about 5 minutes of the suggestion

Posted

As a side note, looking at the release notes of the preview version of intercept X (Although i've not tried it yet) - I'd be interested to know if that works - as I believe they are adding a new "allowed applications" policy - that seems to suggest it will check again a hash/certificate of the application.

@thatley you've probably seen already but they posted a KB article on the hyper-v issue on the 10th @ https://community.sophos.com/kb/en-us/127797

Posted
In the case i've got open they seemed to suggest that it should be possible to add an exclusion:

 

"Hitman pro did detect this but did not stop the application. From Sophos Central Dashboard go to Global Settings

Under General Click on Exploit Mitigation Exclusions...."

 

Although I know that doesn't work so bounced it back to the engineer within about 5 minutes of the suggestion

 

You'd think they would be coordinating this a bit better - I was asked to try this about a week ago :(

Posted
As a side note, looking at the release notes of the preview version of intercept X (Although i've not tried it yet) - I'd be interested to know if that works - as I believe they are adding a new "allowed applications" policy - that seems to suggest it will check again a hash/certificate of the application.

@thatley you've probably seen already but they posted a KB article on the hyper-v issue on the 10th @ https://community.sophos.com/kb/en-us/127797

 

Would that mean we'd need all the hash/certificates of all the updated exe's pushed out when SIMS upgrade before we can upgrade?

Posted
Would that mean we'd need all the hash/certificates of all the updated exe's pushed out when SIMS upgrade before we can upgrade?

 

If it's a certificate saying "trust capita's 2012 digital signing certificate" that would cover anything signed by them - I'm thinking Applocker behaviour

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...