Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of Ghost Security Forums > Ghost Security Suite (GSS)
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #76  
Old March 17th, 2007, 06:54 PM
vlk vlk is offline
AV Expert
 
Join Date: Dec 2002
Posts: 513
Default Re: RegTest Released - Test your protection

BTW... just noticed this little tool and tried it out... Unfortunately I have to say that I don't think the way it's working is correct, actually.

That is, for simple registry blockers the results will certainly be positive. However, for more sophisticated/powerful tools (redirectors/virtualizers) it says the test failed even though it has not!

Redirectors/virtualizers work in the way that they make the application beleave that all the operations succeeded - but the underlying storage is left intact. When the application tries to read the data it has written, it gets them correctly - but these are in fact spoofed by the virtualizer.

It would be really helpful if your tool could handle this kind of sophisticated applications and correctly report that they're doing their job well. Otherwise, the results may be very confusing for the user.

Cheers
Vlk
  #77  
Old March 17th, 2007, 07:54 PM
EASTER.2010
 
Posts: n/a
Default Re: RegTest Released - Test your protection

KIS6 passes all this test. Other security related wares like AS/AT's and even some HIPS didn't fair as well on at least #1.
  #78  
Old March 17th, 2007, 09:51 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,409
Default Re: RegTest Released - Test your protection

GW passes it( Test one is Virtualized so it,s pass).
Test 2, that,s wonderful to see via GW policy notifications, suh a huge no. of policy restictions blocked by GW and test 2 can,t reboot the system, a total success of GW.
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #79  
Old March 17th, 2007, 10:06 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,409
Default Re: RegTest Released - Test your protection

Quote:
Originally Posted by vlk
BTW... just noticed this little tool and tried it out... Unfortunately I have to say that I don't think the way it's working is correct, actually.

That is, for simple registry blockers the results will certainly be positive. However, for more sophisticated/powerful tools (redirectors/virtualizers) it says the test failed even though it has not!

Redirectors/virtualizers work in the way that they make the application beleave that all the operations succeeded - but the underlying storage is left intact. When the application tries to read the data it has written, it gets them correctly - but these are in fact spoofed by the virtualizer.

It would be really helpful if your tool could handle this kind of sophisticated applications and correctly report that they're doing their job well. Otherwise, the results may be very confusing for the user.

Cheers
Vlk
Hi, it is a more than PASS in my opinion as malware is fooled in a way that it has done its job. I don,t see anything wrong in the test as long as u understand it.
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #80  
Old March 18th, 2007, 04:36 AM
vlk vlk is offline
AV Expert
 
Join Date: Dec 2002
Posts: 513
Default Re: RegTest Released - Test your protection

All I'm saying is that if there's a virtualizer in place, it's more than PASS but RegTest reports it as FAIL. Which is very confusing for the user (and all the "testers" out there who rely on RegTest's report).

Cheers
Vlk
  #81  
Old March 18th, 2007, 02:30 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: RegTest Released - Test your protection

vlk,
I agree with you. However, people playing with these tests is aware of lot of things
I don´t see the average Norton/McAfee/Trend user playing with security demos/tests.
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #82  
Old March 19th, 2007, 04:07 AM
vlk vlk is offline
AV Expert
 
Join Date: Dec 2002
Posts: 513
Default Re: RegTest Released - Test your protection

I don't quite agree. The mere goal of the RegTest program is to test certain functionality and report the result of the test to the user.

Now it turns out that for certain classes of programs, the reported result is incorrect. How can then the user tell if that's because the program is really unable to shield registry attack - or rather because RegTest just can't see it?

Take e.g. this test here: http://www.techsupportalert.com/security_HIPS.htm
I'm sure the author RELIED on the results reported by RegTest, without really looking for a reason if an application failed.

Cheers
Vlk
  #83  
Old March 19th, 2007, 02:56 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: RegTest Released - Test your protection

If I am going to do some public tests, I must know the inner workings of the products tested and the tools used for testing.
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #84  
Old March 19th, 2007, 03:41 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,409
Default Re: RegTest Released - Test your protection

Quote:
Originally Posted by vlk
Take e.g. this test here: http://www.techsupportalert.com/security_HIPS.htm
I'm sure the author RELIED on the results reported by RegTest, without really looking for a reason if an application failed.

Why you r so sure? I don,t think he is not aware of this simple fact.
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #85  
Old March 20th, 2007, 08:36 AM
Jason_R0's Avatar
Jason_R0 Jason_R0 is offline
Developer
 
Join Date: Feb 2005
Location: Australia
Posts: 1,038
Default Re: RegTest Released - Test your protection

Quote:
Originally Posted by vlk
BTW... just noticed this little tool and tried it out... Unfortunately I have to say that I don't think the way it's working is correct, actually.

That is, for simple registry blockers the results will certainly be positive. However, for more sophisticated/powerful tools (redirectors/virtualizers) it says the test failed even though it has not!

Redirectors/virtualizers work in the way that they make the application beleave that all the operations succeeded - but the underlying storage is left intact. When the application tries to read the data it has written, it gets them correctly - but these are in fact spoofed by the virtualizer.

It would be really helpful if your tool could handle this kind of sophisticated applications and correctly report that they're doing their job well. Otherwise, the results may be very confusing for the user.

Cheers
Vlk

It isn't really my responsibility to ensure people who use RegTest know how it works, and how a HIPS works either. We see this kind of misreporting of software testing in many places. Most people who read RegDefend's forum know a lot more about how HIPS work than most of the reviewers out there.

There is no real way of knowing if you are under a "virtualizer" as you called it or not, unless you specifically try and detect the presence of them. If you were at ring0 (like a driver) you could probably fool the "virtualizer" and get around it's protection, which is why you need protection against driver installations. However since most malware is ring3, I think RegTest serves the purpose of being a generic attack for registry defenders to test themselves against.
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of Ghost Security Forums > Ghost Security Suite (GSS) « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:36 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums