![]() |
|
#1
|
||||
|
||||
|
http://www.outpostfirewall.com/forum...277#post202277
I have a question for MS. Why is explorer so h.ll bent for leather to access screens, clipboards and keystrokes? I've done the restraints (any user with a firewall can) and I can still do everything I need to do on the www.
__________________
Escalader ![]() i7 8 GB RAM Notebook, 1TB External Drive Sandboxie, Nod32, OP FW Pro, KeyScrambler, MVPS HOSTS File IE 9 Hardened Active X,SmartScreen,Tracking Protection Paragon Backup and Imaging |
|
#2
|
||||
|
||||
|
I've always blocked explorer.exe from Internet comms and never had a problem doing so. There should then be no reason to restrict its inter-process actions with HIPS because its actions are, after all, being contained within the pc.
__________________
Win 7x64 Ultimate SUA | UAC @ Max | AppLocker w/DLL enforcement | Win fw w/advanced security| EMET 3.5 | Chrome w/AdBlock+ | GPO restrictions | Bitlocker and Truecrypt | ShadowProtect images | IFW data backups + dual boot to XP Pro: GPO, SRP, Jetico firewall w/Process Attack filter |
|
#3
|
||||
|
||||
|
Quote:
Thanks, but what I'm not as confident as that about these inter-process NOT passing clip board data etc along to other executables that DO have www access.
__________________
Escalader ![]() i7 8 GB RAM Notebook, 1TB External Drive Sandboxie, Nod32, OP FW Pro, KeyScrambler, MVPS HOSTS File IE 9 Hardened Active X,SmartScreen,Tracking Protection Paragon Backup and Imaging |
|
#4
|
||||
|
||||
|
Quote:
Good point for sure, although I think you have to be careful not to overdo things, otherwise there's the risk of breaking required functionality. The MS explorer.exe that resides in %Windir% has to be considered, at least to considerable extent, a trusted process. If those restrictions you applied are working fine with no negative impact on the sytem, then all the better for you ![]()
__________________
Win 7x64 Ultimate SUA | UAC @ Max | AppLocker w/DLL enforcement | Win fw w/advanced security| EMET 3.5 | Chrome w/AdBlock+ | GPO restrictions | Bitlocker and Truecrypt | ShadowProtect images | IFW data backups + dual boot to XP Pro: GPO, SRP, Jetico firewall w/Process Attack filter |
|
#5
|
||||
|
||||
|
Quote:
Well, my plan has broken down! I can't get the control panel to activate!
__________________
Escalader ![]() i7 8 GB RAM Notebook, 1TB External Drive Sandboxie, Nod32, OP FW Pro, KeyScrambler, MVPS HOSTS File IE 9 Hardened Active X,SmartScreen,Tracking Protection Paragon Backup and Imaging |
|
#6
|
|||
|
|||
|
cant get it to activate? you mean open?
|
|
#7
|
|||
|
|||
|
I'm not familiar with Outpost and how it stores its rules and settings or if it allows you to save, export, and import existing rulesets. Assuming that it does, I'd hope that:
1, you made a backup of the starting ruleset before you began tightening explorer permissions. 2, you have been at least documenting the details of the changes you're making or that you're saving rulesets as you go, last known good or similar. I'd also hope that you're making changes 1 or 2 at a time, then checking through your system to see if anything broke or if there's any adverse effects. If nothing else, make a full backup/image of the OS before you go in too deep. Tightening and experimenting are not only useful, they're good for teaching the details about how your system operates, as long as you have a way back if things go wrong.
__________________
Sitting in a bunker, here behind my wall, waiting for the worms to come. |
|
#8
|
||||
|
||||
|
Quote:
Exactly! It opens then says explorer has stopped working.
__________________
Escalader ![]() i7 8 GB RAM Notebook, 1TB External Drive Sandboxie, Nod32, OP FW Pro, KeyScrambler, MVPS HOSTS File IE 9 Hardened Active X,SmartScreen,Tracking Protection Paragon Backup and Imaging |
|
#9
|
||||
|
||||
|
Explorer is an integral part of Windows. Restrict it too much and the OS starts to break down. I'm sure it's fun to see how far you can take it before it all crumbles. Kind of like taking a thumbscrew to ... well, never mind
![]() |
|
#10
|
||||
|
||||
|
I take this approach with everything on my setup, not just Explorer. What I'll do with it, as with everything else, is block it on a per case basis, and see if I'm still able to carry out the action. If not, then I'll do it again and grant it the access it needs that time and check the box to remember it. I've never had my system crash as a result.
I have keyboard & computer monitor access blocked outright. Everything else is set to Ask, and only allowed on per case basis. Internet access blocked as well. And I haven't gotten an Explorer popup in quite some time.
__________________
XP Pro SP3: Comodo FW/D+ 5.10 ▪ Sandboxie 3.76 ▪ VT Hash Check 1.01 ▪ OpenVPN 2.2.1 ▪ VirtualBox |
|
#11
|
||||
|
||||
|
Impressive I must say. That's a tight ship you are running!
|
|
#12
|
||||
|
||||
|
I can feel the heavy pain in setting this up... you must have some free time at disposal
![]() |
|
#13
|
||||
|
||||
|
It's really not that difficult. You open control panel, or whatnot, and realize Explorer needs some type of access... you check the box to remember it. You never hear from it again. For about the first 2 weeks after a fresh install this happens the first time you run an app, you set the appropriate access, then it quiets down. Now I never hear a peep out of it.
