kareldjag
March 15th, 2005, 06:08 AM
Hi,
On my first post about RegDefend, i've mentioned protection against hidden keys.
So i've tested RegDefend against this kind of methods used by rootkits for instance.
The test tool is RegHide by Sysinternals:
http://www.sysinternals.com/ntw2k/info/tips.shtml#registryhidden
RegHide creates a hidden key in the HKLM_Software group.
During the test, i've monitored all changes with InstallSpy (a monotoring free soft).
I've added the HKLM_Software group to the rules with different configurations:
*block,
*ask user .
Conclusion: RegDefend has a real and efficiency protection against hidden keys:
*RegHide was able to create the key (Systems Internals\Can't touch me):
-With the "ask user" rule, and "allow" answer to the RegDefend's pop up box .
*RegHide was not able to create the keys in all the others case:
-"block" rule,
-"ask user" rule and "block" answer to the pop up box.
To be objective, there's many monitoring softs (free or paid) which have not a real and efficiency prevetion protection of the registry (prevent=block, not only monitor and detect).
In this case, RegDefend, as RegRun, is an efficiency program which protects against advanced attacks .
But just some little remarks (or whishes) :
*Why RegDefend is not already pre-rules configured?
If Wilders members are well informed about computer's security, it's not the case of John Doe, Monsieur Dupont, our friends or family's members.
Three rules with different level (low, medium, high security) could be interesting for newbies and classicals users.
*For more security, hashes values to authenticate the registry could also be interesting.
MD5 is enough, SHA-1 can be more secure but also too slow and too long.
Regards
On my first post about RegDefend, i've mentioned protection against hidden keys.
So i've tested RegDefend against this kind of methods used by rootkits for instance.
The test tool is RegHide by Sysinternals:
http://www.sysinternals.com/ntw2k/info/tips.shtml#registryhidden
RegHide creates a hidden key in the HKLM_Software group.
During the test, i've monitored all changes with InstallSpy (a monotoring free soft).
I've added the HKLM_Software group to the rules with different configurations:
*block,
*ask user .
Conclusion: RegDefend has a real and efficiency protection against hidden keys:
*RegHide was able to create the key (Systems Internals\Can't touch me):
-With the "ask user" rule, and "allow" answer to the RegDefend's pop up box .
*RegHide was not able to create the keys in all the others case:
-"block" rule,
-"ask user" rule and "block" answer to the pop up box.
To be objective, there's many monitoring softs (free or paid) which have not a real and efficiency prevetion protection of the registry (prevent=block, not only monitor and detect).
In this case, RegDefend, as RegRun, is an efficiency program which protects against advanced attacks .
But just some little remarks (or whishes) :
*Why RegDefend is not already pre-rules configured?
If Wilders members are well informed about computer's security, it's not the case of John Doe, Monsieur Dupont, our friends or family's members.
Three rules with different level (low, medium, high security) could be interesting for newbies and classicals users.
*For more security, hashes values to authenticate the registry could also be interesting.
MD5 is enough, SHA-1 can be more secure but also too slow and too long.
Regards