Tested Firewalls & Leaktests

Discussion in 'other firewalls' started by Rilla927, Nov 28, 2006.

Thread Status:
Not open for further replies.
  1. cprtech

    cprtech Registered Member

    Joined:
    Feb 26, 2006
    Posts:
    335
    Location:
    Canada
    With no fewer than three alerts, Outpost easily blocked the "Internetconnection" test.

    *EDIT*

    sorry, I overwrote my previous post. My version of SSM is paid, 2.2.0.602
     
    Last edited: Dec 15, 2006
  2. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    SSM 602 did intercept the HIPS test:

    If SSM is not warning of this on your setup, then you may of found a conflict with SSM + Outpost
     

    Attached Files:

    • test.JPG
      test.JPG
      File size:
      83.6 KB
      Views:
      574
  3. cprtech

    cprtech Registered Member

    Joined:
    Feb 26, 2006
    Posts:
    335
    Location:
    Canada
    Okay Stem, no problems, SSM was intercepting the memory modification attempt. It was doing it "silently". I deleted explorer.exe from SSM's rules, then launched the ex-coat test and was immediately alerted by SSM on the memory mod attempt. Whew! I feel better now :)
     

    Attached Files:

  4. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    Good to hear, I have installed OP4 to check on any possible conflict. I ran the test, and was given the alerts from SSM, I allowed these and then was given a popup from OP:-
     

    Attached Files:

    • test.jpg
      test.jpg
      File size:
      22.8 KB
      Views:
      559
  5. WSFuser

    WSFuser Registered Member

    Joined:
    Oct 7, 2004
    Posts:
    10,639
    im not DA, but ill explain. some people compensate for a leaky firewall by using a HIPS.
     
  6. cprtech

    cprtech Registered Member

    Joined:
    Feb 26, 2006
    Posts:
    335
    Location:
    Canada
    Thanks Stem. I get the alert from OP if I disable SSM (I guess SSM kicks in before Outpost does). However, take a look at the ss. Notice that excoat is able to write its code to the target process memory, before the test fails. SSM doesn't let excoat get quite that far. You can see the results on my earklier screenshots. Could you confirm how far PS and Jetico combination allow the test to go? Thanks again!
     
  7. cprtech

    cprtech Registered Member

    Joined:
    Feb 26, 2006
    Posts:
    335
    Location:
    Canada
    Sorry, forgot ss.
     

    Attached Files:

    Last edited by a moderator: Dec 16, 2006
  8. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    Interception / blocked O.K.
     

    Attached Files:

    • test.jpg
      test.jpg
      File size:
      26.9 KB
      Views:
      570
  9. cprtech

    cprtech Registered Member

    Joined:
    Feb 26, 2006
    Posts:
    335
    Location:
    Canada
    Excellent! Same result with SSM.
     
  10. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    @ WSFuser

    Yes I know but I wonder why DA says that HIPS are not able to stop leaktests? Or maybe he meant that HIPS can not stop ALL leaktests? In that case, well yes, I already knew about that. But I´ve checked it out myself and a lot of leaktests are stopped by HIPS, so my firewall does not have to be super advanced is my conclusion. But I may be wrong, I hope DA will respond. :)
     
  11. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
  12. cprtech

    cprtech Registered Member

    Joined:
    Feb 26, 2006
    Posts:
    335
    Location:
    Canada
  13. Stem

    Stem Firewall Expert

    Joined:
    Oct 5, 2005
    Posts:
    4,948
    Location:
    UK
    Jetico (1 & 2) intercepts both the InfectProcess(for HIPS) and the InternetConnection test.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.