View Full Version : Geswall + Sandboxie + Returnil
Gargoyle
December 23rd, 2007, 09:42 PM
As I'm still learning about HIPS, I am thinking about using all three programs for things I download from the internet that I'm not sure aren't filled with malware. Has anyone tried running all three programs together? If so, any problems such as BSOD? And, would you say the setup is redundant?
LoneWolf
December 23rd, 2007, 10:42 PM
-{ Quote: "As I'm still learning about HIPS, I am thinking about using all three programs for things I download from the internet that I'm not sure aren't filled with malware. Has anyone tried running all three programs together? If so, any problems such as BSOD? And, would you say the setup is redundant?" }-
I run GeSWall at all times (one of my main pieces of security software at this time)
I fire up SandBoxie when I know i'm going into possible dangerous territory.
But in order to do this without getting this error from SandBoxie I change the security setting in GeSWall to low,start SandBoxie then change the setting in GeSWall back to medium. Now I have a sandbox with all contents under the policy restrictions of GeSWall as well as my other security layers in place.
Not sure about Returnil as I have never tried this app.
Gargoyle
December 23rd, 2007, 11:28 PM
It seems you are running Sandboxie inside Geswall. Have you tried running Geswall inside Sandboxie and see how it goes? Like, download something using your favorite Geswalled web browser. Then run sandboxie on the application after it has the isolated icon. That method, Geswall inside Sandboxie, is what I intend to do.
ErikAlbert
December 23rd, 2007, 11:41 PM
Returnil will save you from the many BSOD's on your computer, if you read this :
http://www.returnilvirtualsystem.com/index_files/rvspersonal.htm
Except for testing new softwares that require a reboot during installation.
In that case, you will need your Image Backup/Restore software, if something goes wrong.
If nothing goes wrong, but you don't like the software, you can't uninstall it with Returnil, then you have to uninstall it with the classical tools or restore an image.
You can also use a Virtual Machine to test softwares, which is probably the best way.
LoneWolf
December 23rd, 2007, 11:49 PM
-{ Quote: "It seems you are running Sandboxie inside Geswall. Have you tried running Geswall inside Sandboxie and see how it goes? Like, download something using your favorite Geswalled web browser. Then run sandboxie on the application after it has the isolated icon. That method, Geswall inside Sandboxie, is what I intend to do." }-
No never tried that. My way is just extra protection while surfing,not testing a software. After testing software and if its not staying I rollback to an earlyer snapshot,like it was never there.
aigle
December 24th, 2007, 04:04 AM
-{ Quote: "As I'm still learning about HIPS, I am thinking about using all three programs for things I download from the internet that I'm not sure aren't filled with malware. Has anyone tried running all three programs together? If so, any problems such as BSOD? And, would you say the setup is redundant?" }-
I will never suggest to combine GE and SBIE9 very same type of software). Just use either one of them. Adding Returnil might be OK though.
LUSHER
December 24th, 2007, 05:17 AM
-{ Quote: "As I'm still learning about HIPS, I am thinking about using all three programs for things I download from the internet that I'm not sure aren't filled with malware. Has anyone tried running all three programs together? If so, any problems such as BSOD? And, would you say the setup is redundant?" }-
I would say traditional/conventional wisdom is that you can probably drop GesWall or Sandboxie. And add something like Threatfire and ProSecurity. :D
Gargoyle
December 24th, 2007, 11:45 PM
I'm still learning about classical hips and it just so happens I'm trying Prosecurity right now. EQsecure is something I can fall back.
Aigle, check your PM.
poirot
December 25th, 2007, 06:21 AM
Imho the combination of
ProSecurity 1.40
GeSWall 2.6 free
and
Returnil -any version
makes for a rather omnicomprehensive and rather unhackable combination.
You can drop anything else and have just a firewall and/or Router.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums