Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > other software & services
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 5th, 2009, 01:46 PM
Luxeon Luxeon is offline
Regular Poster
 
Join Date: Mar 2007
Posts: 123
Default LUA, SRP, DEP, UAC...?

I am finally beginning to understand the acronyms LUA, SRP, DEP and UAC...but, have a question or two.

I have Vista x64 Home premium with UAC enabled. Currently using Defender with Spynet, NOD32, SAS (nice program), router, Windows Firewall, Firefox (soon to be equipped with NoScript and maybe AdBlock). Internet Explorer, on the rare occasion it is used, is in protected mode.

We are also using LUA.

Currently, DEP is set like this: "Turn DEP On for Essential Windows Vista Programs and Services Only"

Should I set it to the higher level "Turn DEP On for All Programs and Services Except for the Ones you Select?"

I find Software Restriction Policy to be a bit...confusing. I read this: http://www.mechbgon.com/srp/ , but apparently it doesn't apply to my system, and I admit that my understanding is still pretty...thin.

Does SRP apply to my system? (It looks like UAC is a kind of SRP-for-dummies) If so, how can I optimize it?

Man, there is a lot to learn about this stuff...
  #2  
Old April 5th, 2009, 02:32 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: LUA, SRP, DEP, UAC...?

Hi Luxeon, if your computer supports it then I'd recommend DEP for all yes*, you can then add an exception if one of your programs baulks. SRP in Vista as a Standard user is for the Business, Ultimate and Enterprise versions - have you read this thread.

*btw DEP is always enabled for 64bit native programs in 64bit versions of Windows.

To quickly tell if hardware DEP is available in Vista, as admin, enter wmic OS Get DataExecutionPrevention_Available in a command line. If TRUE is returned then it is available .
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld

Last edited by Meriadoc : April 5th, 2009 at 02:58 PM.
  #3  
Old April 5th, 2009, 09:49 PM
Arup
 
Posts: n/a
Default Re: LUA, SRP, DEP, UAC...?

If you really want DEP to be effective then the system wide setting via boot.ini is the only way. The only thing is that certain programs might have issues with it, in my case I discovered Avast and Orbit having issues, I replaced them with Avira and FDM and it went away. Every other program installed have no issues.
  #4  
Old April 6th, 2009, 02:18 AM
TOMxEU's Avatar
TOMxEU TOMxEU is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: Slovakia
Posts: 1,532
Default Re: LUA, SRP, DEP, UAC...?

If you play games, do not enable DEP for all, it will shut them down and mostly it does not even notify, that it is because of DEP. Otherwise no problem.
__________________
Real-Time: Nothing | On-Demand: Nothing [ Lenovo E525 | Yandex | CCleaner | KC SUMo | WiseCare 365 ] ( BlackViper / DEP / OpenDNS / UAC / WiFiRouter )
  #5  
Old April 6th, 2009, 06:01 AM
Raza0007's Avatar
Raza0007 Raza0007 is offline
Frequent Poster
 
Join Date: Mar 2009
Posts: 985
Default Re: LUA, SRP, DEP, UAC...?

I use Vista 32 bit so I will only comment on UAC and DEP, I don't think LUA and SRP are applicable to 32 bit OS.

UAC: I turned it off when I received my new computer and have not turned it back on since. You do not need it under ordinary circumstances. Keeping a good updated antivirus will provide you with adequate protection.

DEP: There are two kinds software based and hardware based.

Hardware based only has two settings enabled or disabled. You can only change it from your BIOS. It is only available if you processor supports it. Recommended setting is to leave it enabled. If it is causing problems for certain trusted software you may temporarily disable it.

Software based has four setting Optin, Optout, Always on, Always off. Default is Optin. In this setting it provides protection for essential windows programs only. You should leave it at its default setting. If some program is conflicting with it then you may select Optout. Then it protects all programs but those you mention in the exclude list.
  #6  
Old April 6th, 2009, 06:20 AM
Osaban's Avatar
Osaban Osaban is offline
Massive Poster
 
Join Date: Apr 2005
Posts: 3,086
Default Re: LUA, SRP, DEP, UAC...?

Quote:
Originally Posted by Meriadoc
Hi Luxeon, if your computer supports it then I'd recommend DEP for all yes*, you can then add an exception if one of your programs baulks.

Exceptions don't always work, as an example UltimateDefrag 2008 won't work on my Vista Ultimate32 with DEP enabled (hardware), even when the .exe is added to the exceptions.
__________________
Samsung Series 7 Chronos & Windows 8 (64bit)
“We are the cosmos made conscious and life is the means by which the universe understands itself.” Brian Cox
  #7  
Old April 8th, 2009, 08:42 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: LUA, SRP, DEP, UAC...?

If you don't have hardware DEP you'll also get the warning in the exceptions window of the DEP tab telling you the processor does not support hardware DEP. (XPSP2-)

To easily check on DEP policy you can enter in a command prompt :

wmic OS Get DataExecutionPrevention_SupportPolicy

the returned value would be 0-3

0 AlwaysOff DEP is not enabled for any processes
1 AlwaysOn DEP is enabled for all processes
2 OptIn Only Windows system components and services
3 OptOut DEP is enabled for all processes, but you can create an exception

There is also Securable which will tell you if you have hardware DEP (and hardware virtualization.) It will also tell you if Hardware DEP is off in the BIOS.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld

Last edited by Meriadoc : April 8th, 2009 at 08:53 PM.
 

Wilders Security Forums > Software, Hardware and General Services > other software & services « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:22 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums