Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 11th, 2007, 04:25 PM
Rasheed187 Rasheed187 is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 1,883
Default Haute Secure (HIPS)

It´s probably crap, but check it out:

http://www.hautesecure.com/
  #2  
Old July 11th, 2007, 04:44 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Haute Secure (HIPS)

Have you used it Rasheed187?..install in VM and tell us if it is or not

Apparently has a good pedigree.
  #3  
Old July 11th, 2007, 06:36 PM
WSFuser WSFuser is offline
Incredibly Massive Poster
 
Join Date: Oct 2004
Location: California, USA
Posts: 10,324
Default Re: Haute Secure (HIPS)

Quote:
Today we support Internet Explorer. Soon we will also keep you safe from malware when using Firefox or Safari.
Since Im using Firefox I guess this does nothing for me.

Browsing the forums gives more info: How does Haute Secure protect me from malware?
__________________
  #4  
Old July 11th, 2007, 06:37 PM
tamdam tamdam is offline
Regular Poster
 
Join Date: Feb 2007
Posts: 88
Default Re: Haute Secure (HIPS)

actually, its an interesting concept reading from the website, it sounds awfully similar to linkscanner pro.

edit: anyway, if it is a HIPS it seems to be limited to internet based only - not things like cd-roms maybe.
  #5  
Old July 11th, 2007, 06:41 PM
Espresso's Avatar
Espresso Espresso is offline
Frequent Poster
 
Join Date: Aug 2006
Posts: 974
Default Re: Haute Secure (HIPS)

They have a 64bit version as well.

EDIT: Only works on Vista64, not XP x64.

Last edited by Espresso : July 13th, 2007 at 11:21 PM.
  #6  
Old July 11th, 2007, 07:26 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Haute Secure (HIPS)

Okay downloaded Haute Secure. 2.53Mb

Interesting, playing with it now.
Attached Thumbnails
Click image for larger version

Name:	hs1.JPG
Views:	30
Size:	178.6 KB
ID:	191413  

  #7  
Old July 11th, 2007, 09:27 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Haute Secure (HIPS)

Site & content blocking.

Haute Secure knows what I do about this site. Content is blocked when continued to the page.
Attached Thumbnails
Click image for larger version

Name:	hsblock.JPG
Views:	22
Size:	173.0 KB
ID:	191415  

  #8  
Old July 12th, 2007, 11:28 PM
Longboard's Avatar
Longboard Longboard is offline
Massive Poster
 
Join Date: Oct 2004
Location: Sydney, Australia
Posts: 3,097
Default Re: Haute Secure (HIPS)

Another little bait:
http://www.darkreading.com/document.asp?doc_id=128856
might be nice ?
Possibly not crap, might not be fully mature yet.
__________________
Don't confuse me with someone who actually knows what they are talking about.
Linux Registered user 469135
Please, support Medecins Sans Frontieres

Last edited by Longboard : July 12th, 2007 at 11:54 PM.
  #9  
Old July 13th, 2007, 03:06 PM
xuesisi's Avatar
xuesisi xuesisi is offline
Regular Poster
 
Join Date: Mar 2007
Posts: 71
Default Re: Haute Secure (HIPS)

LinkScannerPro is better than it
  #10  
Old July 13th, 2007, 06:46 PM
interstate ron's Avatar
interstate ron interstate ron is offline
Regular Poster
 
Join Date: Mar 2007
Location: over the hill from West "By God"
Posts: 65
Default Re: Haute Secure (HIPS)

I kinda like it so far and it's not a "pro" with a dollar sign.
__________________
Ron
  #11  
Old July 13th, 2007, 08:43 PM
dan_maran's Avatar
dan_maran dan_maran is offline
Very Frequent Poster
 
Join Date: Aug 2004
Location: Brooklyn, NY
Posts: 1,053
Default Re: Haute Secure (HIPS)

http://www.alex-ionescu.com/?p=44

http://blogs.zdnet.com/security/?p=366
__________________
<insert> catchy phrase here</instert>
Let's see how long I'm back for this time
  #12  
Old July 13th, 2007, 09:22 PM
Espresso's Avatar
Espresso Espresso is offline
Frequent Poster
 
Join Date: Aug 2006
Posts: 974
Default Re: Haute Secure (HIPS)

What's a good site to test this software? Preferably something benign.

It's a shame it doesn't work with IE shells like Sleipnir/Maxthon/etc.
  #13  
Old July 13th, 2007, 09:29 PM
gerardwil gerardwil is online now
Massive Poster
 
Join Date: Jan 2004
Posts: 4,510
Default Re: Haute Secure (HIPS)

I tried this one a few days ago but it messed up my machine, so take care.
That said I don't blame Haute Secure for that, could be my setup as well.

Gerard
  #14  
Old July 17th, 2007, 08:28 PM
silat silat is offline
Regular Poster
 
Join Date: Oct 2006
Posts: 135
Default Re: Haute Secure (HIPS)

Quote:
Originally Posted by Espresso
What's a good site to test this software? Preferably something benign.

It's a shame it doesn't work with IE shells like Sleipnir/Maxthon/etc.

Actually when I used Maxthon I got the Haute warnings but had no way to disable as the Haute Toolbar doesnt appear in Maxthon
__________________
Lew

Win7 64-Sandboxie Paid-
Malwarebytes and SAS On Demand Paid-VMware
Shadow Defender-Emisoft AntiMalware-WFC
  #15  
Old July 18th, 2007, 12:44 PM
Rasheed187 Rasheed187 is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 1,883
Default Re: Haute Secure (HIPS)

I checked it out on my VM and I really don´t see what´s so special about this tool. When it comes to the HIPS part, a tool like SSM for example does the except same job, and I have never been a fan of the approach taken by a tool like LinkScanner. Also, it might have been a conflict or something but the GUI was very sluggish, I really don´t see why these obviously smart and talented guys couldn´t come up with something better.

Last edited by Rasheed187 : July 18th, 2007 at 12:55 PM.
  #16  
Old July 19th, 2007, 10:40 AM
LUSHER's Avatar
LUSHER LUSHER is offline
Frequent Poster
 
Join Date: Feb 2007
Posts: 440
Default Re: Haute Secure (HIPS)

It's not meant to compete with SSM Pro.

A closer but not perfect fit would be comparing it with DefenseWall and Sandboxie maybe plus site blocking like SiteAdvisor. It's meant for more ordinary users seeking reasonable security than people like you Rasheed187 seeking to protect themselves from elite hackers. Remember only 0.01% of users are computer geeks.

Most of today's safe browsing security products either focus on advising the user when a bad website is visited, or filtering bad content using signatures. In Web 2.0, we do not consider that sufficient. Any site could be an amalgamation of content from numerous dynamic sources. And polymorphic exploit code and unannounced 0-day vulnerabilities mean sometimes signatures are too slow. That is why Haute Secure takes a multi-layer approach that includes signature-less protection against malware installation.

Haute Secure’s initial beta release is first and foremost a behavior-based malware filter. Haute Secure is capable of identifying and blocking the installation of malware that is delivered through exploitation of a vulnerability in the user’s browser or a browser plug-in. This is what we term “active protection.” Secondarily, it provides URL blocking services for known bad sites. We call this “passive protection.”

Active Protection

Haute Secure’s active protection uses a “soft sandbox” to identify malware installation attempts. (More information is available here: http://community.hautesecure.com/forums/t/29.aspx.) This is different than a traditional sandbox primarily in that it focuses only on trapping certain violations of a behavior rule set, rather than a strict quarantine policy. Soft sandboxing allows most normal actions during browsing to occur without interruption. The behavior rule set triggers when behavior consistent with a transparent installation of software is observed. While the actual rules are a bit more complicated, Haute Secure essentially looks for executable code to be installed on the computer without user consent. Hence, if a user with Haute Secure installs an ActiveX control, this will occur without interruption. If a user downloads and runs a program, this will occur without interruption. However, if the user navigates to a site and the site serves exploit code to the browser that it is not properly patched again, and that exploit code tries to install malware, this will be blocked. Haute Secure uses context clues to determine the difference between intentional and unintentional code installation.


http://community.hautesecure.com/blo...y/default.aspx
  #17  
Old July 19th, 2007, 03:39 PM
Espresso's Avatar
Espresso Espresso is offline
Frequent Poster
 
Join Date: Aug 2006
Posts: 974
Default Re: Haute Secure (HIPS)

