![]() |
|
#1
|
||||
|
||||
|
|
|
#2
|
||||
|
||||
|
Sorry,
All Chinese to me, can't find download link. Please state which tests Comodo failed |
|
#3
|
||||
|
||||
|
Quote:
Comodo almost failed to pass all of them(process is terminated,mouse is locked),but I think the protection was not penetrated. Last edited by Peter2150 : April 21st, 2009 at 12:16 PM. Reason: Removed link to unknown files. |
|
#4
|
||||
|
||||
|
GeSWall results
HTAAA stopped with HTAAA showing error messages unreadable characters HTAAAB causes a massive amount of logs, tries to access all resident software, services or something, nothing happening HTAAC isolated without something happening Stop2 isolated without something happening, Risings PC doctor icon disappears and can't be restarted (via programs) Stop was also isolated according the logs, was denied access to explorer, but hung the system (so this could be the explorer stop) I see you describtions are about right, but not exactly in the Comodo forum, did you really test it? PM Ilya of DefenseWall, he will be intrested in this/ Last edited by Kees1958 : April 21st, 2009 at 12:32 PM. |
|
#5
|
||||
|
||||
|
Yeah, I‘ve tested them with GW, however, HTAAC (start with isolated) kills the exprlorer.exe....
Stop.exe lock the mouse without any LOG.... |
|
#6
|
||||
|
||||
|
Quote:
__________________
Creer,
Member of the Alliance of Security Analysis Professionals Windows 7 32-bit. &. ✓Look 'n' Stop. ✓DefenseWall .✓BestCrypt VE .✓ShadowProtect |
|
#7
|
|||
|
|||
|
The only problem test for DW is the "stop2". I fixed it up, will be released with the next, 2.54 version.
__________________
DefenseWall HIPS developer. www.softsphere.com |
|
#8
|
||||
|
||||
|
Quote:
![]()
__________________
Creer,
Member of the Alliance of Security Analysis Professionals Windows 7 32-bit. &. ✓Look 'n' Stop. ✓DefenseWall .✓BestCrypt VE .✓ShadowProtect |
|
#9
|
|||
|
|||
|
The download via rapidshare link posted in Comodo board isn't possible anymore - download limit (10) reached.
Last edited by cruchot : April 22nd, 2009 at 03:10 PM. |
|
#10
|
||||
|
||||
|
Quote:
Have you contacted GW and sent them any samples? |
|
#13
|
||||
|
||||
|
Quote:
Just on one of your comments. I like Sandboxie and regarding the blacklisting,Drive Sentry has this,kinda a reason I'm thinking about trying drivesentry,but haven't really seen many people running it ![]()
__________________
Windows XP SP3 & GeSWall |
|
#14
|
||||
|
||||
|
Quote:
Doesn't this all boil down to don't install anything unless you know and trust the site it is coming from? If you run everything as trusted in DefenseWall or answer Yes to all pop-ups from a classical HIPS without knowing what you are installing, I don't know of any application, other than image backup / restore, than can protect you. |
|
#16
|
||||
|
||||
|
Quote:
True, but if you know what you are installing and trust where it came from you won't have a problem. Users who will install anything without investigation should probably be using a suite that makes decisions for them or have someone else more knowledgeable determine what to install. |
|
#17
|
||||
|
||||
|
Quote:
So far as I know, CIS pop-ups but can't intercept the behaviors(both locking mouse and terminating processes) actually though the programmes don't penetrate the protection even they are malicious indeed. BTW:except for stop2.exe, S3(netchina),MD,DW seem like they can block the other behaviors correctly. |
|
#18
|
||||
|
||||
|
Quote:
SSJ100, You did not fully grasp the concept of policy management. Idea behind is a) you do not care which program runs on your system, because exectuables AND files originating from untrusted sources are kept in a safe containment b) you do not care where those files and programs are, because the sandbox is completely transparent, let them harmlessly reside between your trusted files and programs, they are paralissed anyway (see 1) c) when you do want to install something explicitely and with your full awareness and agreement, THEN, you have to set the status to trusted. From then on you will give them the full rights of the current user. So a policy sandbox is a kind of resversed HIPS: it does not bother you with pop-ups for known or unknown programs, for legitemate or malicious actions, it only requires 1 action (set to trusted) when you want to install it. Regards Kees |
|
#20
|
||||
|
||||
|
Quote:
Is tzuk aware ?
__________________
Don't confuse me with someone who actually knows what they are talking about. Linux Registered user 469135 Please, support Medecins Sans Frontieres |
|
#22
|
||||
|
||||
|
Hi,
Someone could test the defensive behavior of System Shield usec.at: http://www.usec.at/ushields.html in these cases? Thanks, PROROOTECT
__________________
W.XPSP2,1GBRAM,13proc,17svc;IE8s *** On-DemandPowerTool XueTr NVT Ga S RFS Preventive+FW!! S.Mon. TinyW. JS SettingsX NoDs . = ![]() URL checkZ Q W T U urlQ W IPduh DNS-info Sleuth R W WPT BC WS M BShotSu C $ Rev IP NoAV,Java JRE-Why Why|VOP MalwareTips-Turin Shroud PSus **READs!!! CATS! |
|
#23
|
||||
|
||||
|
Tzuk, Ilya, Xiaolin are the one man band eager beavers, so I should not worry about it very much.
|
|
#24
|
||||
|
||||
|
Quote:
Helas SSJ, can't help you with this As said earlier the most secure way of testing windows software is with Virtual Machine type of application on a different host OS (e.g. linux distro). |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|