PDA

View Full Version : Imon (website access blocking)


marcromero
June 8th, 2006, 07:16 PM
Imon> Setup> Miscellaneous> Website Access Blocking. Lists known websites containing malicious files updated by vendor. Is this a type of host file? if so, where can I find this list?

Blackspear
June 8th, 2006, 07:17 PM
{QUOTE-> Imon> Setup> Miscellaneous> Website Access Blocking. Lists known websites containing malicious files updated by vendor. Is this a type of host file? if so, where can I find this list? <-QUOTE}As far as I know this is maintained by Eset and comes down like an update/or part of an update.

Cheers ;D

marcromero
June 8th, 2006, 07:31 PM
It would appear so, sure would like to know more about it, cannot seem to find any detailed information.

Blackspear
June 8th, 2006, 07:50 PM
{QUOTE-> ...sure would like to know more about it, cannot seem to find any detailed information. <-QUOTE}We'll have to wait for Marcos or one of the Eset guys to come along with further details.

Cheers ;D

i_kenefick
June 8th, 2006, 08:28 PM
{QUOTE-> Imon> Setup> Miscellaneous> Website Access Blocking. Lists known websites containing malicious files updated by vendor. Is this a type of host file? if so, where can I find this list? <-QUOTE}

IMON sits at winsock (in the LSP chain) and intercepts the http traffic. As soon as you attempt to visit xyz.com it redirects you to the warning page. So a little 'lower' than the host file and not configurable to the user ie. just enable or disable this feature.

pykko
June 9th, 2006, 07:21 AM
for example this list contains all (or approximately all) the websites containing the Trojan.Downloader.Zlob variants. ;)

i_kenefick
June 9th, 2006, 07:50 AM
{QUOTE-> for example this list contains all (or approximately all) the websites containing the Trojan.Downloader.Zlob variants. ;) <-QUOTE}

Yeah ;)

rothko
June 10th, 2006, 04:06 AM
{QUOTE-> Imon> Setup> Miscellaneous> Website Access Blocking. Lists known websites containing malicious files updated by vendor. Is this a type of host file? if so, where can I find this list? <-QUOTE}
i asked the same question here http://www.wilderssecurity.com/showpost.php?p=418965&postcount=137 the answer was no you cant see the list

webyourbusiness
June 11th, 2006, 12:38 PM
I've never even seen the warning - if someone knows at least ONE of the sites that generates it, please post a screenshot of the screen we'll see - also - just make sure you obscure the actually link of the site, as posting links to malware or suspected malware is against the TOS of this forum.

cheers

Greg

Brian N
June 11th, 2006, 12:40 PM
{QUOTE-> I've never even seen the warning - if someone knows at least ONE of the sites that generates it, please post a screenshot of the screen we'll see <-QUOTE}
Go to v-codec.com and see for youself ;)
And it will popup with this: http://www.wilderssecurity.com/showpost.php?p=766812&postcount=81

berng
June 11th, 2006, 01:16 PM
I have the Web site block option set but NOD 32 doesn't block me from getting to the site.

Marcos
June 11th, 2006, 01:28 PM
{QUOTE-> I have the Web site block option set but NOD 32 doesn't block me from getting to the site. <-QUOTE}

What site do you mean? If it's actually in the blacklist, access to it must be blocked unless you have the HTTP scanner disabled.

ASpace
June 11th, 2006, 03:39 PM
{QUOTE-> I have the Web site block option set but NOD 32 doesn't block me from getting to the site. <-QUOTE}


Internet Explorer , Mozilla or what browser do you use ?
And what site are we talking about . :)

Brian N
June 11th, 2006, 03:41 PM
v-codec.com probably ...........

ASpace
June 11th, 2006, 03:42 PM
{QUOTE-> v-codec.com probably ........... <-QUOTE}

yeah , but p r o b a b l y ;D ;) ;D

i_kenefick
June 11th, 2006, 04:00 PM
{QUOTE-> Internet Explorer , Mozilla or what browser do you use ?
And what site are we talking about . :) <-QUOTE}

Since IMON is browser independant it doesnt make a difference what browser he/she is using.

ASpace
June 11th, 2006, 04:07 PM
{QUOTE-> Since IMON is browser independant it doesnt make a difference what browser he/she is using. <-QUOTE}

I know that but sometimes on some computers when Mozilla Firefox is in use , IMON doesn't detect Eicar test file (www.eicar.org)
It is detected only by AMON which is strange .

Note it is only sometimes and not on all computers I know

i_kenefick
June 11th, 2006, 04:24 PM
{QUOTE-> I know that but sometimes on some computers when Mozilla Firefox is in use , IMON doesn't detect Eicar test file (www.eicar.org)
It is detected only by AMON which is strange . <-QUOTE}

This happens if SSL is used to get eicar from www.eicar.org.

Brian N
June 11th, 2006, 04:25 PM
{QUOTE-> I know that but sometimes on some computers when Mozilla Firefox is in use , IMON doesn't detect Eicar test file (www.eicar.org)
It is detected only by AMON which is strange .

Note it is only sometimes and not on all computers I know <-QUOTE}
All they gotta do is change higher compatibility to higher efficiency in IMON. Done deal.
SSL cant be scanned obviously.

FirePost
June 11th, 2006, 04:53 PM
One must have higher efficiency set to have the sites blocked. That does not make sense. It is website blocking not individual files. It does explain why some people were able to access the sites.

ASpace
June 11th, 2006, 05:05 PM
{QUOTE-> This happens if SSL is used to get eicar from www.eicar.org. <-QUOTE}

I am not talking about SSL . I know that SSL is not being scanned.

Maybe Brian's suggestion would work but as I said this happends just sometimes and just on Firefox

berng
June 11th, 2006, 06:13 PM
{QUOTE-> Internet Explorer , Mozilla or what browser do you use ?
And what site are we talking about . :) <-QUOTE}

It is v-codec.com using Opera 9 Beta Ver 8473.

Brian N
June 12th, 2006, 01:31 AM
It blocks that site here in Firefox, IE & Opera. I don't use other browers so can't comment on those :)