Wilders Security Forums  

Go Back   Wilders Security Forums > Official Returnil Support Forum > Returnil releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 10th, 2011, 02:43 PM
tuatara's Avatar
tuatara tuatara is offline
Frequent Poster
 
Join Date: Apr 2004
Posts: 758
Unhappy Prevent uploading files

Of course i understand that it is handy to have suspicious or unknown files uploaded to analyse them with the AV.

But whatever i select on the three relevant options, send,ask,never,
Even disable the AV.
It keeps uploading files and reporting a checkbox list with their progress ?!
With all kinds of files i don't want to have uploaded!!!!
The line under these checkboxes is hyper confusing, because it can mean several things.
So,

is it possible to use the last Pro version, without taking the risk of uploading files? Or do i need to make rules for it to block it in a firewall ?

Thanks,

Btw i am happy it ran on a test system
__________________
The old creature tuatara lived here, hundreds of years
before those malware creators arrived on the Internet


  #2  
Old October 10th, 2011, 04:24 PM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,743
Default Re: Prevent uploading files

First, there is no risk and it is even helpful to all users as the information is analyzed to update the black and white lists for all users. This information is only related to the suspicious or unknown files/behavior and nothing private/sensitive is ever sent or even required.

As for turning this off however, simply change the Virus Guard > Settings > Data collection policy to "never" and you should be good to go.
__________________
Returnil: The Real Security!
Follow us on Facebook
  #3  
Old October 10th, 2011, 05:51 PM
tuatara's Avatar
tuatara tuatara is offline
Frequent Poster
 
Join Date: Apr 2004
Posts: 758
Default Re: Prevent uploading files

Hi Coldmoon,

Just as i said, i understand the need for uploading samples.
However instead of uploading the suspicious part of a file it is uploading complete files, for example lots of files of VMware (fresh install).
This must be easy to reproduce.
And i already had set it to Never.
Is it possible that this setting is only activated after a reboot?
There are a lot of companies that have a policy that no files may be uploaded.

Anyway i will reinstall , and check if i am able to change it to never before files are uploaded.
__________________
The old creature tuatara lived here, hundreds of years
before those malware creators arrived on the Internet


  #4  
Old October 10th, 2011, 05:55 PM
tuatara's Avatar
tuatara tuatara is offline
Frequent Poster
 
Join Date: Apr 2004
Posts: 758
Default Re: Prevent uploading files

And about:" nothing private/sensitive is ever sent or even required."

You were wrong here, complete files were uploaded, these could contain confidentional software.
__________________
The old creature tuatara lived here, hundreds of years
before those malware creators arrived on the Internet


  #5  
Old October 10th, 2011, 07:09 PM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,743
Default Re: Prevent uploading files

It shouldn't be uploading anything VMWare as that is well known and not reproducible here on systems in the lab. Which version of VMWare?

As for a restart, the preferences should take effect immediately once you make the change. To investigate, can you PM me your installation ID (preferences > Advanced tab) so we can check our server side comm logs to investigate the traffic?

thanks
Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
  #6  
Old October 12th, 2011, 05:38 AM
tuatara's Avatar
tuatara tuatara is offline
Frequent Poster
 
Join Date: Apr 2004
Posts: 758
Thumbs up Re: Prevent uploading files

Hi Coldmoon,

First of all let me set things straight, i could NOT reproduce this problem.

So, i am very happy with that, but lets explain in detail what i have done.

When the above happened a few days ago, i did this:
FEW DAYS AGO:
1) reinstall a clean Windows with VMware and VNC (and their updates) from a image.
2) installed Returnil RSS the latest version.
3) and 'Do not collect' and are you certain? -> yes
4) Rebooted the system
5) Started scanning
6) then i got the spreadsheet alike matrix with files and their upload progress
And checkboxes
So i decided to remove RSS

TODAY:
I follewed the same steps, (same image, same RSS installer) and making screenshots of every step i took.
And ...... Nothing NOT 1 FILE UPLOADED!!

So, i was beginning to doubt if i perhaps had made the wrong selection a few
days ago regarding the upload of files.
So i reinstalled the image, started the installer and
So i set it to UPLOAD.
And again .. Nothing !! No file was uploaded.?

Hmm, Perhaps i had set it to ASK ME?
Thus, reinstall the image, start the installer and set it to ASK ME
Now i was convinced to see the files and their checkboxes...
But again NOTHING !!!

So, now i don't know what has happened, perhaps i made a mistake in my
selection regarding uploading files, although i am quite precise in these things.
And perhaps It doesn't upload things now, because the checksums/MD5's are known now?

But anyhow, since i can not reproduce the problem, and it is working correctly now, this case for me is closed.

POST READERS: i probably was too fast and made the wrong selection.

But one last thing i like to know is, sadly i haven't got a screenshot of these,
is: When will the list with files , checkboxes and transfer progress appear ?
__________________
The old creature tuatara lived here, hundreds of years
before those malware creators arrived on the Internet



Last edited by tuatara : October 12th, 2011 at 05:46 AM.
  #7  
Old October 12th, 2011, 10:28 AM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,743
Default Re: Prevent uploading files

Quote:
But one last thing i like to know is, sadly i haven't got a screenshot of these,
is: When will the list with files , checkboxes and transfer progress appear ?

The upload queue will not show a progress bar, it will simply work in the background at low priority with items sent taken off the list as soon as the upload is completed. As the bandwidth is set by default at the lowest dialup speed by default, the user should have ample time to see the list.

If you change the default option to not use your preferences for the upload, you would be asked to upload, but would not see a progress bar as described above because at 33.6 kbps, it may take a while to upload anything in the list and a progress bar would be distracting to most users.

As for the non-reproduction, PM me your Installation ID regardless and we can check the server logs to so what (if anything) was uploaded and let you know.

Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
  #8  
Old October 12th, 2011, 02:33 PM
tuatara's Avatar
tuatara tuatara is offline
Frequent Poster
 
Join Date: Apr 2004
Posts: 758
Default Re: Prevent uploading files

The progress was visable not as a progress bar, but as a table in a spreadsheet
For every file there was the file size and the file size size of the part that was uploaded
A bit like this:

[ checkbox] File-abc 1.75 MB 2.25 MB
[ checkbox] File-def 3.25 MB 4.25 MB
Etc.

And a very unclear line with a cryptic question regarding my permission
To upload these files.

What was that about?

Thanks that you are willing to investigate if private files were sent,
but i know that i have prevented that in time.
There were some vmware software files sent and some others were in progress.
__________________
The old creature tuatara lived here, hundreds of years
before those malware creators arrived on the Internet



Last edited by tuatara : October 12th, 2011 at 02:41 PM.
  #9  
Old October 12th, 2011, 02:40 PM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,743
Default Re: Prevent uploading files

Quote:
...And a very unclear line with a cryptic question regarding my permission To upload these files.

Apologies - This option is checked by default and relates to your setting for the data collection policy. If you uncheck this, it would supersede your DCP setting.

If you change the DPC to ask, you would have to authorize the sending of the data manually. Set to do not, it should not send any information.
__________________
Returnil: The Real Security!
Follow us on Facebook
 

Wilders Security Forums > Official Returnil Support Forum > Returnil releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:57 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums