![]() |
|
||||
|
Quote:
I don't toggle security off and on lol. I haven't turned off applocker since I started using it. I have no clue what you mean. If you are toggling applocker off and on then you don't have it setup correctly IMO. I'm not gonna convince you to use applocker. Either you do or you don't, but I'm happy using it.
__________________
OS Hardening + Applocker + ExploitShield + EMET + HitmanPro |
|
||||
|
Just moved my firewall alerts to Very High. Just to try it out...
What rules do you use for applocker? I basically want to block access to certain files/folder for all programs except the ones I say are ok.
__________________
|
|
||||
|
Quote:
My rules are specific to my laptop in a way. Here is one thread http://www.wilderssecurity.com/showthread.php?t=272761 way you can setup applocker, look at MrBrian's posts. I basically use wat's method which is essentially auto-generate rules for exe and scripts, use default rules for MSI and DLLs but also create specific rules for dll files needed to run as well. Best thing to do it setup your rules and then use audit only mode to see what files applocker says wouldn't run if the rules were enforced. You also ask wat aka the applocker troll and he will help ya I'm sure ![]()
__________________
OS Hardening + Applocker + ExploitShield + EMET + HitmanPro Last edited by 1chaoticadult : September 6th, 2011 at 01:50 AM. |
|
||||
|
Quote:
Oh wow! when did you get sandboxie pro? ![]()
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup . built-in security + sandboxing fag. |
|
||||
|
Quote:
create a sandbox specifically for "each program" and use the resource access settings per-sandbox. or you could do this manually for every process (see screenshot):
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup . built-in security + sandboxing fag. Last edited by Konata Izumi : September 6th, 2011 at 02:00 AM. |
|
||||
|
I like that but what I'm trying to do is block EVERY program EXCEPT for one from accessing certain files/ folder.
For example: Comodo apparently stores some config files in userland. I want Comodo to be the only software to access them - perhaps CCleaner as well.
__________________
|
|
||||
|
Quote:
![]()
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736 SRP - UAC - EMET Browser: Google Chrome v25.xx Windows 7 Ultimate x64 |
|
||||
|
Quote:
![]()
__________________
Sandboxie | WinPatrol | CCE | MBAM | OpenDns with DnsCrypt |
|
|||
|
Quote:
What are you doing to apply the low integrity level? |
|
||||
|
I removed AV so my new setup is a little lighter:
Resident: Sandboxie (for browsers) Malware Defender EMET (for internet facing apps and apps that open files) Router with SPI Firewall Windows 7 firewall On demand: Hitman PRO MBAM Acronis True Image Autoruns Secunia PSI
__________________
ESET Nod32 AV • Sandboxie • EMET • Emsisoft EK • OpenDNS • Secunia PSI • Acronis TI My security setup in detail • Always remember you're unique, just like everyone else • |
|
||||
|
With the amount of installing/uninstalling I do (as well as other stuff), running as a standard user was becoming irksome. Because of this, I've decided to go back to running as admin and have re-added avast! Free and removed Sandboxie. UAC is still set to Always Notify and I've beefed up my password to 16 characters.
__________________
Windows 8 Pro • WSA Complete • Ad Muncher • Image for Windows |
|
|||
|
Quote:
Then instead of allowing all for %PROGRAMFILES% and all its subdirectories, you could instead simply, for example, allow for %PROGRAMFILES%\internet explorer, %PROGRAMFILES%\Firefox\*, %PROGRAMFILES%\Secuna\*, %PROGRAMFILES%\Java\* ...etc IOW, you allow very specifically only those programs you want. The rest will be default-denied. Alternatively, you could allow all under %PROGRAMFILES%, then add exceptions to those programs you want to deny. |
|
|||
|
Quote:
The latter option would be better. I think it's Microsoft's recommendation also. I think I've read it somewhere; not sure, though. |
|
|||
|
Quote:
Right, specifically they recommend the allow with exceptions option as opposed to a combination of allow and deny rules. I just looked it up in my AppLocker manual ![]() |
|
|||
|
Quote:
Coming from where? Thanks.
__________________
Genuine Machine : On Access and On Demand Security Apparatus: Maya, My Dearest Beloved Fake Machine (Windows 7): Private Firewall 7, Avast Antivirus 7 (free), and BufferZone 4 |
|
||||
|
Quote:
@Wat/m00n, I'll see what I can do.
__________________
|
|
|||
|
Quote:
I was reading your signature and wow you have quite a set-up. Could you tell me why you removed IE9? Thanks.
__________________
Genuine Machine : On Access and On Demand Security Apparatus: Maya, My Dearest Beloved Fake Machine (Windows 7): Private Firewall 7, Avast Antivirus 7 (free), and BufferZone 4 |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|