![]() |
|
#1
|
|||
|
|||
|
Can someone explain to me exactly what kind of restrictions DW places on untrusted programs? I know its supposed to be stronger than LUA. But exactly what kind of restrictions are these? Are there any kinds of malware which can run in spite of DW restrictions? I know the DW help file states that certain kinds of advanced keyloggers can run, but is there anything else?
|
|
#2
|
||||
|
||||
|
Quote:
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268 |
|
#3
|
|||
|
|||
|
Can they execute? Can they write to C:programs or C:Windows?
|
|
#4
|
||||
|
||||
|
Quote:
if run it as trusted good luck![]() it is criple ![]() )
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268 |
|
#5
|
|||
|
|||
|
So if I were to run SRP together with DW, the malware wouldnt even be able to run right?
|
|
#6
|
||||
|
||||
|
with DefenseWall the malware is in a cage that has no permition to harm you pc,you are quite safe,dont actually need the SRP and also DW is stronger than lua
the only thing you need to do is get a firewall to protect the outbound connection and learn how to use the rollback feature to remove all the debris or left malware malware leave
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268 |
|
#7
|
|||
|
|||
|
But surely SRP will add greater restrictions in addition to those imposed by DW?
|
|
#8
|
||||
|
||||
|
Quote:
![]()
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268 |
|
#9
|
||||
|
||||
|
The best way to see what exactly defense wall protects is to install MD. then run the malware as trusted and from MD see what it does. Then run the malware as Untrusted and see what type of restrictions defense wall puts in place.
__________________
Win7 64bit Ultimate Sandboxie | Applocker | Admuncher | Macrium Reflect | TrueCrypt | FF Add On's | Greasemonkey | Secure Login | Noscript | Ant Video downloader | Status 4 evar |
|
#10
|
|||
|
|||
|
Fantastic Idea Arran!
|
|
#11
|
||||
|
||||
|
Quote:
good idea but dont try it on your real system , better play around with malware on VM ![]() also SRP provide a strong protection since it local policy , which are very restricted . about DW , i think is up to ilya to give a total explantion what DW does to the malware it catches...sure it cripple it , make it in a some sort of cage ![]()
__________________
WINDOWS 8 FIREWALL
Sandboxie (64-bit)
Secuirty software no.1~> YOUR SKILLS
Prevention is better than the cure
using win 8 Pro X64
|
|
#12
|
||||
|
||||
|
Quote:
Obviously Quote:
yea ilya can give an explanation if he wants to, but no reason why you can't use MD to find out as well.
__________________
Win7 64bit Ultimate Sandboxie | Applocker | Admuncher | Macrium Reflect | TrueCrypt | FF Add On's | Greasemonkey | Secure Login | Noscript | Ant Video downloader | Status 4 evar |
|
#13
|
|||
|
|||
|
Quote:
I agree. MD will afford one the ability to "see" key inter-process activity occurring in real time. |
|
#14
|
|||
|
|||
|
Quote:
__________________
DefenseWall HIPS developer. www.softsphere.com |
|
#15
|
||||
|
||||
|
Quote:
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#16
|
||||
|
||||
|
Quote:
yes of course , DW got many features far beyond just SRP , provide a solid protection against malware ![]()
__________________
WINDOWS 8 FIREWALL
Sandboxie (64-bit)
Secuirty software no.1~> YOUR SKILLS
Prevention is better than the cure
using win 8 Pro X64
|
|
#17
|
|||
|
|||
|
Quote:
__________________
DefenseWall HIPS developer. www.softsphere.com |
|
#18
|
||||
|
||||
|
Quote:
it is reliable. Run the malware as trusted and then run it as untrusted. and with MD's logs compare the results. when you run it as untrusted and MD isn't picking up anything then defense wall is fully containing it.
__________________
Win7 64bit Ultimate Sandboxie | Applocker | Admuncher | Macrium Reflect | TrueCrypt | FF Add On's | Greasemonkey | Secure Login | Noscript | Ant Video downloader | Status 4 evar |
|
#19
|
||||
|
||||
|
Quote:
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#20
|
||||
|
||||
|
Quote:
Only to your own usability of the PC. I would run any malware as untrusted with DW, have not seen it go down yet. So the deny execute is in theory safer. |
|
#21
|
||||
|
||||
|
Quote:
Because running malware trusted = DW is not protecting |
|
#22
|
||||
|
||||
|
It seems like I'll have to uninstal DW due to insurmountable problems I face. I just can't make it work properly.
I must say that Ilya was really trying to help and kept answering to my questions with promptness, but I just can't come to a solution. It must be something with my system because I can't even boot into Safe Mode. ![]()
__________________
Declaration of the Independence of Cyberspace ***** http://www.random.org/analysis/dilbert.jpg |
|
#23
|
|||
|
|||
|
The problem with Safe Mode is on your side as DefenseWall do not load its driver this case. The issue may be caused by malware infection (past or present) or system's corruption.
__________________
DefenseWall HIPS developer. www.softsphere.com |
|
#24
|
||||
|
||||
|
Talking about DefenseWall restrictions, I am more than happy to announce that DW doesn't restrict me to use the right-click context menu any more!
After uninstalling Daemon Tools (and goddamn sptd.sys) I reinstalled DefenseWall and everything seems to work just fine now. Ilya, I really appreciate effort and time you invested in trying to find the solution to problems I had. Good work!
__________________
Declaration of the Independence of Cyberspace ***** http://www.random.org/analysis/dilbert.jpg |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|