Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 16th, 2011, 02:56 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default What's your favourite web/url/IP/reputation filter setup and why

Staying out of risky areas is one of the (counter) measures to mitigate the risk of infection through the world wide web. There are several ways of achieving this (DNS-level, Browser-level, Plug-in level)


A second way to mitigate the risks of infection is to increase control on the most commenly used attack carriers (dynamic content, e.g. scripts, adds, PDF's, flash movies, etc), through browser options or plug-ins. See http://www.symantec.com/business/threatreport/build.jsp

Just wondering what Wilders Members are using as easy and cheap means of mitigation.

Regards Kees

Last edited by Kees1958 : November 16th, 2011 at 07:57 AM.
  #2  
Old November 16th, 2011, 03:05 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: What's your favourite web/url/IP/reputation filter setup and why

Web/URL/IP/Reputation
Using Norton DNS malware domain protection (configured in router). Using Chrome's phising protection (is some kind of hash mechanism downloaded and used locally in Chromium). Added Avast Webrep for reputation indexing of Search results and page visits. Using McFee SiteAdvisor as a post visit check. Those work on different levels and are the most effective in terms of download speed and webbrowsing performance tests. The effectiveness of those counter means are estimated between 30-60%, so adding more won't add much protection.

Norton: AV background, is handled at DNS-servers of Norton, so the delays are not noticeable. I disabled Chromium DNS prefetching.
Chromium: the Chrome phising blackist is based on the largest crawler mechanism in the Western World. It checks URL hashes in a very efficient manner with update intervals of half an hour (according the Google info).
Avast Webrep: I like the fact that Avast AV-intelligence is used to reduce false positives (reason I prefer it over WOT) and the fact that it is (with WOT) the fastest search plug-in for Chrome.
McFee SiteAdvisor: the disadvantage of McFee (on Chrome) is that it acts as a post-visit check (the advantage for Chrome is that it is only an icon, no other visible screen pollution). Having the two pre-visit filters (at DNS level=Norton and and Browser level=Chrome URL hash check), I also opted for pre-visit check when searching (Avast WebRep) and a post-visit check (SiteAdvisor). Site Advisor is noticably slower than Avast WebRep in displaying the result. So this asynch slow post visit check does not interfere with my browsing habits (I am reading the page when Sitedvisor does its works) and adds a last check on URL after the page is rendered.


Attack carrier mitigation
Using chrome's internal sandbox to mitigate javascript, PDF and flash (copied Chrome's internal flash and PDF plug-ins for use in Chromium, have not installed adobe PDF or FLash) with enforcement of running PPAPI flash in Renderer and using Native Clients for all web applications.

I think the security advantage of running low rights of renderer and plug-ins is so substantial, I do not need any NoScript like functionality (or browser virtualisation) with Chromium. Only running Adblock plug-in. This is questionable enhancement, although one could argue that any Add Block like functionality reduces the chance of being lurged to pesky websites.

Last edited by Kees1958 : November 16th, 2011 at 04:55 AM.
  #3  
Old November 16th, 2011, 10:06 AM
PJC PJC is offline
Very Frequent Poster
 
Join Date: Feb 2010
Location: Internet
Posts: 2,962
Default What's your favourite web/url/IP/reputation filter setup and why

-Norton DNS
-WOT

[the Malware Domains filter of ABP
-and more than that-...
is included in WOT.]
  #4  
Old November 16th, 2011, 11:26 AM
kjdemuth's Avatar
kjdemuth kjdemuth is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Boston, MA
Posts: 2,352
Default Re: What's your favourite web/url/IP/reputation filter setup and why

Norton DNS
Panda url filter
Ad block plus on firefox
__________________
Realtime:
WSA AV (Maxed Settings), Sandboxie Paid ( Dropmyrights and Browsers sandboxed) Lifetime license, NVT EXE Radar Pro (Lockdown mode). K9 Web protection. (malware, phishing and HTTPS force) Norton DNS.
On-Demand:
MBAM+EAM
Hitman pro (Scans daily)
  #5  
Old November 16th, 2011, 11:34 AM
Amit's Avatar
Amit Amit is offline
Massive Poster
 
Join Date: May 2011
Location: Parallel Universe
Posts: 4,631
Default Re: What's your favourite web/url/IP/reputation filter setup and why

norton dns
panda url filter
wot
ad block plus
__________________
✓The first principle is that you must not fool yourself, and you are the easiest person to fool.
✓Science is the belief in the ignorance of experts.
✓I don't know anything, but I do know that everything is interesting if you go into it deeply enough.


-------Richard P. Feynman---------
  #6  
Old November 16th, 2011, 11:48 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,470
Default Re: What's your favourite web/url/IP/reputation filter setup and why

I personally use no extensions, but two of my relatives have been running BitDefender TrafficLight and WOT, plus Norton DNS.

I prefer BitDefender TrafficLight and WOT over McAfee SiteAdvisor and avast! WebRep.

WOT may not be 100% perfect (nothing is), but it does have quite a few reliable sources, such as Phishtank.

avast! WebRep is more like what users like or what they don't like, isn't it? If I hate dogs and cats, I will hate associations helping these animals; therefore, I'll rate their websites with a low rating. What's going to stop that? If many thousands of people hating dogs and cats do that, then we have thousands of ratings saying that those websites are bad.

This kind of reputation service is not of my liking. I prefer services that keep focus on real dangerous websites, regardless of what they are.
  #7  
Old November 16th, 2011, 12:02 PM
Trooper's Avatar
Trooper Trooper is offline
Very Frequent Poster
 
Join Date: Jan 2005
Posts: 2,538
Default Re: What's your favourite web/url/IP/reputation filter setup and why

DynDNS
Adblock Plus with malware domains subscription on both Firefox and Chrome.
__________________
This space for rent.
  #8  
Old November 16th, 2011, 12:27 PM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: What's your favourite web/url/IP/reputation filter setup and why

Quote:
Originally Posted by m00nbl00d
avast! WebRep is more like what users like or what they don't like, isn't it? If I hate dogs and cats, I will hate associations helping these animals; therefore, I'll rate their websites with a low rating. What's going to stop that? If many thousands of people hating dogs and cats do that, then we have thousands of ratings saying that those websites are bad.

I recall (or think to remember) that VLK (of Avast) has stated that the webrep was checked by the automated web crawlers of Avast (link will be automatically checked by Avast automated malware analysis).

But please tell me when this is not the case
  #9  
Old November 16th, 2011, 12:44 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,470
Default Re: What's your favourite web/url/IP/reputation filter setup and why

Quote:
Originally Posted by Kees1958
I recall (or think to remember) that VLK (of Avast) has stated that the webrep was checked by the automated web crawlers of Avast (link will be automatically checked by Avast automated malware analysis).

But please tell me when this is not the case

To be honest, I limited my self to the scarce info I find. I do remember vlk mentioning a link -http://forum.avast.com/index.php?topic=71981.msg601295#msg601295

Quote:
WebRep is a combination of community voting and malware-related data feed from our virus lab.

[...]

On the onther hand, the community can usually very well tell whether a given e-shop is a good one or a poor one -- something our virus lab will hardly be able to do...

So, are user ratings checked for malicious code by avast! lab? I got my doubts, and it wouldn't make much sense, would it? After all, considering what vlk mentions in that post of his, part of avast! WebRep protection is provided by the users who "spot" and report fraudulent websites (no malicious code in them, simply fraudulent). The same is not to say that they can't rate a website with a low score, just because they feel like it.

-edit-

I've seen quite a few screenshots over avast! forum that show WebRep ratings showing that a website has this or that score due to X number of votes. So, this is coming from the avast! users, correct?
  #10  
Old November 16th, 2011, 01:37 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: What's your favourite web/url/IP/reputation filter setup and why

I just stick to the built in Chrome checks on sites and downloads.
__________________
  #11  
Old November 16th, 2011, 01:55 PM
The Seeker's Avatar
The Seeker The Seeker is offline
Frequent Poster
 
Join Date: Oct 2005
Location: Buxton, UK
Posts: 859
Default Re: What's your favourite web/url/IP/reputation filter setup and why

Ad Muncher.
Google DNS.
__________________
Windows 7 Ultimate 64-bit • WSA Complete • Ad Muncher • Image for Windows
  #12  
Old November 16th, 2011, 03:03 PM
BonskY's Avatar
BonskY BonskY is offline
Regular Poster
 
Join Date: Jul 2011
Location: Montréal, Canada
Posts: 67
Default Re: What's your favourite web/url/IP/reputation filter setup and why

From Google Chrome and Firefox always updated

OpenDNS + WOT+ AdBlock and no Pr0n !

And in case of failure...Sandboxies !

Have nice day guys
__________________
Window XP SP3

|Webroot SecureAnywhere Complete 8.0.2.43|Sanboxies 3.74 (PRO) |OpenDNS|FileHippo Update Checker| Window Update ON| Firefox 17.0.1|No Pr0n !
  #13  
Old November 16th, 2011, 03:07 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: What's your favourite web/url/IP/reputation filter setup and why

Quote:
Originally Posted by The Seeker
Ad Muncher.
Google DNS.
Google DNS doesn't use any filtering.
__________________
  #14  
Old November 16th, 2011, 03:19 PM
ExtremeGamerBR's Avatar
ExtremeGamerBR ExtremeGamerBR is offline
Frequent Poster
 
Join Date: Aug 2010
Posts: 963
Default Re: What's your favourite web/url/IP/reputation filter setup and why

Nothing, just Sandboxie to contain anything.
__________________
Windows 7 Home Premium 64 Bits
Sandboxie | Keyscrambler Pro | Norton ConnectSafe
Chrome > Ghostery (all enabled) | Adblock Plus | AntiSocial | Laspass
Malwarebytes' Anti-Malware (PRO) | Keriver 1-Click Restore Pro | Skydrive
  #15  
Old November 16th, 2011, 06:06 PM
wat0114
 
Posts: n/a
Default Re: What's your favourite web/url/IP/reputation filter setup and why

Primary DNS = ISP
Secondary DNS = OpenDNS

Windows Firewall w/Advanced security to restrict application remote port connections and force applications to DNS lookups with DNS Client service disabled.

IE 9 Smartscreen filter
  #16  
Old November 16th, 2011, 06:13 PM
cheater87's Avatar
cheater87 cheater87 is offline
Massive Poster
 
Join Date: Apr 2005
Location: West Chester Pennsylvania.
Posts: 3,003
Default Re: What's your favourite web/url/IP/reputation filter setup and why

WOT/Trafficlight for search results and for DNS I use Comodo.
__________________
I have Windows 7 64 bit Comodo Firewall 6 set to block, Avast Free Edition, K9 Web Protection set to block malicious and phishing sites only, Zemana Free Anti Keylogger, Comodo DNS, Firefox with Noscript, Adblock Plus, WOT set to block, Secunia PSI, and common sense. ^_^
  #17  
Old November 16th, 2011, 07:53 PM
bo elam bo elam is offline
Very Frequent Poster
 
Join Date: Jun 2010
Posts: 1,043
Default Re: What's your favourite web/url/IP/reputation filter setup and why

I being wanting to find a good Web/URL filter for a long time and I think I found it 10 days ago when I installed Panda URL filter. Tried AVG link scanner and Traffic Light before and did not feel convinced of its effectiveness as they never detected any site as malicious during real life browsing and only detected a few sites as malicious when trying URLs from MDL and other sites.

On the other hand, even though Panda URL filter has not detected any malicious site during my normal browsing, it has blocked every malicious URL from MDL and malwareurl that I have tried except two. I am kind of convinced that it works well, I also like that it can be installed without having to install the antivirus.

I am also using Norton DNS off and on and Firefox with NoScript and Adblock plus.

Bo
  #18  
Old November 17th, 2011, 02:37 AM
enemyofarsenic enemyofarsenic is offline
Regular Poster
 
Join Date: Jun 2011
Posts: 63
Default Re: What's your favourite web/url/IP/reputation filter setup and why

great thread...
  #19  
Old November 17th, 2011, 10:59 AM
treehouse786's Avatar
treehouse786 treehouse786 is offline
Very Frequent Poster
 
Join Date: Jun 2010
Location: Lancashire
Posts: 1,050
Default Re: What's your favourite web/url/IP/reputation filter setup and why

see this
__________________
Active@ Disk Image | 10 On-Demand Scanners

  #20  
Old November 17th, 2011, 01:50 PM
G1111's Avatar
G1111 G1111 is offline
Very Frequent Poster
 
Join Date: May 2005
Location: USA
Posts: 1,723
Default Re: What's your favourite web/url/IP/reputation filter setup and why

Norton DNS
WOT
Web protection enabled in MBAM Pro and Emsisoft Anti-Malware
  #21  
Old November 17th, 2011, 01:57 PM
progress
 
Posts: n/a
Default Re: What's your favourite web/url/IP/reputation filter setup and why

Quote:
Originally Posted by m00nbl00d
If many thousands of people hating dogs and cats do that, then we have thousands of ratings saying that those websites are bad.

I agree - that's the problem with WOT I guess Norton DNS or McAfee SiteAdvisor are better alternatives
  #22  
Old November 17th, 2011, 06:12 PM
PJC PJC is offline
Very Frequent Poster
 
Join Date: Feb 2010
Location: Internet
Posts: 2,962
Wink What's your favourite web/url/IP/reputation filter setup and why

This Poll fits perfectly...
  #23  
Old November 17th, 2011, 06:25 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: What's your favourite web/url/IP/reputation filter setup and why

Probably listed in order of preference...

Chrome's anti-malware and anti-phishing
Norton DNS
MBAM Pro website blocking
WOT extension
TrafficLight extension
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #24  
Old November 17th, 2011, 06:34 PM
tomazyk's Avatar
tomazyk tomazyk is offline
Frequent Poster
 
Join Date: Dec 2006
Location: Slovenia
Posts: 601
Default Re: What's your favourite web/url/IP/reputation filter setup and why

Dragon's and Firefox's build-in defences + AdBlock Plus
__________________
ESET Nod32 AV • Sandboxie • EMET • OpenDNS
My security setup in detail
• Always remember you're unique, just like everyone else •

  #25  
Old November 17th, 2011, 07:23 PM
Atomas31's Avatar
Atomas31 Atomas31 is offline
Frequent Poster
 
Join Date: Sep 2004
Location: Montréal, Québec
Posts: 919
Default Re: What's your favourite web/url/IP/reputation filter setup and why

Norton DNS
Panda URL Filtering
Adblock Plus
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:17 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums