![]() |
|
#1
|
|||
|
|||
|
Would Malware Defender fair any better on Matousec's latest tests with customized rules or will program updates be the only way to block the attack vectors that Matousec found? I'm surprised to see Kaspersky so high this time and would like to see MD take #1!
|
|
#2
|
||||
|
||||
|
I'm only new to MD and no malware expert, but by looking at where MD failed it appears yes the results could be improved with custom rules, and others may need updates.
For example on this page it failed DNStealer which says: Quote:
With MD we can decide what's trusted, so that could pass with rules. So i'm sure with a hardened rule set MD could shake the top of the charts. ![]()
__________________
Malware Defender |
|
#3
|
||||
|
||||
|
Quote:
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender |
|
#4
|
||||
|
||||
|
Quote:
|
|
#5
|
||||
|
||||
|
Yes I do believe that with xtra configuration MD would do much better.
Remember these tests are all about controlling the Behavior after the executables have been given to permission to run. If MD denied the creation of the executable files and denied them from running in the first place then MD would obviously pass 100 percent. quote Description: DNStester tries to determine whether the tested product filters DNS queries from an untrusted process. well that's easy if you are running an untrusted Process you would obviously limit its permissions like blocking it from accessing the network, but then again why would you even allow untrusted Processes to run in the first place?? so even tho Matousec's says MD fails dnstester I consider it to be a pass.
__________________
Win7 64bit Ultimate Sandboxie | Applocker | Admuncher | Macrium Reflect | TrueCrypt | FF Add On's | Greasemonkey | Secure Login | Noscript | Ant Video downloader | Status 4 evar Last edited by arran : July 5th, 2009 at 03:02 AM. |
|
#6
|
||||
|
||||
|
I would like to hear what Xiaolin have to say about "bugs", (I would say) cheating (pass test's specific implementation vs. failed test's technique):
Quote:
__________________
My defense on WIN 7 64 bits: F-Secure Client Security 9.01, Sandboxie 3.46, AI RoboForm Pro v.6.10.0 Sorry for bad English Thanks
Last edited by Einsturzende : July 5th, 2009 at 05:14 AM. |
|
#7
|
|||
|
|||
|
Quote:
|
|
#8
|
|||
|
|||
|
Quote:
I do not know why MD failed the SSS3 test, I cannot recreate it. Other failed tests except crash7 are related to accessing COM objects. MD implemented the COM protection using ring3 hooks. The Matousec's test will restore ring3 hooks, and any protection for the ring3 hooks will be taken as a direct attack against the test, and will fail the test. I have no plan to change the implementation of COM protection yet, so MD will not get higher score in the near future. Thanks ![]() Last edited by xiaolin : July 7th, 2009 at 04:27 AM. |
|
#9
|
||||
|
||||
|
Quote:
I don't care about this. MD is more of a classical HIPS not a firewall to filter low level packets.
__________________
Win7 64bit Ultimate Sandboxie | Applocker | Admuncher | Macrium Reflect | TrueCrypt | FF Add On's | Greasemonkey | Secure Login | Noscript | Ant Video downloader | Status 4 evar |
|
#10
|
||||
|
||||
|
^^ Agree ^^
__________________
Webroot SecureAnywhere |
|
#11
|
|||
|
|||
|
Quote:
"Security Software Testing Suite - SSS3 Copyright by www.matousec.com, Different Internet Experience Ltd. http://www.matousec.com/ ERROR: Unable to initiate the system shutdown. Error code: 1115 Error message: A system shutdown is in progress. YOUR SYSTEM PASSED THE TEST!"
__________________
Nick |
|
#12
|
||||
|
||||
|
Quote:
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13 |
|
#13
|
||||
|
||||
|
Quote:
100% every time.
__________________
Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil 2008, Microsoft Virtual PC 2007 SP1, Drive Snapshot
|
|
#14
|
|||
|
|||
|
Quote:
|
|
#15
|
||||
|
||||
|
Quote:
![]() |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|