Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 5th, 2004, 04:06 AM
iwod's Avatar
iwod iwod is offline
Frequent Poster
 
Join Date: Jun 2004
Posts: 707
Default HTTP / TCP scanning.......

I remember i vouguely asked this question sometime ago but i couldn't understand the answer still.

I realize many of the AV today has add HTTP or TCP or internet resident scanning such as NOD32 Imon and Avast 4.5

But i still don't understand the need of it. Doesn't the webpage get downloaded before view? And therefore will be checked by ( NOD32 4 example ) AMon? This is to the similar question as to why i need DMON as well if AMon does the job anyway. Does that mean if i open a office Document with virus AMon won't detect it?

One of the few questions i had about HTTP scanning is that it create little problems with there and then. Like select open a torrent file when download it with IE doesn't work.

I seriously hope F prot 4 doesn't include this because so far i haven't seen a HTTP scanner that is totally transperant.
  #2  
Old December 5th, 2004, 06:01 AM
RejZoR's Avatar
RejZoR RejZoR is offline
Polymorphic Sheep
 
Join Date: May 2004
Location: Europe/Slovenia/Ljubljana
Posts: 5,366
Default Re: HTTP / TCP scanning.......

IMON HTTP scanning can be disabled so there is no problem at all if you don't want to use it. The whole point is that IMON checks the data before it comes to browser. IE tends to render some things directly which is not good.
But yes,AMON checks the cached data that is stored by browser in browser cache.
__________________
RejZoR's Little Secrets
  #3  
Old December 5th, 2004, 06:11 AM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: HTTP / TCP scanning.......

Quote:
Originally Posted by iwod
But i still don't understand the need of it. Doesn't the webpage get downloaded before view? And therefore will be checked by ( NOD32 4 example ) AMon? This is to the similar question as to why i need DMON as well if AMon does the job anyway. Does that mean if i open a office Document with virus AMon won't detect it?
There is a thread here on incoming file checking and what order it comes in: http://www.wilderssecurity.com/showt...ighlight=order and post number 34 gives the correct order.

Basically with a HTTP scanner the infection is detected at the front door, it is not allowed in to your computer. Should something get past IMON then AMON will spring into action upon execution. Same for DMON, incoming scanner, anything gets past AMON pounces...

Hope this helps...

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:43 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums