Protecting the Registry

Discussion in 'other security issues & news' started by WilliamP, May 23, 2004.

Thread Status:
Not open for further replies.
  1. optigrab

    optigrab Registered Member

    Joined:
    Nov 6, 2002
    Posts:
    624
    Location:
    Brooklyn/NYC USA
    Having problems with RegProt here too - though different problems I'm guessing. I could be an idiot (could be?) but it doesn't sem to be working properly in the Power User account.

    Disabled SSM a couple of days ago, switched to RegProt yesterday, now what? :mad:
     
  2. Dazed_and_Confused

    Dazed_and_Confused Registered Member

    Joined:
    Mar 4, 2004
    Posts:
    1,831
    Location:
    USA
    So Notageek, your using nothing to protect the registry? I guess that doesn't concern you? Maybe I shouldn't be concerned either. I am using PG (for now). Maybe that is enough.
     
  3. Dazed_and_Confused

    Dazed_and_Confused Registered Member

    Joined:
    Mar 4, 2004
    Posts:
    1,831
    Location:
    USA
    The type of protection I'm really interested in would fall into catetory 3 above (nice post Hojtsy). It sounds as if SSM, RP, RR, and GRR meet this criteria. Already discarded RP (died a slow death). Waiting on Opti's evaluation of SSM. WilliamP is also running a test on GRR - looking forward to his conclusions there. Lots of positive comments here about RR, but kind of pricey. What'a girl to do?? :)
     
  4. notageek

    notageek Registered Member

    Joined:
    Jun 3, 2002
    Posts:
    1,601
    Location:
    Ohio
    I was concerned about my registry at one time (not so long ago) but now I'm not so worried about my registry. I do want to know what's using my registry but I aslo make sure I know what I'm installing. I read everything about the program I'm going to install. But on my other system I will not. Like take weatherbug for instance. I installed it on my other machine to check out what kind of trash it really put out there. I am in no way of saying you should not be concerned about your registry. That is a personal choice. :) I'm just saying what I have running. Maybe someday I will use one. I tried out GRR and didn't like it much so I ruled that out.
     
  5. hojtsy

    hojtsy Registered Member

    Joined:
    Dec 28, 2003
    Posts:
    351
    DCS RegProt, Teatimer and SSM are pollers (category 1). I don't know for sure about GRR and RegRun, but I suspect they are pollers too! The only proxy I know of is Process Guard but it protects only a single registry key (APPINIT_DLL), and blocks modification withouth dialogs. We would need the technology built into PG with more keys, and control.
    -hojtsy-
     
  6. Dazed_and_Confused

    Dazed_and_Confused Registered Member

    Joined:
    Mar 4, 2004
    Posts:
    1,831
    Location:
    USA
    Hojtsy - I have sed RP, and it does ask prior to allowing certain registry entries. Are you sure it's a poller?
     
  7. hojtsy

    hojtsy Registered Member

    Joined:
    Dec 28, 2003
    Posts:
    351
    How do you mean prior? Just check the registry with regedit while the RegProt dialog is displayed! The change is already there! RegProt just offers to undo the value to the previously stored one. The wording of RegProt dialog boxes may be confusing you. By the way it is also quite easy to identify a poller with the software Sysinternals RegMon which displays the repeating registry read operations real-time. So I am quite sure RP is a poller.
    -hojtsy-
     
  8. Dazed_and_Confused

    Dazed_and_Confused Registered Member

    Joined:
    Mar 4, 2004
    Posts:
    1,831
    Location:
    USA
    Thanks, Hojtsy. I can't remember exactly what the dialog box said (the app caused too many problems and I'm not using it anymore). You might be right, but it sure gave me the impression it was asking for my permission to allow the entry.
     
  9. hojtsy

    hojtsy Registered Member

    Joined:
    Dec 28, 2003
    Posts:
    351
    The same oversimplification goes for other pollers too. They love to confuse undoing with denial.
    -hojtsy-
     
  10. tuatara

    tuatara Registered Member

    Joined:
    Apr 7, 2004
    Posts:
    777
    Another thing is that the registry is protected for the installation of new progs,
    that you perhaps don't want to install.

    But adding data to excisting registry keys, like 2 GIG to a key,
    is still allowed, and can still corrupt your registry.

    That is what happened to one of my servers here.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.