Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old January 23rd, 2007, 09:49 PM
dRag0nMa dRag0nMa is offline
Regular Poster
 
Join Date: Aug 2003
Location: SH China
Posts: 77
Default Re: DefenseWall as a HIPS

i give it a total uninstalled.
i get BSOD every day, even i just fire the IE.
btw. i use the latest version w/ expert mode
  #27  
Old January 24th, 2007, 03:23 AM
Ilya Rabinovich Ilya Rabinovich is offline
Developer
 
Join Date: Sep 2005
Posts: 1,516
Default Re: DefenseWall as a HIPS

Quote:
Originally Posted by dRag0nMa
i give it a total uninstalled.
i get BSOD every day, even i just fire the IE.
btw. i use the latest version w/ expert mode

Send me minidump files for those BSOD's via forum- my e-mails are still ain't working.
  #28  
Old January 29th, 2007, 10:21 AM
Rasheed187 Rasheed187 is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 1,883
Default Re: DefenseWall as a HIPS

Thanks for the screenshots Ilya, I think the GUI will be just fine as long as you donīt forget the basic rules like: "Applications must remember its screensize + position, same goes for columns (+ remember column-sorting"). Btw, I now know what I forgot to ask: In Sandboxie, every change to the file system and registry will be made only in the virtual sandbox. So apps are not able to do any damage to the real system. But is this the same with DW? This is whatīs bugging me a bit.

Last edited by Rasheed187 : January 29th, 2007 at 10:32 AM.
  #29  
Old January 30th, 2007, 04:38 PM
Ilya Rabinovich Ilya Rabinovich is offline
Developer
 
Join Date: Sep 2005
Posts: 1,516
Default Re: DefenseWall as a HIPS

Quote:
Originally Posted by Rasheed187
Btw, I now know what I forgot to ask: In Sandboxie, every change to the file system and registry will be made only in the virtual sandbox.

Correction- will be made within virtualization container. It is standard file system folder and registry key in case of SBIE.

Quote:
Originally Posted by Rasheed187
So apps are not able to do any damage to the real system. But is this the same with DW? This is whatīs bugging me a bit.

No, it is not the same. DW has policy-based file system protection instead of virtualization. Also, registry protection is, mostly, policy-based also (but there is limited virtualization). The point is that if sandbox gives you 95-98% of automatical defense against unknown, 0-day malware. DefenseWall do this job and, in future, will be able to do it even better. As about defense rate- well, maybe, file system virtualization may give some little advantages, but the price for that is standard- simplicity in everyday use and learning curve. In fact, classical HIPS may give you ~99% of defense- but it will be impossible to use it due to huge number of popups. This balance- simplicity and defense rate- is highly important thing!
  #30  
Old January 31st, 2007, 03:03 PM
Defenestration Defenestration is offline
Frequent Poster
 
Join Date: Jul 2004
Posts: 990
Default Re: DefenseWall as a HIPS

Ilya - re. the rollback feature, does this mean it's possible to view all changes made to the file system and registry by a process, with detailed info on what it used to be and what it has been changed to ?
  #31  
Old January 31st, 2007, 03:23 PM
Drew99GT Drew99GT is offline
Frequent Poster
 
Join Date: Jun 2006
Location: Colorado Springs
Posts: 270
Default Re: DefenseWall as a HIPS

Is there a free version of Defensewall?
  #32  
Old January 31st, 2007, 04:35 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: DefenseWall as a HIPS

Quote:
Originally Posted by Drew99GT
Is there a free version of Defensewall?
No
Thereīs a 30-day trial.
  #33  
Old February 1st, 2007, 07:42 AM
Ilya Rabinovich Ilya Rabinovich is offline
Developer
 
Join Date: Sep 2005
Posts: 1,516
Default Re: DefenseWall as a HIPS

Quote:
Originally Posted by Defenestration
Ilya - re. the rollback feature, does this mean it's possible to view all changes made to the file system and registry by a process, with detailed info on what it used to be and what it has been changed to ?

Not all of them. "Time machine" from Apple requires second hard drive!
  #34  
Old February 14th, 2007, 09:51 AM
Rasheed187 Rasheed187 is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 1,883
Default Re: DefenseWall as a HIPS

@ Ilya Rabinovich

But isnīt DefenseWall basicly almost the same as GESwall? So itīs restricting apps with policies so that malicous apps canīt damage a system? But apps can still access certain parts of the real file sytem and registry otherwise they wouldnīt be able to work, and thatīs why you need the rollback feature, correct?

I donīt know why but I still canīt visualize it completely, sorry about that. But with Sandboxie I know that the file system and registry will not be touched, with that I mean they will be virtualized and changes are kept in the sandbox. Iīm not saying that itīs better, but Iīm just trying to figure things out.
  #35  
Old February 14th, 2007, 01:40 PM
Ilya Rabinovich Ilya Rabinovich is offline
Developer
 
Join Date: Sep 2005
Posts: 1,516
Default Re: DefenseWall as a HIPS

Quote:
Originally Posted by Rasheed187
But isnīt DefenseWall basicly almost the same as GESwall? So itīs restricting apps with policies so that malicous apps canīt damage a system? But apps can still access certain parts of the real file sytem and registry otherwise they wouldnīt be able to work, and thatīs why you need the rollback feature, correct?

Basically- yes, you are correct.

Quote:
Originally Posted by Rasheed187
But with Sandboxie I know that the file system and registry will not be touched, with that I mean they will be virtualized and changes are kept in the sandbox.

Not in the sandbox, but inside virtualization container. In case of SBIE is it a folder within "Documents and Settings" one.
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:56 AM.


Powered by vBulletinŪ Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright Đ2002 - 2013, Wilders Security Forums