PDA

View Full Version : Safe'n'Sec, adding "execution control"


polocanada
August 25th, 2007, 01:58 PM
I see some people recommend Safe'n'Sec as being one of the most complete HIPS and behaviour blocking software. Does anybody know how to plug in the "process execution" hole in Safe'n'Sec?

Safe'N'Sec doesn't provide process execution. For me this is something I don't grasp. At least if they would provide an option for people to turn it on and off (for those who don't want this).

Is there any way to turn this on through rules etc in Safe'n'Sec?

If it can't be turned on, what other light and free software would you recommend for just "execution control". Process Guard? Some of the apps overlap.

Here is a link expaining strengs and weaknesses of Safe'n'Sec.
http://www.safensoft.com/security.phtml?c=221&id=1178
I was pleasantly surprised that this company admits weaknesses of their software. Here they talk about execution control. Explanation is stupid but the fact they are fair and opend was also another reasons I subscribed to their service. Many other security companies just tell marketing cr@p...

Here is another link (I am sure somebody else posted it here already) about comparison, in fact Execution control is one area where Safe'n'Sec is missing.
http://wiki.castlecops.com/HIPS/IDP_programs/services

Cheers.

Polo

lu_chin
August 25th, 2007, 02:39 PM
I don't understand how SNS 3.0 works either. I bought and used 2.0 and 2.5 and they both asked for me permission when some new application first ran. But 3.0 did not seem do that anymore.

Rasheed187
August 26th, 2007, 03:17 PM
Very interesting review, makes me want to take another look at SnS, but to be honest, while I did like it, I was not really happy with the alert popups and GUI in general, but I´m extremely picky when it comes to these things. :)

polocanada
August 26th, 2007, 04:30 PM
I have to say I'd use better my brain next time. I just don't know why I was so rush with giving it a positive review and sending money without testing ir properly ...
this inmature, I think my brain got cooked in this summer temperature in my backyard.

Here we go... plot thickens.. After a reboot the program doesn't start.

Originally I thought there was a problem with ESS which I also have installed. First time I installed SNS on Vista I couldn't boot into desktop. It kept saying my Vista is not genuine. (funny isn't it...?)...

I removed ESS because I sensed that might dislike SNS. Rebooted. Reinstalled SNS. Looks ok. Logged off. (ALL things above done in admin account)....

Logged in back to admin account. Seems to work fine.

Restarted.... starting starting... All seems fine, but SNS is not starting.... Clicking again, looking into tasks... it doesn't even appear after I double click on icon to start the proggy.

This is funny here. I will post another review about what HISP actually works on Vista.

Developers, Developers, Developers.... Developers, Deverlopers, Developers.... Get to work!

Cheers...

polocanada
August 26th, 2007, 04:32 PM
Also - I found this little free proggy does do exactly and only one thing : application execution control.. so it might be a nice square peg into square hole. :thumb:

http://winpooch.free.fr/page/home.php?lang=en&page=home

Cheers

Rasheed187
September 10th, 2007, 01:18 PM
OK, so I checked out SnS Pro but I don´t get it, it doesn´t seem to alert about a single thing, and malware can do whatever the hell they want, am I missing something? Do you need to configure it in a certain way? Because it did seem to have a lot of options. ::)

bellgamin
September 10th, 2007, 09:27 PM
{QUOTE-> Also - I found this little free proggy does do exactly and only one thing : application execution control.. so it might be a nice square peg into square hole. :thumb:

http://winpooch.free.fr/page/home.php?lang=en&page=home

Cheers <-QUOTE}Winpooch is a high-potential HIPS freebie. Unfortunately, it is abandonware. Same seems true for CoreForce (http://force.coresecurity.com/index.php?module=base&page=main)

ink
September 10th, 2007, 09:44 PM
you don't need excution control, just make sure the system is clean, and then make a file rule to ask for creation of excutable files, it is much better than excution control. if you are using +antivurs, sns will scan before ask your question, then you can abandon your real time antivirus.