And for programs that are constantly reading/writing to/deleting new file names, like CCleaner for example, the popups would never end, so you simply allow it that type of access permanently. I'd love to be able to lie and say it was a lifetimes work on my part, like a house wife with a Betty Crocker cake that acted like she slaved in the kitchen all day... but it really didn't require much time/effort on my part at all. This whole notion that HIPS are some monumental (chatty) inconvenience is severely flawed, drudged up by people that really don't understand how to deploy them effectively.
__________________
XP Pro SP3: Comodo FW/D+ 5.10 ▪ Sandboxie 3.76 ▪ VT Hash Check 1.01 ▪ OpenVPN 2.2.1 ▪ VirtualBox |
|
#14
|
||||
|
||||
|
Good to hear its not a monumental pain
|
|
#15
|
|||
|
|||
|
Quote:
__________________
Sitting in a bunker, here behind my wall, waiting for the worms to come. |
|
#16
|
|||
|
|||
|
Salut,
Whether to allow explorer.exe in the local network, otherwise windows does not like. When you sometimes open files in Explorer, explorer.exe may request access to the internet, often for updates of the file open, to allow once. Il faut autoriser explorer.exe dans le réseau local, sinon windows n'aime pas. Quand vous ouvrez parfois des fichiers dans l'explorateur, explorer.exe peut demander à accéder à internet, souvent pour des mises à jour du fichier ouvert, à autoriser UNE fois. |
|
#17
|
||||
|
||||
|
Quote:
yepperz
__________________
XP Pro SP3: Comodo FW/D+ 5.10 ▪ Sandboxie 3.76 ▪ VT Hash Check 1.01 ▪ OpenVPN 2.2.1 ▪ VirtualBox |
|
#18
|
||||
|
||||
|
Quote:
How does the typical pc user know how to respond to the alerts of potentially 14 different types of actions explorer.exe might attempt to perform (screenshot examples)? Quote:
If this is the case, then something broke down earlier in the security enforcement process, if indeed an application did get exploited; possibly the user made a wrong decision answering a HIPS alert, or allowed a malicious script to unleash through the web browser.
__________________
Win 7x64 Ultimate SUA | UAC @ Max | AppLocker w/DLL enforcement | Win fw w/advanced security| EMET 3.5 | Chrome w/AdBlock+ | GPO restrictions | Bitlocker and Truecrypt | ShadowProtect images | IFW data backups + dual boot to XP Pro: GPO, SRP, Jetico firewall w/Process Attack filter |
|
#19
|
||||
|
||||
|
Quote:
No one knows, and it all ends with accepts/permit all, otherwise it may lose functionality of your PC. For this I find that HIPS/HOPS alert software is not usable for average user.
__________________
We secure the world ;-) |
|
#20
|
||||
|
||||
|
No typical user would ever even think attempting this. Heck, they barely keep their AV updated. Clearly this is pretty close to the last inner circle of protection. It's certainly not the first thing in any security umbrella but something for somebody that wants to play around with a paranoid level security setup.
It is, after all, an interesting experiment. That's how it should be viewed. |
|
#21
|
|||
|
|||
|
Quote:
Quote:
__________________
Sitting in a bunker, here behind my wall, waiting for the worms to come. |
|
#22
|
||||
|
||||
|
Quote:
I place lots of emphasis on the most common gateways for malware, especially the web browser. Quote:
As long as the attacks are unsuccessful in delivering their payload, I'm not too concerned. For me eliminating or at least greatly reducing scripting attacks through the browser should take care of pretty much everything. Quote:
True enough. It's just that I found them them to be high maintenance, in spite of what was suggested earlier in this thread. Even AppLocker with DLL enforcement enabled, where there are several hash rules in place (I like hash rules for non-protected directories) can and does require routine maintenance to keep the hash rules up to date when the file's hash changes or when hash rules are created for new applications. Apparmor in Linux is nice because it usually means exercising the profile via sudo aa-logprof to help in generating rules that may have been missed during the original profiling exercise. It's been very low maintenance for me so far.
__________________
Win 7x64 Ultimate SUA | UAC @ Max | AppLocker w/DLL enforcement | Win fw w/advanced security| EMET 3.5 | Chrome w/AdBlock+ | GPO restrictions | Bitlocker and Truecrypt | ShadowProtect images | IFW data backups + dual boot to XP Pro: GPO, SRP, Jetico firewall w/Process Attack filter |
|
#23
|
|||
|
|||
|
Quote:
__________________
Sitting in a bunker, here behind my wall, waiting for the worms to come. |
|
#24
|
||||
|
||||
|
Quote:
They don't. A "typical user" doesn't belong anywhere near a HIPS in the first place though, rendering that point moot. A typical user in fact shouldn't use any kind of filtering whatsoever, other than the packet filtering their router/inbound FW provides automatically. Nor should they use any program that requires user input/decisions... because the "typical user" is an idiot. That shouldn't stop the rest of us from implementing the measures. There is nothing high maintenance about it whatsoever to me. It is set-&-forget protection for me now, and has been ever since those initial 2 weeks or so. It is now, as noone put it, hardening... completely invisible protection.
__________________
XP Pro SP3: Comodo FW/D+ 5.10 ▪ Sandboxie 3.76 ▪ VT Hash Check 1.01 ▪ OpenVPN 2.2.1 ▪ VirtualBox |
|
#25
|
||||
|
||||
|
I only posed the question because in post #13 you stated it's really not difficult, so I thought you implied it's not difficult for anyone in particular.
__________________
Win 7x64 Ultimate SUA | UAC @ Max | AppLocker w/DLL enforcement | Win fw w/advanced security| EMET 3.5 | Chrome w/AdBlock+ | GPO restrictions | Bitlocker and Truecrypt | ShadowProtect images | IFW data backups + dual boot to XP Pro: GPO, SRP, Jetico firewall w/Process Attack filter |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|