Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 28th, 2005, 12:47 PM
starfish_001's Avatar
starfish_001 starfish_001 is offline
Very Frequent Poster
 
Join Date: Jan 2005
Posts: 1,015
Default HIPs and Sandboxes

Not a strong area for me So I was wondering as a Process Guard / SNS user what the likes of DefenceWall and BufferZone actually give me. I liked Defencewall when I ran the Beta but ... Given I have these PG/SNS already and could run processes untrusted by launching like below:

http://msdn.microsoft.com/library/de...re11152004.asp

Michael Howard outlined how you can programmatically spawn a process that runs with reduced privilege, even if you are logged on as an administrator. The aim was to run processes performing Internet functions (applications most subject to attack), such as Web browsers and e-mail clients, in reduced privilege to decrease the damage potential of any malware using these agents as attack vectors.


What am I missing?
  #2  
Old December 28th, 2005, 02:38 PM
Notok's Avatar
Notok Notok is offline
Very Frequent Poster
 
Join Date: May 2004
Location: Portland, OR (USA)
Posts: 2,958
Default Re: HIPs and Sandboxes

Running things as a non-admin is always a good idea, even if it is only with something like DropMyRights. DefenseWall will give you stronger protection that's a little easier to manage, but DropMyRights with ProcessGuard makes for some very strong protection as well. The one advantage you would have with something like DefenseWall is that once something is inside the sandbox area, it can't even see anything outside of the sandbox, which is not true for DropMyRights.

Either way you go is going to give you very strong protection, so I think it's mainly up to you. My own preference is to use DefenseWall.
__________________
Security is not a brand name.

NSA security configuration guides -- Best Practices for Securing a Home Network
  #3  
Old December 28th, 2005, 02:43 PM
starfish_001's Avatar
starfish_001 starfish_001 is offline
Very Frequent Poster
 
Join Date: Jan 2005
Posts: 1,015
Default Re: HIPs and Sandboxes

Notok

Thanks - I came to that conclusion - defencewall does make the admin very nice - I'd forgotten about being able to see out of the sandbox area
  #4  
Old December 28th, 2005, 02:46 PM
Notok's Avatar
Notok Notok is offline
Very Frequent Poster
 
Join Date: May 2004
Location: Portland, OR (USA)
Posts: 2,958
Default Re: HIPs and Sandboxes

You can actually run DW and DRM together, for that extra paranoid(tm) protection! (I did for a while, and actually didn't have any problems at all.)
__________________
Security is not a brand name.

NSA security configuration guides -- Best Practices for Securing a Home Network
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:07 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums