![]() |
|
#1
|
||||
|
||||
|
NeoavaGuard HIPS has some unique features as compraed to other classical HIPS. I tried three malware samples.
1- Aliz worm 2- Sober worm Both these worm spread themselves by sending their copies by e-mail. They get the e-mail addresses from windows address book and Sober worm als scans many files like text file on the PC and finds e-mail addresses. 3- GPcode trojan- A malware that encrpts many files on infected PC( like text files) causing data loss. NG gave pop ups for all these actions though it was not fully successful to stop the damage( like it did not stopped the encrption of text files by malware) but it,s interesting to see such a functionality. I have not seen such filters in any other HIPS( atleast upto best of my knowledge). Am i right? I have made thread on Comdod forums to add such filters in CFP. What are your thoughts? Thanks
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, Last edited by aigle : July 5th, 2008 at 05:03 PM. |
|
#2
|
||||
|
||||
|
Some more screenshots here!
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, Last edited by aigle : July 5th, 2008 at 05:04 PM. |
|
#3
|
|||
|
|||
|
No other thoughts, than that NeoavaGuard didn't do a very good job and that these three threats are executables, which are easy to kill with better security softwares. Thanks for the tests, but NeoavaGuard was never on my list, BUT I need a Script Blocker with artificial intelligence.
![]()
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
Last edited by ErikAlbert : July 5th, 2008 at 05:28 PM. |
|
#4
|
||||
|
||||
|
I knew that already Eric!
This thread is for people with a taste different from urs. We don,t want to kill them, that,s so easy. Why want to remove their venom.But thanks for the comments. ![]()
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#5
|
||||
|
||||
|
It just goes to show what a real tragedy it was when the developer of NG ceased maintaining it. In my opinion, he should resume working on it --- the *competition* is getting thinner every day, in both the number & the competency of classical HIPS.
I think that a re-vitalized NG would quickly become a big winner -- and a major prospect for buy-out by one of the AV outfits.
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender |
|
#6
|
|||
|
|||
|
Quote:
![]()
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
|
|
#7
|
||||
|
||||
|
aigle, have you tested how effective the partition protection of neova guard is? ever hear of "bypassdisk.exe"? i wonder if neova guard or any other hips would catch the program before it attempted to destroy the disk (if it was allowed to execute of course).
__________________
Current Security Apps - Desktop/Laptop : SRP + LUA + KAFU, Antivir (free - on demand) LUA+SRP+KAFU = WIN!!!111 |
|
#8
|
||||
|
||||
|
Quote:
I wholeheartily agree. It completely escapes me why on earth these makers don't just continue to build on apps (HIPS) like these and make them even better then before. This is i hope a temporary trend and not something we're going to be seeing happen on a regular basis. I admit i haven't even got around to trying this one but it's no less still useful and any one could easily overtake the field at some point in time. And bellgamin, you're very sadly right, it's indeed a tragedy when very promising security applications without warning cease to proceed and gives serious rise to concerns. We need MORE innovations of this nature no matter how useful sandboxes & virtual systems, AS/AV's etc. are in keeping our PC's protected. Allow me to compliment also on the screenshots, thanks a ton for taking the time to show them. Regards EASTER
__________________
★AX 64 Time Machine★
★Shadow Defender★|
Maxthon 4 | X Iron 17.0 | Chromium 19.0 | Pale Moon 20.1
¶Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot¶
¶Linux Mint 14 MATE¶ |
|
#9
|
||||
|
||||
|
Quote:
![]()
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#10
|
|||
|
|||
|
Quote:
I don't want to sound flip, but I believe it has something to do with rent/food/living expenses. The market is saturated with offerings, which severely dilutes their economic potential. Blue |
|
#11
|
||||
|
||||
|
Quote:
As far as I know some body in the past tested NG against KillDisk and NG was able to protect against it. That,s partition table protection. However I can,t say about bypassdisk. Can you PM me the sample by the way, if u have? Any more tests with this utility/ POC? Thanks
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, Last edited by aigle : July 5th, 2008 at 05:51 PM. |
|
#12
|
||||
|
||||
|
Quote:
Unfortunately, but then they also reserve the option of selling the source or sitting on it which these days can gather rust very fast. So in retrospect, the end user or potential customer must take a seat and wait out for either something similar or entirely new.
__________________
★AX 64 Time Machine★
★Shadow Defender★|
Maxthon 4 | X Iron 17.0 | Chromium 19.0 | Pale Moon 20.1
¶Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot¶
¶Linux Mint 14 MATE¶ |
|
#13
|
|||
|
|||
|
|
|
#14
|
||||
|
||||
|
Quote:
It can be downloaded from here........ http://www.smokey-services.eu/forum/index.php Just be aware it is not currently being developed,there is no support for it and it is beta. Last edited by LoneWolf : July 6th, 2008 at 06:44 AM. |
|
#15
|
|||
|
|||
|
Quote:
Are you referring to web-embedded Browser scripts, or attacks that use script files (vbs, etc)? |
|
#16
|
|||
|
|||
|
Quote:
I have configured EQS to prevent all access to Windows Address Book and e-mail files. Only OE is permitted access to these. A simple check box in EQS, similar to NeovaGuard, enables or disables this feature. Scanning of text files for e-mail addresses is something I didn't consider though.
__________________
Online-Armor | Defensewall | EQSecure 3.41 | AntiVir | Returnil |Sandboxie | A-squared Anti-Malware |
|
#17
|
||||
|
||||
|
Quote:
Last year I wanted to try NG and I only got BSOD's as soon as starting my computer. It's a shame they don't develop it anymore, it seems it would have been a great HIPS
__________________
I ♥ SandboxIE
|
|
#18
|
||||
|
||||
|
Quote:
Thanks
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#19
|
||||
|
||||
|
Quote:
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#20
|
|||
|
|||
|
Quote:
Shots of E-mail file protection rules and pop-up when anything tries to access these files.
__________________
Online-Armor | Defensewall | EQSecure 3.41 | AntiVir | Returnil |Sandboxie | A-squared Anti-Malware |
|
#21
|
|||
|
|||
|
Quote:
Removing these scripts is not a problem, stop them from running is a problem. I need something like AE, but for scripts. Authorized scripts are allowed to run, any other script is killed immediately.
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
Last edited by ErikAlbert : July 6th, 2008 at 01:04 PM. |
|
#22
|
||||
|
||||
|
Quote:
Accordingly, I do hope this thread stays primarily on its topic of discussing generic/unique HIPS capabilities instead of getting diverted to yet another discussion of "let's all find what Erik wants."
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender Last edited by bellgamin : July 6th, 2008 at 02:24 PM. |
|
#23
|
|||
|
|||
|
Quote:
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
|
|
#24
|
|||
|
|||
|
Quote:
Quote:
http://www.wilderssecurity.com/showt...=210179&page=4 -- |
|
#25
|
||||
|
||||
|
Quote:
If you want to endlessly discuss "what Erik wants" I suggest you start your own thread and stop hi-jacking others.
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|