Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #18376  
Old September 6th, 2011, 01:37 AM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: What is your security setup these days?

Applocker sounds.... invasive =p I don't ever want to have to "toggle" my security on and off. But I would like to restrict some applications from being able to read/write to certain areas.

I don't want anything being able to access certain registry keys or files/folder that belong to my security software or browser or really anything that they don't need access to.
__________________
  #18377  
Old September 6th, 2011, 01:38 AM
1chaoticadult's Avatar
1chaoticadult 1chaoticadult is offline
Very Frequent Poster
 
Join Date: Oct 2010
Location: Chaotic Land
Posts: 2,219
Default Re: What is your security setup these days?

Quote:
Originally Posted by Hungry Man
Applocker sounds.... invasive =p I don't ever want to have to "toggle" my security on and off. But I would like to restrict some applications from being able to read/write to certain areas.

I don't want anything being able to access certain registry keys or files/folder that belong to my security software or browser or really anything that they don't need access to.

I don't toggle security off and on lol. I haven't turned off applocker since I started using it. I have no clue what you mean. If you are toggling applocker off and on then you don't have it setup correctly IMO. I'm not gonna convince you to use applocker. Either you do or you don't, but I'm happy using it.
__________________
OS Hardening + Applocker + ExploitShield + EMET + HitmanPro
  #18378  
Old September 6th, 2011, 01:39 AM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: What is your security setup these days?

Just moved my firewall alerts to Very High. Just to try it out...

What rules do you use for applocker? I basically want to block access to certain files/folder for all programs except the ones I say are ok.
__________________
  #18379  
Old September 6th, 2011, 01:42 AM
1chaoticadult's Avatar
1chaoticadult 1chaoticadult is offline
Very Frequent Poster
 
Join Date: Oct 2010
Location: Chaotic Land
Posts: 2,219
Default Re: What is your security setup these days?

Quote:
Originally Posted by Hungry Man
Just moved my firewall alerts to Very High. Just to try it out...

What rules do you use for applocker? I basically want to block access to certain files/folder for all programs except the ones I say are ok.

My rules are specific to my laptop in a way. Here is one thread http://www.wilderssecurity.com/showthread.php?t=272761 way you can setup applocker, look at MrBrian's posts. I basically use wat's method which is essentially auto-generate rules for exe and scripts, use default rules for MSI and DLLs but also create specific rules for dll files needed to run as well. Best thing to do it setup your rules and then use audit only mode to see what files applocker says wouldn't run if the rules were enforced. You also ask wat aka the applocker troll and he will help ya I'm sure
__________________
OS Hardening + Applocker + ExploitShield + EMET + HitmanPro

Last edited by 1chaoticadult : September 6th, 2011 at 01:50 AM.
  #18380  
Old September 6th, 2011, 01:47 AM
Konata Izumi's Avatar
Konata Izumi Konata Izumi is offline
Very Frequent Poster
 
Join Date: Nov 2008
Posts: 1,512
Default Re: What is your security setup these days?

Quote:
Originally Posted by Hungry Man
Removing Mamutu. I may add it back in eventually.

EDIT: Just removed it.

Also set up a sandbox for CCCP Media Player. Removed sandbox from Comodo. Comodo is now only sandboxing two vaio services.

I'm keeping CIS installed for the cloud scanners, so that it can sandbox the two vaio services, for the firewall, and for Defense+.


Oh wow! when did you get sandboxie pro?
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup .
built-in security + sandboxing fag.
  #18381  
Old September 6th, 2011, 01:49 AM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: What is your security setup these days?

A few days ago. Liking it quite a bit. Still working out kinks.

So anyone know if I can basically restrict certain files from being written to except by specific programs?
__________________
  #18382  
Old September 6th, 2011, 01:54 AM
Konata Izumi's Avatar
Konata Izumi Konata Izumi is offline
Very Frequent Poster
 
Join Date: Nov 2008
Posts: 1,512
Default Re: What is your security setup these days?

Quote:
Originally Posted by Hungry Man
A few days ago. Liking it quite a bit. Still working out kinks.

So anyone know if I can basically restrict certain files from being written to except by specific programs?

create a sandbox specifically for "each program" and use the resource access settings per-sandbox.

or you could do this manually for every process (see screenshot):
Attached Images
 
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup .
built-in security + sandboxing fag.

Last edited by Konata Izumi : September 6th, 2011 at 02:00 AM.
  #18383  
Old September 6th, 2011, 02:05 AM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: What is your security setup these days?

I like that but what I'm trying to do is block EVERY program EXCEPT for one from accessing certain files/ folder.

For example: Comodo apparently stores some config files in userland. I want Comodo to be the only software to access them - perhaps CCleaner as well.
Attached Images
 
__________________
  #18384  
Old September 6th, 2011, 02:53 AM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: What is your security setup these days?

Can I run Chrome at LowIL without problems?

EDIT: I guess so... doing it now! haha
__________________

Last edited by Hungry Man : September 6th, 2011 at 03:01 AM.
  #18385  
Old September 6th, 2011, 03:29 AM
Noob's Avatar
Noob Noob is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 5,225
Default Re: What is your security setup these days?

Quote:
Originally Posted by Hungry Man
Can I run Chrome at LowIL without problems?

EDIT: I guess so... doing it now! haha
Just try it
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #18386  
Old September 6th, 2011, 03:30 AM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: What is your security setup these days?

Seems to be working fine.

Hm... I ran it but processexplorer shows it as medium.
__________________
  #18387  
Old September 6th, 2011, 03:43 AM
Kernelwars's Avatar
Kernelwars Kernelwars is offline
Very Frequent Poster
 
Join Date: Aug 2010
Location: TX
Posts: 2,155
Default Re: What is your security setup these days?

Hungry you r having lot of fun with sandboxing my friend
__________________
Sandboxie | WinPatrol | CCE | MBAM | OpenDns with DnsCrypt
  #18388  
Old September 6th, 2011, 03:51 AM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: What is your security setup these days?

Yes, definitely!

Very frustrated with Chrome though... I'm trying to set it to low integrity but it won't work.
__________________
  #18389  
Old September 6th, 2011, 03:59 AM
Kernelwars's Avatar
Kernelwars Kernelwars is offline
Very Frequent Poster
 
Join Date: Aug 2010
Location: TX
Posts: 2,155
Default Re: What is your security setup these days?

Quote:
Originally Posted by Hungry Man
Yes, definitely!

Very frustrated with Chrome though... I'm trying to set it to low integrity but it won't work.
are you running the broker and child processes with low integrity level?
__________________
Sandboxie | WinPatrol | CCE | MBAM | OpenDns with DnsCrypt
  #18390  
Old September 6th, 2011, 04:02 AM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: What is your security setup these days?

I'm attempting to... but the broker won't go to LowIL.
__________________
  #18391  
Old September 6th, 2011, 05:49 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,439
Default Re: What is your security setup these days?

Quote:
Originally Posted by Hungry Man
I'm attempting to... but the broker won't go to LowIL.

What are you doing to apply the low integrity level?
  #18392  
Old September 6th, 2011, 07:02 AM
tomazyk's Avatar
tomazyk tomazyk is offline
Frequent Poster
 
Join Date: Dec 2006
Location: Slovenia
Posts: 601
Default Re: What is your security setup these days?

I removed AV so my new setup is a little lighter:

Resident:
ESET Nod32
Sandboxie (for browsers)
Malware Defender
EMET (for internet facing apps and apps that open files)
Router with SPI Firewall
Windows 7 firewall

On demand:
Hitman PRO
MBAM
Acronis True Image
Autoruns
Secunia PSI
__________________
ESET Nod32 AV • Sandboxie • EMET • Emsisoft EK • OpenDNS • Secunia PSI • Acronis TI
My security setup in detail
• Always remember you're unique, just like everyone else •

  #18393  
Old September 6th, 2011, 11:48 AM
The Seeker's Avatar
The Seeker The Seeker is offline
Frequent Poster
 
Join Date: Oct 2005
Location: Buxton, UK
Posts: 859
Default Re: What is your security setup these days?

With the amount of installing/uninstalling I do (as well as other stuff), running as a standard user was becoming irksome. Because of this, I've decided to go back to running as admin and have re-added avast! Free and removed Sandboxie. UAC is still set to Always Notify and I've beefed up my password to 16 characters.
__________________
Windows 8 Pro • WSA Complete • Ad Muncher • Image for Windows
  #18394  
Old September 6th, 2011, 12:05 PM
trjam's Avatar
trjam trjam is offline
Incredibly Massive Poster
 
Join Date: Aug 2006
Location: North Carolina
Posts: 8,615
Default Re: What is your security setup these days?

back to Avira.
__________________
Eset Antivirus
  #18395  
Old September 6th, 2011, 12:31 PM
wat0114
 
Posts: n/a
Default Re: What is your security setup these days?

Quote:
Originally Posted by Hungry Man
I basically want to block access to certain files/folder for all programs except the ones I say are ok.

Then instead of allowing all for %PROGRAMFILES% and all its subdirectories, you could instead simply, for example, allow for %PROGRAMFILES%\internet explorer, %PROGRAMFILES%\Firefox\*, %PROGRAMFILES%\Secuna\*, %PROGRAMFILES%\Java\* ...etc

IOW, you allow very specifically only those programs you want. The rest will be default-denied.

Alternatively, you could allow all under %PROGRAMFILES%, then add exceptions to those programs you want to deny.
  #18396  
Old September 6th, 2011, 12:35 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,439
Default Re: What is your security setup these days?

Quote:
Originally Posted by wat0114
Then instead of allowing all for %PROGRAMFILES% and all its subdirectories, you could instead simply, for example, allow for %PROGRAMFILES%\internet explorer, %PROGRAMFILES%\Firefox\*, %PROGRAMFILES%\Secuna\*, %PROGRAMFILES%\Java\* ...etc

IOW, you allow very specifically only those programs you want. The rest will be default-denied.

Alternatively, you could allow all under %PROGRAMFILES%, then add exceptions to those programs you want to deny.

The latter option would be better. I think it's Microsoft's recommendation also. I think I've read it somewhere; not sure, though.
  #18397  
Old September 6th, 2011, 12:47 PM
wat0114
 
Posts: n/a
Default Re: What is your security setup these days?

Quote:
Originally Posted by m00nbl00d
The latter option would be better. I think it's Microsoft's recommendation also. I think I've read it somewhere; not sure, though.

Right, specifically they recommend the allow with exceptions option as opposed to a combination of allow and deny rules. I just looked it up in my AppLocker manual
  #18398  
Old September 6th, 2011, 01:09 PM
CogitoTesting CogitoTesting is offline
Frequent Poster
 
Join Date: Jul 2009
Location: Sea of Tranquility
Posts: 896
Default Re: What is your security setup these days?

Quote:
Originally Posted by trjam
back to Avira.

Coming from where?

Thanks.
__________________
Genuine Machine : On Access and On Demand Security Apparatus: Maya, My Dearest Beloved
Fake Machine (Windows 7): Private Firewall 7, Avast Antivirus 7 (free), and BufferZone 4
  #18399  
Old September 6th, 2011, 01:14 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: What is your security setup these days?

Quote:
Originally Posted by m00nbl00d
What are you doing to apply the low integrity level?
icacls "C:\Users\your_username\AppData\Local\Google\Chrome\Application\Chrome.exe" /setintegritylevel (oi)(ci)Low


@Wat/m00n, I'll see what I can do.
__________________
  #18400  
Old September 6th, 2011, 01:17 PM
CogitoTesting CogitoTesting is offline
Frequent Poster
 
Join Date: Jul 2009
Location: Sea of Tranquility
Posts: 896
Default Re: What is your security setup these days?

Quote:
Originally Posted by Hungry Man
I'm attempting to... but the broker won't go to LowIL.

I was reading your signature and wow you have quite a set-up. Could you tell me why you removed IE9?

Thanks.
__________________
Genuine Machine : On Access and On Demand Security Apparatus: Maya, My Dearest Beloved
Fake Machine (Windows 7): Private Firewall 7, Avast Antivirus 7 (free), and BufferZone 4
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:16 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums