![]() |
|
#151
|
|||
|
|||
|
Quote:
The web page is ONLY launched on uninstall, not installation.
__________________
SUPERAntiSpyware.com http://www.superantispyware.com |
|
#152
|
|||
|
|||
|
Quote:
OK. So, I confused when it SAS opens IE. Still, the same concern applies, because it opens IE in a non Protected Mode, and with full administrative rights. Someone providing a security application should be aware that huge problems may come from this, would SAS web site ever be hijacked by hackers. (Let's never say no. Others have fallen.) P.S: Don't take this as bad criticism; rather as good one. Last edited by m00nbl00d : December 22nd, 2010 at 10:20 AM. Reason: typo |
|
#153
|
|||
|
|||
|
Quote:
Uninstallation is not in admin mode, it's in the user context, FYI.
__________________
SUPERAntiSpyware.com http://www.superantispyware.com |
|
#154
|
|||
|
|||
|
Quote:
Hmmm... In Start Menu there's no option to uninstall SAS. So, at the time, I first uninstalled SAS via Add/Remove Programs, which will start the all process with administrator rights (it asks for permissions). Also, the stand alone uninstaller I got from SAS forum, because somehow SAS failed to properly uninstall, does require administrator rights as well. Later on, I found there's an uninstaller executable in SAS folder, and this too require administrative rights to be executed. How does it require only current user (standard user) rights? |
|
#155
|
|||
|
|||
|
Quote:
It should be launched at the lowest priv level. We will continue to have that uninstallation page as it provides valuable data to improve our product.
__________________
SUPERAntiSpyware.com http://www.superantispyware.com |
|
#156
|
|||
|
|||
|
Quote:
And, how exactly would this "should" (I made the emphasis) make it uninstall SAS with lowest rights? A standard user has no permissions to install or uninstall from %ProgramFiles%. The only way for SAS not require administrator rights to install or uninstall would be for it to be installed to user space. Which would go against a proper administrative policy. So, SAS does uninstall in administrative mode and does open IE in administrative mode as well. |
|
#157
|
|||
|
|||
|
Quote:
I appreciate your concern regarding the browser being launched - it really doesn't represent any issue in real-world situations and hasn't caused any issues in over 35 million installations.
__________________
SUPERAntiSpyware.com http://www.superantispyware.com |
|
#158
|
||||
|
||||
|
I did some testing on a Vista virtual machine and it does launch the browser process as admin. I should have known it would but had not really though about it. This is probably low odds of being a problem... unless the user keeps that browser open and continues to go to other sites with it. As I paid customer of SUPERAntiSpyware and an employee of the software industry in general I can appreciate what they are trying to do by launching this page to begin with but I can see the potential problem with this. I am thinking there is a way to launch a child process that does not inherit the admin rights but I can't think of how to do it without some research. It might be well worth looking into.
|
|
#159
|
|||
|
|||
|
Quote:
There really is no potential problem - if you are already infected, it can't cause you to get infected - the infection would have to be there already.
__________________
SUPERAntiSpyware.com http://www.superantispyware.com |
|
#160
|
||||
|
||||
|
Would it be an issue in a hostile network?
__________________
Americans are the enemy? Mil. can arrest you? What the heck is going on? |
|
#161
|
|||
|
|||
|
Quote:
m00nbl00d do you ever give it a break, I dont think you have ever had to many good coments a SAS thru this entire thread, you know what because of you Im going to give SAS a go. Nessy ![]() |
|
#162
|
|||
|
|||
|
Quote:
OK. I guess that volunteering to translate SAS to my language, clearly shows a sign of disdain... or not giving a rest to SAS and SAS team, uh? Maybe I'll take my offer back. I don't use and won't be using SAS, though for the extra comfort of some relatives, I have it installed in some relative's systems, for on-demand scans. They do understand English, though. So... this wouldn't be a favor I'd be doing to me or my relatives... but to a general audience. Some people simply seem not to deserve the help of others. ![]() I just stated realities over the thread... and more recently one more regarding that it does open IE under FULL rights. If I wanted to run IE under FULL rights, I'd be using an Administrator account with UAC disabled. Or, even in standard user account with IE executed with FULL rights. The problem... and I had examples in the family, is that most enjoy easy to do stuff. A relative connects to the Internet using a 3G USB device; the ISP application automatically opens IE, when connecting to the Internet (the work around is to close the app after entering credentials and using Windows own connection mechanism). This made things so comfortable to my relative, because didn't have to manually open IE. Hopefully, IE process was started under standard user rights. Can you imagine the problem if it was started under FULL rights? Well... you know what people use to say: crap and accidents do happen... So, I just express a concern... because when I see security companies like Kaspersky having their main website hacked... it makes me wonder if the same couldn't happen with such SAS page. (Maybe not... maybe some divine protection is out there.) Anyway, it's my last post here. |
|
#163
|
|||
|
|||
|
Quote:
So you won't translate SUPERAntiSpyware because your point was rebutted? Yes IE opens as the same priv as the current process - in reality that doesn't do anything harmful. There is ALWAYS away to come up with a "possible" situation, but you have to look at probability, not just possibility.
__________________
SUPERAntiSpyware.com http://www.superantispyware.com |
|
#164
|
|||
|
|||
|
Quote:
Purchased SAS. Nessy |
|
#165
|
|||
|
|||
|
Quote:
I guess no one wondered about the probability of security vendors like Kaspersky seeing their website being hacked; nor the possibility of such ever happen, I guess. ![]() And, I actually believe such situation happened more than once. I guess no one ever thought about the probability of a second possibility just around the corner. ![]() |
|
#166
|
|||
|
|||
|
Quote:
Glad you can now see the humor in it All the vendors do their best - nothing is perfect.
__________________
SUPERAntiSpyware.com http://www.superantispyware.com |
|
#167
|
|||
|
|||
|
Quote:
By the way, I did not mention I'd no longer translate SAS. It was a merely reaction to this comment http://www.wilderssecurity.com/showp...&postcount=161 |
|
#168
|
||||
|
||||
|
@SUPERAntiSpy
If you don't mind can I know when will the SAS 5.0 will be released officially?
__________________
Avast IS,Sandboxie,SafeOnline and MBAM Pro |
|
#169
|
||||
|
||||
|
You know they're going to say "when it's ready".
![]()
__________________
Now that I'm older, I seem to have more patience. It turns out I just don't give a crap. WIN 7 64x, Avast! PRO V8, Outpost FW Pro 8.x, MBAM Pro Real Time, Shadow Defender, Active@ Disk Image, Macrium Reflect Standard, AX64 Time Machine
|
|
#170
|
||||
|
||||
|
Quote:
i wonder if its gunna be the same as SuperAdBlocker in that sense lol ![]()
__________________
Windows 7 x64 - Windows Defender: Disabled - UAC: Disabled Real-Time: Avast Free / Zemana Free / WinPatrol On-Demand: HitmanPro / MBAM |
|
#171
|
|||
|
|||
|
Quote:
That's exactly right, but it's close to public pre-release!
__________________
SUPERAntiSpyware.com http://www.superantispyware.com |
|
#172
|
||||
|
||||
|
Quote:
Thank you for the news,I'm quite excited how the new version will perform. ![]()
__________________
Avast IS,Sandboxie,SafeOnline and MBAM Pro |
|
#173
|
|||
|
|||
|
still to have for an normal PC with 2GB Ram and 2Ghz,
|
|
#174
|
|||
|
|||
|
Quote:
What are you asking here?
__________________
SUPERAntiSpyware.com http://www.superantispyware.com |
|
#175
|
||||
|
||||
|
Guess he is trying to say it's too heavy. Looking forward to pre-release, I'm sure it'll be great. Good luck!
__________________
Microsoft Security Essentials |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|