Applocker problem :(

Discussion in 'other security issues & news' started by exus69, Aug 13, 2011.

Thread Status:
Not open for further replies.
  1. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Thanks for your help wat, I appreciate it. I tend not to change my setup as much as I used to because I pretty much found apps that I am content with using.
     
  2. wat0114

    wat0114 Guest

    You're welcome.
     
  3. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Ok one more question pleaseeeeeeeeeeeee...:D I noticed you have a publisher rule for Adobe Flash. Did you create that for the dll file (or was it the ocx file) in that directory because its not covered by the default windows dll rule?
     
  4. wat0114

    wat0114 Guest

    You know, it was so long ago so I can't remember the reason, but that could very well have been it. There was a logical reason for it is all I can tell you. Weird things sometimes happen so customized rules need to be created to resolve the AppLokcer block issues.

    A good example is an executable rule needed for not only Process Explorer's procexp.exe file, but also for its procexpx64 file, the latter of which only gets generated when Process Explorer is launched. Hope this makes sense.

    This is an example of why it's nice to have those instant Task Scheduler event alerts when weird things like this happen.
     
  5. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Ok then. I will see what happens when I get around to re-installing windows and getting things setup. I understand the process explorer issue as I had an issue similar with another app. Yes it does make sense. Thanks again.
     
  6. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Well I'm currently setting up applocker now and looks like I will have to create individual publisher rules for each dll file in Chrome's directory? Wondering if the publisher is the same for the dll files do I need a rule for each dll file or just for each publisher? Didn't know it wasn't an auto-generate for dll rules, oh well. Any thoughts Wat?
     
    Last edited: Sep 4, 2011
  7. wat0114

    wat0114 Guest

    Yes, Publisher rules for DLL files are a bit of a PITA, because unlike the autogenerate option for executables, the DLL Rules doesn't have this option. However, you should not have to create a rule for every DLL file related to Chrome. Just create the ones you find in the Event Viewer logs whenever you get a block alert.

    Probably the easiest way to go about this is open up Event viewer to the AppLocker logs (Application and Services Logs\Microsoft\Windows\AppLocker\EXE and DLL), clear them, then open Chrome and start using it until you get an AppLocker block from either AppLocker itself or the custom Task Scheduler event you hopefully have created already. Check under the Details tab and look for the FilePath entry which will display the file path of the blocked executable or DLL, whichever the case may be. You can then create your AppLocker rule based on that info.
     
    Last edited by a moderator: Sep 4, 2011
  8. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Yea I see but its fine. I don't mine learning it. ;) Ok gotcha. I will do an audit test and see what happens.
     
  9. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Actually I did that my friend and I found two dll files would be blocked if I enforced the rules. Created publisher rules and bam success. Still testing to see if I need to add anymore dll rules and after this its applocker full time :D Again I thank you for your time and energy in helping with this.
     
  10. wat0114

    wat0114 Guest

    Good to see you're making progress :)
     
  11. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Yep I'm glad as well :). I feel bad as well though because I could have been asking for help when I tried applocker the first time lol, but I never gave applocker a chance. And this is before I even considered using DLL rules lol.
     
    Last edited: Sep 4, 2011
  12. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
  13. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Thanks MrBrian. Will tell a look.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.