PDA

View Full Version : SLIPFEST Windows HIPS evaluation


Rasheed187
November 18th, 2007, 03:50 PM
Hi,

This is a bit too technical for me, so can anyone with some more knowledge tell how to use this tool, or better yet, how to interpret the results? Should HIPS protect against all these methods, and can they currently be bypassed?

http://slipfest.cr0.org/
www.cansecwest.com/slides06/csw06-tinnes.pdf

Rasheed187
November 25th, 2007, 12:36 PM
Nobody thinks that this tool is useful to test HIPS? Perhaps LUSHER can give some feedback. :)

LUSHER
November 26th, 2007, 09:55 AM
-{ Quote: "Nobody thinks that this tool is useful to test HIPS? Perhaps LUSHER can give some feedback. :)" }-

A quick look seems to indicate that it is of very little usefulness for "testing" the type of HIPS you are interested in.

Rasheed187
December 2nd, 2007, 01:09 PM
A bit more info in layman terms is welcome. I mean, do HIPS need to alert about the things that are triggered by this tool? Btw your inbox is full.