Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 7th, 2012, 11:50 PM
Gullible Jones
 
Posts: n/a
Default List of FW/HIPS with default deny modes?

Since discovering the virtues of learning mode in various HIPS, I've come to appreciate the capabilities of such software a bit more. However, even with learning mode, HIPS often strike me as having a serious flaw... They rely too much on user input. Click the wrong button -> bam, infected.

So, what HIPS software out there can be configured to ignore user input?

i.e.

Normal behavior: You're browsing somewhere in Firefox, and something tries to hijack your browser to run an evil payload. The HIPS asks if you want to proceed, and you click "Yes" without thinking. Much wailing and gnashing of teeth follows.

Default deny: Something tries to run an evil payload through your browser, and the HIPS immediately denies it, then gives you a popup notification about the denial. This way, the only way you could get infected is if you went to the hostile site while in learning mode.

---

Failing that... What HIPS incur some sort of delay when allowing an event? e.g.
- Requiring the user to click through an extra popup
- Having a countdown before the event can be allowed
- Requiring a selection from a drop-down menu, or a check box to be clicked
- Making the "Allow" button smaller and less visible than the "Deny" one

I know this sounds simple and probably stupid, but I suspect it's A Good Thing.
  #2  
Old July 8th, 2012, 12:30 AM
a256886572008's Avatar
a256886572008 a256886572008 is offline
Regular Poster
 
Join Date: Oct 2007
Posts: 95
Default Re: List of FW/HIPS with default deny modes?

comodo with the configuration enabled,

internet security
  #3  
Old July 8th, 2012, 10:00 PM
0strodamus's Avatar
0strodamus 0strodamus is offline
Frequent Poster
 
Join Date: Aug 2009
Location: US
Posts: 671
Default Re: List of FW/HIPS with default deny modes?

Malware Defender has a "Silent Mode" that will disable all prompting.
  #4  
Old July 9th, 2012, 07:39 PM
Blues7's Avatar
Blues7 Blues7 is offline
Frequent Poster
 
Join Date: May 2009
Location: Blue Ridge Mountains
Posts: 639
Default Re: List of FW/HIPS with default deny modes?

From the Comodo site fwiw...you'd need to research further to see if it meets your needs:

Quote:
Comodo Firewall uses a defaut-deny protection paradigm to make sure only known PC-safe applications are allowed to run. Auto Sandbox Technology™, a virtual operating environment for untrusted programs, means the default deny protection paradigm can be executed without disrupting the workflow of the user. Cloud based Behavior Analysis bolsters this proctection by helping to identify zero-day malware.


Also, PrivateFirewall requires (in manual mode / no auto-response) that you respond to and approve any pop-ups. If you don't respond to an alert, it's denied via policy.
__________________
Blues

Real-Time: ★ Emsisoft Internet Security ★ Sandboxie ★

On-Demand: ★ Drive Snapshot / Macrium Reflect ★ Shadow Defender ★

Last edited by Blues7 : July 9th, 2012 at 07:58 PM.
  #5  
Old July 9th, 2012, 08:07 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: List of FW/HIPS with default deny modes?

AppGuard Just Install and set in lock down mode thats it,no learning Apps,No user decisions to be made,Excutables are Denied.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #6  
Old July 9th, 2012, 08:15 PM
Blues7's Avatar
Blues7 Blues7 is offline
Frequent Poster
 
Join Date: May 2009
Location: Blue Ridge Mountains
Posts: 639
Default Re: List of FW/HIPS with default deny modes?

Quote:
Originally Posted by djohn
AppGuard Just Install and set in lock down mode thats it,no learning Apps,No user decisions to be made,Excutables are Denied.

In line with that...NoVirusThanks Exe Radar Free (or Pro) should be able to take care of the default deny aspect of keeping a process from running without your explicit say so.

I tested the free version and it's a very small (meg or two) install and has some nice features and options and is very user friendly.

Of course you'd have to have you firewall as a separate app.

(If the payload is coming via the browser I prefer to just stop it dead with Sandboxie with its auto-delete function upon closing the browser.)
__________________
Blues

Real-Time: ★ Emsisoft Internet Security ★ Sandboxie ★

On-Demand: ★ Drive Snapshot / Macrium Reflect ★ Shadow Defender ★
  #7  
Old July 9th, 2012, 08:22 PM
Gullible Jones
 
Posts: n/a
Default Re: List of FW/HIPS with default deny modes?

Thanks... Though Appguard and ExeRadar are "just" executable blockers, no? i.e. they won't stop a friendly process from being hijacked for malicious purposes? Or do they incorporate mechanisms to help reduce the risk of that?
  #8  
Old July 9th, 2012, 08:25 PM
Blues7's Avatar
Blues7 Blues7 is offline
Frequent Poster
 
Join Date: May 2009
Location: Blue Ridge Mountains
Posts: 639
Default Re: List of FW/HIPS with default deny modes?

Quote:
Originally Posted by Gullible Jones
Thanks... Though Appguard and ExeRadar are "just" executable blockers, no? i.e. they won't stop a friendly process from being hijacked for malicious purposes? Or do they incorporate mechanisms to help reduce the risk of that?

I'd check with kjdemuth on the capabilities of Exe Radar Pro since he's been running it for some time now and can give you the lowdown on its capabilities in that regard. Also, the developer has posted regularly in the forums. I wouldn't want to misspeak since I no longer have it installed.
__________________
Blues

Real-Time: ★ Emsisoft Internet Security ★ Sandboxie ★

On-Demand: ★ Drive Snapshot / Macrium Reflect ★ Shadow Defender ★
  #9  
Old July 9th, 2012, 08:30 PM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: List of FW/HIPS with default deny modes?

Quote:
Originally Posted by Gullible Jones
Thanks... Though Appguard and ExeRadar are "just" executable blockers, no? i.e. they won't stop a friendly process from being hijacked for malicious purposes? Or do they incorporate mechanisms to help reduce the risk of that?
See here in Lock Down.
Attached Images
 
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #10  
Old July 10th, 2012, 04:25 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: List of FW/HIPS with default deny modes?

Quote:
Originally Posted by Blues7
In line with that...NoVirusThanks Exe Radar Free (or Pro) should be able to take care of the default deny aspect of keeping a process from running without your explicit say so.

I tested the free version and it's a very small (meg or two) install and has some nice features and options and is very user friendly.

Of course you'd have to have you firewall as a separate app.

(If the payload is coming via the browser I prefer to just stop it dead with Sandboxie with its auto-delete function upon closing the browser.)
No argument from me Sandboxie is fantastic.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
 

Wilders Security Forums > Security Products > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:44 AM.


Powered by vBulletinฎ Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ฉ2002 - 2013, Wilders Security Forums