![]() |
|
#1
|
||||
|
||||
|
For all I know it has been there for a long time, but I just discovered that you can run MBAM's malicious website blocking feature real-time without enabling the filesystem protection module. The button to turn it on is under the 'Protection' tab. It's been running for a couple of days now on my computer without problems with my other browsing protection. Anyone have any information on it or know how effective it is? Or how long it's been available?
__________________
Sandboxie WebrootSA MBAM HMP EEK SecuniaPSI Router Win7x64FW NortonDNS Chrome: WOT Ghostery AB LastPass MacriumReflectPro pluginHD & rescue disks |
|
#2
|
|||
|
|||
|
As far as I'm aware, the IP blocker has been there a good long time. What it does ( at least my take on it) is check whether an IP address you're connecting to or attempting to is associated with known malware distribution or is currently hosting malware either through temporary infection or intentionally. If it determines the IP unsafe, it will refuse to either load the website associated with that website or the link/s on an otherwise safe website associated with the troubled IP address. It's usually quite effective in my past experiences with it. Sometimes a little too effective at times
What I mean by that is that there have been times that an IP wasn't infected, but, as with the case of P2P websites, were considered "risky" and therefore were blocked.It works very well and is a great tool to have in your defense if you so desire. Just be aware there may be times you and it may disagree ![]() |
|
#3
|
||||
|
||||
|
A recent update to Malwarebytes has allowed users to independently enabled/disable the File System Protection and Website Protection. Also eliminated having to reboot after installing the update.
__________________
My Current Setup |
|
#4
|
|||
|
|||
|
It uses a black listing of known malicious IP addresses. I would consider it basic protection at best. Problem is the sheer number of web sites that can be infected on a daily basis makes effective maintenance of black lists almost impossible.
Personally I like the proactive approach. Install the WOT add-on to your browser and you will get a visual display of if a web site is safe or not prior to selecting it. Also if your the "asleep at the keyboard type", WOT will warn you of a malicious web site prior to entering it. Bottom line is with today's malware, you need browser protection that will detect malicious activity via behavior, hueristics, and file signatures. |
|
#5
|
|||
|
|||
|
Please be cautious with WOT however. It can be a decent tool to get an idea of what to expect, but be aware a good amount of ratings are user-driven and not necessarily proof a website is good or bad.
|
|
#6
|
||||
|
||||
|
Quote:
I couldn't find the exact date, but I do know that v1.43 was released on December 30th, 2009, so it was sometime prior to that... a good 3 years ago. A little more info can be found here... IP Protection Module http://forums.malwarebytes.org/index...0&#entry162100 I run MBAM Pro on 3 machines, justenough, including the Website Blocking (IP Protection Module). I find it to be a far greater asset than any problems it might cause with blocking non-infected sites, and if I want access to a blocked site, it's easy to add it to the Ignore List.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams |
|
#7
|
|||
|
|||
|
Just because it rarely gets mentioned.....
MBAM also blocks uploads to malicious servers. Quote:
IP based is more proactive than domain based. One IP can have almost unlimited domains and something like WOT would have trouble keeping up rapidly generated domains while we should just block the IP outright. That being said WOT + MBAM is even better.
__________________
Bruce Harrison Malwarebytes Lead Researcher |
|
#8
|
||||
|
||||
|
Quote:
Good to know.
__________________
May you fly straight to heaven - but if you go to Hades - may Lethe run with Guinness |
|
#9
|
||||
|
||||
|
Quote:
![]() Quote:
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams |
|
#10
|
||||
|
||||
|
Thanks for the links and other good information. The more I learn about MBAM the more I appreciate what it can do. I knew that MBAM had malicious website blocking, but a couple of days ago I first saw that you have the choice to run it real-time without also running 'filesystem protection'. Since the internet is my main security risk, being able to use the malicious website blocking on its own is just what I need, glad it's become available.
__________________
Sandboxie WebrootSA MBAM HMP EEK SecuniaPSI Router Win7x64FW NortonDNS Chrome: WOT Ghostery AB LastPass MacriumReflectPro pluginHD & rescue disks |
|
#11
|
|||
|
|||
|
Quote:
__________________
Windows Vista Home Premium AVG IS SAS Pro The Lord is my Shepherd i shall not want Psalm 23;1 |
|
#12
|
||||
|
||||
|
Quote:
You may be right gery, I'm certainly capable of not seeing the separate website browsing option in MBAM when it's been right in front of me.
__________________
Sandboxie WebrootSA MBAM HMP EEK SecuniaPSI Router Win7x64FW NortonDNS Chrome: WOT Ghostery AB LastPass MacriumReflectPro pluginHD & rescue disks |
|
#13
|
||||
|
||||
|
Quote:
Version 1.51 (May 31st, 2011) Website Blocking is now disabled when protection is turned off. Version 1.60.0.1800 (December 27th, 2011) Settings for Protection Module behavior can be changed without protection being active. Malwarebytes Anti-Malware History / Updates
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams |
|
#14
|
|||
|
|||
|
~snip~
Quote:
I find this hard to believe. If MBAM Pro had this capabilty, it would be in essence operating as an outbound firewall. Great idea though especially for users of Vista and WIN 7 firewalls that only use inbound protection. |
|
#15
|
|||
|
|||
|
Quote:
Malwarebytes does not care what kind of connection it is or if its inbound or outbound. If the connection is to a black listed IP then the connection will fail and no data will be transmitted. This comes in handy for these situations: Undetected downlaoder attempts to gets it friends from blacklisted IP. Undetected trojan tries to upload your data to a blacklisted IP. Exploit on a site tries to pull payload from a blacklisted IP. I am sure you guys can think of more cases like this but the main point is that this technology does a lot more than block bad sites from loading. This is not a real firewall though as nothing is evaluated, connections are simply blocked. This allows you to use the firewall of your choice so that the two forms of web blocking combined can synergize each other.
__________________
Bruce Harrison Malwarebytes Lead Researcher Last edited by nosirrah : October 27th, 2012 at 11:24 PM. |
|
#16
|
||||
|
||||
|
this is a cool feature indeed
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13 |
|
#17
|
||||
|
||||
|
Will this conflict with Avira Premium(Paid)2013?
__________________
Desktop -Win 7 Home Premium 64 bit, NAT Router Firewall, Windows Firewall, Avira Antivirus Premium V13, MBAM PRO 1.75 , WOT, Win 7's System imaging. Netbook-Avira Antivirus Premium V13 , MBAM PRO 1.75, WOT. |
|
#18
|
|||
|
|||
|
Quote:
It is made to be used along with standard AV. But just to be sure, you can exclude Avira's folder in MBAM and vice versa. |
|
#19
|
||||
|
||||
|
Quote:
Good Explanation. MBAM is ~ Snipped as per TOS ~ A very good product on multiple levels. I hope they keep developing and improving the product at the same rate that they have since its inception. And -- MBAM achieved another impressive score in the most recent MRG tests. http://www.blog.mrg-effitas.com/ 100% passed in Zero Hour test. (SAS got 100% fail -- again) Good stuff. -ftp .
__________________
"I think computer viruses should count as life. I think it says something about human nature that the only form of life we have created so far is purely destructive. We've created life in our own image." —Stephen Hawking SEP 12.1, MBAM Pro, WinPatrol Plus, Norton DNS, ABP, EAM Scanner Last edited by JRViejo : October 27th, 2012 at 07:06 PM. Reason: Clever Alteration of a Possibly Offensive Phrase Removed - JRViejo |
|
#20
|
||||
|
||||
|
Quote:
No matter what, it remains a controversial issue whether MBAM can really co-exist effectively with any AV on any machine, with its real time protection activated. It is good enough for me to have it on demand.
__________________
Samsung Series 7 Chronos & Windows 8 (64bit) “We are the cosmos made conscious and life is the means by which the universe understands itself.” Brian Cox |
|
#21
|
||||
|
||||
|
Quote:
__________________
Desktop -Win 7 Home Premium 64 bit, NAT Router Firewall, Windows Firewall, Avira Antivirus Premium V13, MBAM PRO 1.75 , WOT, Win 7's System imaging. Netbook-Avira Antivirus Premium V13 , MBAM PRO 1.75, WOT. |
|
#22
|
||||
|
||||
|
Quote:
__________________
Samsung Series 7 Chronos & Windows 8 (64bit) “We are the cosmos made conscious and life is the means by which the universe understands itself.” Brian Cox |
|
#23
|
||||
|
||||
|
Quote:
__________________
Desktop -Win 7 Home Premium 64 bit, NAT Router Firewall, Windows Firewall, Avira Antivirus Premium V13, MBAM PRO 1.75 , WOT, Win 7's System imaging. Netbook-Avira Antivirus Premium V13 , MBAM PRO 1.75, WOT. |
|
#24
|
|||
|
|||
|
Quote:
No need to download whole database each time you update it. |
|
#25
|
||||
|
||||
|
Quote:
Before reading this, I wouldn't have thought to use MBAM as a reinforcement for the firewall. Great to hear, since the strength of the firewall that comes with Windows 7x64 has been a long-term unresolved question for me. I've tried all the main 3rd-party firewalls and always return to the Windows one because it is basically invisible in use, never causing any trouble and is probably adequate for the job. In my particular set-up what this blocking module adds to internet security is on its own more than worth the price of MBAM.
__________________
Sandboxie WebrootSA MBAM HMP EEK SecuniaPSI Router Win7x64FW NortonDNS Chrome: WOT Ghostery AB LastPass MacriumReflectPro pluginHD & rescue disks |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|