Quote:
Originally Posted by silat
Actually when I used Maxthon I got the Haute warnings but had no way to disable as the Haute Toolbar doesnt appear in Maxthon

I just tried Maxthon and got no warning when I went to a crack site that is blocked in IE.
  #18  
Old July 23rd, 2007, 01:58 PM
Rasheed187 Rasheed187 is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 1,883
Default Re: Haute Secure (HIPS)

@ LUSHER

I agree, if it can stop drive by attacks it is indeed a very useful tool for non-geeks. I wish some expert could take this tool for a testdrive, to see how it actually performs against attacks. I also wonder if it might do a better job in protecting your browser than a regular HIPS. So far I´ve only gotten a couple of strange alerts for no apparent reason.

And I don´t believe it´s crap, but I do hope that they will make the GUI a bit more handy to use and easier to understand. Also, I´m not sure but I think it might conflict a bit with a couple of HIPS, so I don´t think I will install it on my box anytime soon. But still, I will keep my eye on this tool, because it sure looks interesting.

Last edited by Rasheed187 : July 23rd, 2007 at 02:06 PM.
  #19  
Old August 29th, 2007, 09:52 AM
Espresso's Avatar
Espresso Espresso is offline
Frequent Poster
 
Join Date: Aug 2006
Posts: 974
Default Re: Haute Secure (HIPS)

Anyone notice that CtUrlHistoryCatalog.ctlog in the C:\WINDOWS\Ct\ folder has ballooned to a large size? It was over 100MB on my sister's computer. She's been complaing of IE slowdowns and Haute Secure appears to be the culprit so I ditched it.
  #20  
Old August 30th, 2007, 02:30 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Haute Secure (HIPS)

Expresso,

Noticed this to. When you have opted for the feedback program, it will collect all sites you visit. So you allow HauteSecure to spy on you. But there is away to work around this by using autoruns:
1. Unselect the items marked in the attached images.
2. Reboot.
3. Copy the files CtUrlHistoryCatelog.Ctlog and CtUrlHistoryCatelog.Ctlog.ctidx from a location after you just fresh installed HauteSecure (so they will be ste back to their initial value of a few kliobytes)
4. Select the in step 1 unselected items
5. Reboot

And hautesecure is trimmed sown again.

Not the procedure one would imagine user friendly, but runningVista64 itis the onlly strong protection offered on IE
Go to auto
Thx
Attached Thumbnails
Click image for larger version

Name:	HauteSecure driver unselect.jpg
Views:	3
Size:	192.1 KB
ID:	193027  

Click image for larger version

Name:	HauteSecure Internet Explorer unselect.jpg
Views:	1
Size:	101.0 KB
ID:	193028  


Last edited by Kees1958 : August 30th, 2007 at 02:34 PM.
  #21  
Old August 31st, 2007, 09:41 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Haute Secure (HIPS)

Got a reply from the developers. Haute secure only tracks 5 days of URL history. In future the numbe rof days can be set by the configuration util.

Experiences so far:
Soft Sandbox feature:
Does not seem to slow doen the system, has not yet kicked in. Has the great advantage that it is the only containment offered on Vista64 at the moment.

URL protection
Although only a limited number of users are feeding the central engine, it kicks in at the usual suspect sites (warez etc).

No freeby nag screens or other Beta hassles, so for the time being it is a keeper.

Regards Kees
  #22  
Old September 1st, 2007, 04:47 AM
Sportscubs1272 Sportscubs1272 is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 328
Default Re: Haute Secure (HIPS)

Antivir Premium gave me a warning when I installed this on my machine.
  #23  
Old September 1st, 2007, 05:04 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Haute Secure (HIPS)

Okay,

A year ago a dll of Dynamic Security Agent was also flagged by Antivir. Do not install when you don't trust it.

Regards Kees
  #24  
Old September 1st, 2007, 09:28 AM
Perman Perman is offline
Very Frequent Poster
 
Join Date: Nov 2005
Posts: 2,156
Default Re: Haute Secure (HIPS)

Hi, folks: This puzzles me:Haute Secure Has flagged Wilders site as warning level1, bronze colour.
  #25  
Old September 2nd, 2007, 12:43 AM
Sportscubs1272 Sportscubs1272 is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 328
Default Re: Haute Secure (HIPS)

I had the (AntiVir) heuristics on high so that might be the problem!
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:26 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums