![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Application Layer Gateway Service
Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Application Layer Gateway Service
- This topic has 20 replies, 11 voices, and was last updated 6 years, 2 months ago.
AuthorTopicdturnidge
AskWoody PlusMarch 7, 2019 at 11:57 am #338595Just got one of “those” calls from a person who did not have English as their first language.They asked me to go to MSCONFIG and then Services. They directed me to “Application Layer Gateway Service”…This is when I ended the conversation. I have googled this name, and haven’t come up with anything helpful. I looked it up in askwoody – and came up with nothing.What is it, and why would they want me to do something with it?Viewing 6 reply threadsAuthorReplies-
Elly
AskWoody MVPMarch 7, 2019 at 12:26 pm #338620 -
Kirsty
ManagerMarch 7, 2019 at 12:44 pm #338629Digging deeper in Wikipedia’s information:
An ALG may offer the following functions:
– allowing client applications to use dynamic ephemeral TCP/ UDP ports to communicate with the known ports used by the server applications, even though a firewall configuration may allow only a limited number of known ports. In the absence of an ALG, either the ports would get blocked or the network administrator would need to explicitly open up a large number of ports in the firewall — rendering the network vulnerable to attacks on those ports.I expect they were trying to take control of the computer, as you suspected @dturnidge
1 user thanked author for this post.
-
dturnidge
AskWoody PlusMarch 7, 2019 at 1:10 pm #338642Thank you. My assumption, based on the name, was that if I activated the service it would give him access to my system – which I wouldn’t allow to happen!
I just wondered if my assumption would be correct. What would they do if I DID activate the service? What other info would they need? What software on THEIR end would they use to do their damage?
-
-
-
joep517
AskWoody MVP -
dturnidge
AskWoody Plus
-
-
OscarCP
MemberMarch 7, 2019 at 1:29 pm #338653For what it is worth, I have been receiving, and for some time already, the same pre-recorded call where a woman’s voice, speaking n a sort of threatening stage whisper, informs me that “your computer has been infected with a virus…”, and that is when I hang up.
It is a curious fact that the robocall systems never seem to learn that calling my number is just a waste of their crooked owners’ time. Too cheaply built for that?. Or designed that way, hoping that a different person might answer next time?
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AV -
anonymous
Guest
-
-
Fred
AskWoody LoungerMarch 7, 2019 at 1:31 pm #338655 -
b
AskWoody_MVPMarch 7, 2019 at 1:33 pm #338657I think they just pick a couple of services at the top of the alphabetical list which they know are likely to show “Stopped”, so that they can convince you that you have some “problems” to be fixed:
Security disabled. How do I enable? (OR was someone trying to scam me?)
-
dturnidge
AskWoody PlusMarch 7, 2019 at 1:37 pm #338659 -
b
AskWoody_MVP -
OscarCP
MemberMarch 7, 2019 at 3:46 pm #338729These people sending fake messages are criminals, maybe violent ones, and in this age of “you have absolutely no privacy, so forget about it”, they may even have means to know where one lives. So best not to tempt the devil and avoid trying to get in touch with them, even if it is to tell them off. Unless it is a live call from an actual person, so one is already in touch with them.
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AV -
dturnidge
AskWoody Plus
-
-
-
-
wavy
AskWoody PlusMarch 8, 2019 at 5:12 pm #339177I would have been interested in what they were actually going to tell you to do. (w/o you doing it of course. ) It seems to be a service that could allow all manor of mischief if abused. FYI mine is stopped.
Just because you don't know where you are going doesn't mean any road will get you there. -
dturnidge
AskWoody Plus -
anonymous
Guest
-
-
GoneToPlaid
AskWoody LoungerMarch 8, 2019 at 10:11 pm #339264Some of these hackers can turn around and behave in very malicious ways. It is best to simply tell them that you don’t have any Windows computers, that you have no issues, thank them for their concern, and hang up. The upshot is, do not egg them on in any way. I have been DDOSd twice. Once, for a comment I made here on this forum. That DDOS was from Russia. The other time (around 20 years ago) was from a specific person in Canada, yet again for a comment I made on another forum. The takeaway is that there are really bad people out there online.
I have never received one of these kinds of calls because I am extraordinarily careful about what I put “out there” on the Internet or on other public records. It is far better to be a ghost, in terms of your online identity everywhere and whenever possible, and to make sure that you never use the same password twice anywhere online, than to fall victim to either identity theft or to phishing scams or to robocalls.
Some food for thought…
(Forum mods, please feel free to consider moving and editing all of the following since it really belongs under some sort of Online Security topic. It would be nice to turn the following, and to expand on the following in terms of online security. After all, education is one of the goals of the AskWoody forum!)
Talk to one of your local bank’s representatives to discuss and learn how to implement every additional security measure which they have to offer for you — including receiving email alerts for all transactions above zero cents, and for implementing a verbal password so that your bank can confirm that they are talking to you and nobody else who is trying to impersonate you. Unfortunately, many banking institutions do not first offer a verbal “challenge” word, which you should know, before you give up your verbal password! Incoming phone numbers shown on your home phone or cell phone can so easily be faked. Learn more by simply Googling “phone swatting”.
Change your card pin numbers at least as often as every three months. Request replacement cards every year. If you are paranoid, request replacement cards every six months. Do not link bank accounts for overdraft protection. Additionally request additional debit cards which you never use, unless the other debit cards become compromised, so that you have a fall back method. These additional “emergency” debit cards should have a different PIN number.
Create a separate bank account which you will use for all online transactions. Do not link this bank account to any of your other bank accounts. Replenish funds in this bank account only as needed in order to cover your online purchases. The point here is to limit how much money a hacker can steel from you in the event of a data breach of an online retailer from which you made purchases.
Try to do the same thing for your credit cards. Some banking institutions might object to you having more than one debit or credit card which is associated with one of your bank accounts. You must explain to the banking institution that these cards will be “emergency” cards which will only be used in the event that the other cards have become compromised, perhaps by a retailer data breach, et cetera.
Never travel internationally without having some way, in particular some never used way, to pay for any expenses in the dire event that all of your other payment methods have been compromised or suspended.
Many people pay their bills online. Most companies allow the user to save details about their payment method. That is a bad thing if a company becomes the victim of a data breach. Never save details for your payment method online. Yeah, you have to forgo the “convenience factor”. I never save my payment details online. Yeah, this is a real [annoyance], but this also prevents my payment method becoming part of a data breach.
-
satrow
AskWoody MVPMarch 8, 2019 at 11:16 pm #339271Before asking your bank anything, check the security of their servers first: https://www.ssllabs.com/ssltest/
3 users thanked author for this post.
-
GoneToPlaid
AskWoody LoungerMarch 9, 2019 at 12:39 pm #339419Hello Satrow,
Very slick, although time consuming to perform (you have to wait a good while for all results). Yet well worth the effort in terms of waiting for all results to eventually be displayed.
Satrow, thank you so very much for the link to this most worthwhile utility which anyone can use to check the worthiness of any bank’s web site before anyone considers opening accounts with a new bank.
Satrow’s link to Qualis can also be used to check any web site. In particular, other online web sites which most people regularly use to pay their car insurance, to pay their utility bills, et cetera. I think that it is worthwhile for everyone to use Satrow’s link for the Qualis utility to check such sites, in particular for whether or not you decide to save your payment credentials with a given web site for convenience.
Obviously for online banking, one would expect the Qualis tests to report an A+ grade, even if there are a few issues in terms of users not having upgraded their web browsers to disallow older TLS protocols. Yeah, banks tend to choose to continue to support older TLS protocols in order to keep customers happy, even though those customers refuse to upgrade their web browsers or also refuse to upgrade to a more modern OS.
One big thing to look for in the Qualis report is that your online bank has implemented later and more secure versions of TLS. In particular, TLS with RSA and with AES 128 or AES 256. The AES level (128 or 256) really doesn’t matter. In the Qualis test report, you all will be looking for at least one green colored line under the Protocols and Cypher Suites sections. Further, you should also look at and consider the potential implications of any orange colored lines in the report.
I reckon that Satrow can elucidate further on Qualis reports much better than I can.
Again, satrow’s link is most remarkable in its usefulness, and in terms of helping you to decide whether or not you should consider allowing any given web site to store your payment credentials. Personally, I never allow any web sites to store my payment credentials — other than Paypal. Even with Paypal, I use a specific card which has very limited available funds. This is a real [pain] since I have to enter my payment credentials every single time on all other web sites. Yet I feel much safer by having to do so, versus allowing web sites to save my payment credentials in their databases.
I operate under two basic assumptions. First, is that data breeches are inevitable — even years down the road. Second, is that the US government will not do a thing about it, other than at most slaps on the wrist. I could rant about the latter, yet it is what it is.
Best regards and with a special thanks to satrow,
–GTP
-
satrow
AskWoody MVPMarch 9, 2019 at 7:09 pm #339506Browsers make up the other side of the secure connection equation, test yours here.
1 user thanked author for this post.
-
-
-
Viewing 6 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Android 15 and IPV6
by
Win7and10
3 hours, 35 minutes ago -
KB5058405 might fail to install with recovery error 0xc0000098 in ACPI.sys
by
Susan Bradley
9 hours, 45 minutes ago -
T-Mobile’s T-Life App has a “Screen Recording Tool” Turned on
by
Alex5723
12 hours, 27 minutes ago -
Windows 11 Insider Preview Build 26100.4202 (24H2) released to Release Preview
by
joep517
7 hours, 2 minutes ago -
Windows Update orchestration platform to update all software
by
Alex5723
19 hours, 46 minutes ago -
May preview updates
by
Susan Bradley
7 hours, 9 minutes ago -
Microsoft releases KB5061977 Windows 11 24H2, Server 2025 emergency out of band
by
Alex5723
9 hours, 20 minutes ago -
Just got this pop-up page while browsing
by
Alex5723
11 hours, 58 minutes ago -
KB5058379 / KB 5061768 Failures
by
crown
9 hours, 2 minutes ago -
Windows 10 23H2 Good to Update to ?
by
jkitc
6 hours, 11 minutes ago -
At last – installation of 24H2
by
Botswana12
1 day, 11 hours ago -
MS-DEFCON 4: As good as it gets
by
Susan Bradley
6 hours, 23 minutes ago -
RyTuneX optimize Windows 10/11 tool
by
Alex5723
1 day, 23 hours ago -
Can I just update from Win11 22H2 to 23H2?
by
Dave Easley
1 day, 16 hours ago -
Limited account permission error related to Windows Update
by
gtd12345
2 days, 12 hours ago -
Another test post
by
gtd12345
2 days, 13 hours ago -
Connect to someone else computer
by
wadeer
2 days, 7 hours ago -
Limit on User names?
by
CWBillow
2 days, 10 hours ago -
Choose the right apps for traveling
by
Peter Deegan
2 days ago -
BitLocker rears its head
by
Susan Bradley
1 day, 8 hours ago -
Who are you? (2025 edition)
by
Will Fastie
1 day, 7 hours ago -
AskWoody at the computer museum, round two
by
Will Fastie
2 days, 2 hours ago -
A smarter, simpler Firefox address bar
by
Alex5723
2 days, 23 hours ago -
Woody
by
Scott
3 days, 8 hours ago -
24H2 has suppressed my favoured spider
by
Davidhs
1 day, 8 hours ago -
GeForce RTX 5060 in certain motherboards could experience blank screens
by
Alex5723
3 days, 23 hours ago -
MS Office 365 Home on MAC
by
MickIver
3 days, 16 hours ago -
Google’s Veo3 video generator. Before you ask: yes, everything is AI here
by
Alex5723
4 days, 13 hours ago -
Flash Drive Eject Error for Still In Use
by
J9438
1 day, 7 hours ago -
Windows 11 Insider Preview build 27863 released to Canary
by
joep517
5 days, 7 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.