suggestions for the next version of TDS

Discussion in 'Trojan Defence Suite' started by hoju, Jul 27, 2004.

Thread Status:
Not open for further replies.
  1. paulson

    paulson Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    25
    Location:
    South Of Germany
  2. dallen

    dallen Registered Member

    Joined:
    May 11, 2003
    Posts:
    825
    Location:
    United States
    paulson,
    I corrected the grammatical error that you pointed out. Your Canadian girlfriend is correct in assessing my origin. My spelling is horrible, I'll concede to that.

    Jooske,
    Thanks for you input. I was thinking that was the case, but I must admit that I'm not well versed in Australian slang. The real question is are there cultures in which "bloody" and/or "crap" are truly offensive. Maybe one culture's acceptible slang is another culture's curse word. Or maybe paulson is overly sensitive, but I find that unlikely. As anyone, Canadian or otherwise, that is able to watch Mike Tyson can't be that sensitive. :D
     
  3. wayne_b

    wayne_b Registered Member

    Joined:
    May 29, 2004
    Posts:
    56
    I am a recent newcomer to TDS-3 (May 2004) I never had much of an issue with TDS-3 including the GUI. I find the interface easy to navigate for the items I find relevant. Any Q I need answering, the Help file answered most if not all of the questions.
    Basically, set and forget ;) except for the occasional manual scan. I like the options even if I don’t use some of them! At least it is there if and when I may need them :)

    I can’t see where TDS-4 could improve on TDS-3 unless DiamondCS knows of newer Trojan variants that require a new interface? Guess we will find out soon enough.

    -wayne
     
  4. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Thanks for the correct link, my last visit on the other was some time ago :)
     
  5. paulson

    paulson Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    25
    Location:
    South Of Germany
    @ dallen: Good (grim) sense of humour man! :D

    back to "suggestions..." if you're working with multiple TDS-windows open, f.e. TCP inspector, localhost scaner and others it would be more easy to handle if there will be a possibility to select them via "alt + tab" or the systray 'cause sometimes they get lost in the background.

    Btw Tyson got knocked out in the 4th round, how he's in real deep trouble and I'm off for the weekend.
    Cheers and have fun
    paulson
     
  6. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    TDS and the forums should really contains some cultural info and links; just surfed on this one http://www.australiablog.com/
    see the boxing kanga image on the right which original was some 20 meters high mascot when Australia won the America's Cup in 1983 and around that time the song "Land down yunder" was a big hit.
    In the DiamondCS forum at the site is more culture between the messages, including a ss3 script of Peedy singing that song via TDS.
     
  7. dallen

    dallen Registered Member

    Joined:
    May 11, 2003
    Posts:
    825
    Location:
    United States
    Paulson,
    I asked one of my girlfriends (she's as American as I) w.t.h. did he want to say to me? She said "this guy must be a Canadian Indian. I think they say 'How' when the mean 'Hello'." :-*

    If you mean now=> how ; your statement couldn't be more true.
     
  8. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    So you would like a translation engine (with language settings to chose from Canadian English, Aussie English, US English, UK English) and a knocking (smack!) the hacker included in the TDS-4?
     
  9. md411

    md411 Registered Member

    Joined:
    Jul 5, 2004
    Posts:
    24
    It be great if TDS4 could detect if a computer has been compromised by a rootkit...
     
  10. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    TDS4 Will have new engines but in the case of rootkits prevention is far better than cure, hopefully TDS4 will be able to at least prevent them:) Having said that, one of the reasons why Process Guard was developed was because of these new VERY dangerous threats.
    My guess is that there will be far greater integration of DCS products but with a modular approach rather than a one does all - We have to wait and see :D
     
  11. md411

    md411 Registered Member

    Joined:
    Jul 5, 2004
    Posts:
    24
     
  12. Gavin - DiamondCS

    Gavin - DiamondCS Former DCS Moderator

    Joined:
    Feb 10, 2002
    Posts:
    2,080
    Location:
    Perth, Western Australia
    No current rootkit can be installed if you block services/drivers from being installed. The new version will be out soon which will ensure that any newer tricks they try to pull will fail too :)
     
  13. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    In addition to Gavin's comments.
    And as far as I know rootkits require the facility to be able to inject a .dll into another programs memory space - Process Guard prevents this providing that you have the General option 2 enabled.
     
    Last edited: Aug 2, 2004
  14. Gavin - DiamondCS

    Gavin - DiamondCS Former DCS Moderator

    Joined:
    Feb 10, 2002
    Posts:
    2,080
    Location:
    Perth, Western Australia
    You dont need any general protection options to stop DLL injection, all listed processes are protected from DLL injection as an injector needs WRITE access

    DLL rootkits need this access, and usually a system process like winlogon.exe is the target. Its a good idea to add protection for all internet-enabled apps though :)

    DRIVER rootkits (true system level rootkits) need to install a driver :)
     
  15. Jason_DiamondCS

    Jason_DiamondCS Former DCS Moderator

    Joined:
    Nov 11, 2002
    Posts:
    1,046
    Location:
    Perth, Western Australia
    I'll just add, the 2 least common DLL injection methods are covered with General Protection Options. As long as you have APP_INIT blocked and Global Hooks, you are covered pretty much 100%.
     
  16. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    Thanks for the clarification guys :cool:
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.