Wilders Security Forums  

Go Back   Wilders Security Forums > Official Returnil Support Forum > Returnil Betas
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 16th, 2010, 08:24 AM
Dark Star 72 Dark Star 72 is offline
Frequent Poster
 
Join Date: May 2007
Location: UK
Posts: 580
Default RVS 2011 Lite query

When using RVS 2011 Lite with System Protection ON and System Guard ON and 'Prompt user(s) for action when unauthorized access occurs' ticked I get the pop-up shown below when I activate Process Explorer. If I click 'Terminate' ProExp doesn't start as is to be expected. If I click 'Pass' ProExp starts up . However, if I click 'Deny' it still starts normally . If I untick 'Prompt user...' etc ProExp just starts normally.
So, what should 'Deny' do? Or does it allow ProExp because it isn't actually doing anything malicious?
I was was also under the impression that if I unticked 'Prompt user...' etc it would become like 'Default-Deny' and block without a warning pop-up.
Not sure if I have misunderstood quite how it works but some clarification would be welcome.

Also, I notice that there is a countdown timer on the pop-up and when it gets to zero the 'suspended' application then starts. Shouldn't it terminate it?
Attached Images
 
  #2  
Old July 16th, 2010, 12:31 PM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,744
Default Re: RVS 2011 Lite query

Hi DS,
What is happening is that Process Explorer's Kernel Mode driver is blocked. What is not obvious here is that PE can still run without this driver being installed or working. The important part to keep in mind here is that the content that could have presented a potential threat is the installation of Kernel Mode drivers which the System Guard prevented.

For the rest:

1.) Terminate button: If the user selects the Terminate button, it will terminate the specific running process.

2.) Deny button: If the user chooses deny, it will not allow the operation shown in the dialog. (ref: create .sys driver in the system folder).

3.) Count down: There is a 60 second count down at the end of which, if there is no user response to take action, the System Guard will automatically default to Deny.

Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
  #3  
Old July 16th, 2010, 01:37 PM
Dark Star 72 Dark Star 72 is offline
Frequent Poster
 
Join Date: May 2007
Location: UK
Posts: 580
Default Re: RVS 2011 Lite query

Thanks for your usual comprehensive reply Mike.

Just to be sure I have got this right:
Deny Button: Had it been a malicious software/application and I had clicked Deny it would not have run, or not been able to access any critical parts of the OS? ie: It could not have done any harm or installed anything malicious.

Same with the Countdown Timer and the Prompt User functions, non-malicious and it would have started with 'limited' rights but malicious/malware and it would have been stopped?
This would seem similar to the way DefenseWall works.

I notice we have new toys to play with now, RSS Pro 2011 Pro and the Multi Snapshot. Will install them later and play
  #4  
Old July 16th, 2010, 02:01 PM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,744
Default Re: RVS 2011 Lite query

Quote:
Deny Button: Had it been a malicious software/application and I had clicked Deny it would not have run, or not been able to access any critical parts of the OS? ie: It could not have done any harm or installed anything malicious.

Don't confuse blocking the program with blocking installation of kernel mode drivers. The threat comes from kernel rather than user mode content. This means that if the program had been malicious, it could have infected your virtual system but could not have gotten around the virtualization which is the true goal here.

Quote:
Same with the Countdown Timer and the Prompt User functions, non-malicious and it would have started with 'limited' rights but malicious/malware and it would have been stopped?
This would seem similar to the way DefenseWall works.

As I do not know DW at a low enough level to comment, I would refer you to their support staff to get specific information about their program and how it works.

Regarding the count down timer and System Guard functionality, the timer is there for the user, not the software as the content is blocked regardless of the wait for a response from the user. If you allow (Pass), then the software would unblock at that point. If you deny, it remains blocked.

Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
 

Wilders Security Forums > Official Returnil Support Forum > Returnil Betas « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:03 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums