What is your setup with NO blacklist (no antivirus - naked) setup

Discussion in 'other anti-malware software' started by Kees1958, Apr 8, 2011.

Thread Status:
Not open for further replies.
  1. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857

    S23, just out of curiosity: did you manage to get an auto log in when something requires admin priveledges, if so woudl you please post it (or PM it)

    thx Kees
     
  2. s23

    s23 Registered Member

    Joined:
    Feb 22, 2009
    Posts:
    263
    Hi Kees. This is something I not tried to do. The ones I read about but I imagine you already are aware is use Task Scheduler or the Microsoft Application Compatibility Toolkit to launch elevated without prompt. When I read, they tried the Compatibility Toolkit with the option "Run as invoker" but there is "RunAsAdmin" and RunAsHighest", but not sure if can make difference. I just installed Ubuntu beta here on top of Win7, so I cannot confirm.

    http://www.sevenforums.com/tutorials/11949-elevated-program-shortcut-without-uac-prompt-create.html (task scheduler)
    http://www.techrepublic.com/blog/wi...e-uac-for-your-trusted-vista-applications/635 (Microsoft Toolkit)
     
  3. noone_particular

    noone_particular Registered Member

    Joined:
    Aug 8, 2008
    Posts:
    3,798
    Except for a hosts file that blocks the bigger adservers and Google garbage (analytics, syndication, etc) I haven't used a blacklist based security app since 2006. Am using 4 PCs with operating systems ranging from 98FE to XP-Pro-SP3. Except for certain test configurations, all of them are secured by a default-deny security policy, enforced by SSM free or pro, Kerio 2.1.5, Proxomitron, and system policy/configuration.

    Excess and unneeded components have been removed from all of them. Internet Explorer has been removed from all but one. All unneeded services are disabled. User folders such as documents and desktops have been moved to a data partition. The browser cache(s) and temp folders have been moved to ramdrives. The system partitions are nearly static. All auto-updaing is disabled. Updating and installing are allowed for the administrator only. The integrity of each OS system partition is checked from another OS by comparing file lists obtained from another OS to ones compiled by the OS. On all PCs, SSM protects the registry. In addition, batch files replace the registries with clean, optimized copies on the 9X systems.

    All internet access is denied except for apps that specifically require it to function. Except for those running apps like Tor, none of the PCs have open ports. All browser traffic is forced through Proxomitron, which enforces default-deny on the web content. Content such as PDFs and flash media are opened with their own applications, not in the browsers. In addition to enforcing a process whitelist, SSM helps to isolate attack surface apps by blocking their access to any other apps and processes not absolutely necessary to their operation.

    I've been using this arrangement for nearly 5 years without incident. Until I see evidence that it can be defeated, I see no reason to change it.
     
  4. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    you are well protected my friend;)
     
  5. Konata Izumi

    Konata Izumi Registered Member

    Joined:
    Nov 23, 2008
    Posts:
    1,557
    i replaced my Sandboxie with Returnil System Safe 2011 FREE
     
  6. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Why don't you email the guys from VMlite appstudio that you want to join their beta version test for the freeware they release to plan. Will give you sandboxie like VM application virtualisation.


    (Suggesting this not becasue Returnil is not a great freebie, but because you have played with GeSWall, BufferZone and Sandboxie)

    Regards Kees
     
  7. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    I'd run GW if I could, but it makes my games lag either way. Might test it if they release a 64-bit version soon, see how it does.
     
  8. Konata Izumi

    Konata Izumi Registered Member

    Joined:
    Nov 23, 2008
    Posts:
    1,557
    cool app! but I'm lazy e-mailing people so I think I'd have to wait to try it :)

    I'm also waiting for Bufferzone 4 Beta
     
  9. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    is Bufferzone 4 going to be 64 bit ready?thanks
     
  10. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Yes, that's one of the main new features.
     
  11. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    cool i may check this out as geswall pro will have 64 bits when i dont know but they said it will and even defensewall i heard but out of the 3 ofcourse i will prefer my beloved defensewall ;)
     
  12. tipo

    tipo Registered Member

    Joined:
    Dec 29, 2008
    Posts:
    440
    Location:
    romania
    only my sig
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.