Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 10th, 2007, 05:20 PM
Monkey_Feces Monkey_Feces is offline
Regular Poster
 
Join Date: Aug 2006
Posts: 52
Default Defensewall whitelist questions

I'm a lazy ass and don't want to use DW's expert mode since I am no expert. Are the whitelisted program lists proactively created after some sort of application analysis? What if I accidentally run an altered version of a default whitelisted app? Would DW catch it and make it run untrusted? Basically, how safe am I when I use default mode vs expert?
  #2  
Old April 11th, 2007, 01:30 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Defensewall whitelist questions

HI,

You only have to enter the untrusted aps. There are some defaults, but make sure all your e-mail, chat, skype, webbrowser, p2p, gamespeak, phone download softeware is added (via a standard add file windows dialogue).
  #3  
Old April 11th, 2007, 04:14 AM
Monkey_Feces Monkey_Feces is offline
Regular Poster
 
Join Date: Aug 2006
Posts: 52
Default Re: Defensewall whitelist questions

Are you saying I should manually run all apps I open with the right click menu as untrusted? Secondly, does defensewall offer any user aid or information via context menus/tooltips? I find that its interface and help file are lacking. How will I know if I'm infected with anything if everything is done manually with defensewall? If that's the case, I'm thinking of sticking exclusively with Prevx1. Out of every other HIPS, it wasn't too intrusive like SSM or a resource hog like CyberHawk.
  #4  
Old April 11th, 2007, 06:22 AM
Ilya Rabinovich Ilya Rabinovich is offline
Developer
 
Join Date: Sep 2005
Posts: 1,516
Default Re: Defensewall whitelist questions

Quote:
Originally Posted by Monkey_Feces
Are you saying I should manually run all apps I open with the right click menu as untrusted?


There are four ways to run application as untrusted.

1. There is built-in list of known threatgate applications. It installs on demand or during installation process.
2. Add in into untrusted list manually.
3. With right-click menu.
4. Application have been created by untrusted process and already in untrusted list (default mode).

Quote:
Originally Posted by Monkey_Feces
Secondly, does defensewall offer any user aid or information via context menus/tooltips?


Yes, via Explorer's context menu.

Quote:
Originally Posted by Monkey_Feces
I find that its interface and help file are lacking.


Will be improved for v2.0.

Quote:
Originally Posted by Monkey_Feces
How will I know if I'm infected with anything if everything is done manually with defensewall?

1. If malware is within untrusted area- you will never been infected as malware won't be able install itself propertly into your system.

2. Definition of penetration is a not DW's job as it is not an expert HIPS. At least, current versions...
  #5  
Old April 11th, 2007, 07:40 AM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Defensewall whitelist questions

Quote:
Originally Posted by Ilya Rabinovich
1. If malware is within untrusted area- you will never been infected as malware won't be able install itself propertly into your system.
That's what I need in my frozen FDISR-snapshot, to protect me against infections in the period between TWO reboots.
Security softwares that prevent the installation and execution of malware have my full attention.
I have Anti-Executable and DefenseWall on my wish list already. Now I'm trying Sandboxie.
Even when these three softwares fail, I still have my frozen snapshot to remove the rest.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #6  
Old April 11th, 2007, 08:29 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Wink Re: Defensewall whitelist questions

HI, Monkey face

Defensewall is real easy. The default programs marked by DW as untrusted my wife uses are:
- MS outlook express mail
- MS internet explorer
- MS media player

Some weak programs are added by DW to this list by default
- hh.exe
- winhlp.exe
- tftp.exe
- ftp.exe
- ntvdm.exe

I added:
- LimeWire as her P2P program
- Scriptdefender (it intercepts all scripts, now all scripts run untrusted)
- 7Zip (is my default unzip program, DW handles windows zip, but with
this 'trick' all archives unpacked files are untrusted)
- DVD/CD Rom, the 2 USB-stick drives and the floppy drive
- The shared directory of limewire and the incomplete download directory
- Her Nokia 73 download manager

So all is very limited and very transparent.

Erik Albert,
When you use an anti-excutable (AE of FD which would be your first choice due to its compatibility with frozen snapshots, on-line armour, primary response safe connect) with default white and black lists and DefenseWall
you problably have the safest and user friendliest defense on top of your R.I.P.S protection

Last edited by Kees1958 : April 11th, 2007 at 08:41 AM.
  #7  
Old April 11th, 2007, 09:22 AM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Defensewall whitelist questions

Quote:
Originally Posted by Kees1958
Erik Albert,
When you use an anti-excutable (AE of FD which would be your first choice due to its compatibility with frozen snapshots, on-line armour, primary response safe connect) with default white and black lists and DefenseWall
you problably have the safest and user friendliest defense on top of your R.I.P.S protection
Finally somebody at Wilders, who fully understands me.

P.S. for all members :
R.I.P.S. doesn't exist, I heard about H.I.P.S. and C.I.P.S., but never R.I.P.S.
It's my sense of humor. LOL.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #8  
Old April 11th, 2007, 09:32 AM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,847
Default Re: Defensewall whitelist questions

Quote:
Originally Posted by ErikAlbert
Finally somebody at Wilders, who fully understands me.

P.S. for all members :
R.I.P.S. doesn't exist, I heard about H.I.P.S. and C.I.P.S., but never R.I.P.S.
It's my sense of humor. LOL.

Aren't Rest In Peace Systems run by funeral directors
  #9  
Old April 11th, 2007, 06:21 PM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Defensewall whitelist questions

Quote:
Originally Posted by Peter2150
Aren't Rest In Peace Systems run by funeral directors
That is a part of the joke, my R.I.P.S. can also end up in a complete disaster.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:54 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums