Secure Folders to protect folders (and use as anti-executable)

Discussion in 'other anti-malware software' started by Windows_Security, Oct 21, 2014.

  1. pegr

    pegr Registered Member

    Joined:
    Apr 8, 2008
    Posts:
    2,280
    Location:
    UK
    Hi Rasheed187,

    I'll try Hide Folders 5 at the same time when I get round to retesting SecureFolders. Thanks for the tip. :)

    Regards
    pegr
     
  2. 142395

    142395 Guest

    Looks interesting, but can I make a question?

    What does Trusted programs mean?
    Is this setting change access token of that program? Then can't it make potential attack surface 'cause those programs might get higher privilege (of course not talking about integrity level) than before, depending on context?

    Also, for whom does folder restriction apply? Everyone, or Users?
     
  3. Using this program for a while now and it seems that
    - trusted programs are allowed to bypass the limitations imposed by SecureFolders itself
    - restrictions apply for Everyone
     
  4. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    How does it uninstall? Does it restore ACLs when removed?
     
  5. 142395

    142395 Guest

    Do you know how Secure Folders perform this?
    I suppose it modify subjects' access token, but not sure.
     
  6. ArchiveX

    ArchiveX Registered Member

    Joined:
    Apr 7, 2014
    Posts:
    1,501
    Location:
    .
    509
    Bandwidth Limit Exceeded

    The server is temporarily unable to service your request due to
    bandwidth limit has been reached for this site.

    Please try again later.



    What happened to their site? :confused:
     
  7. Tarantula

    Tarantula Guest

    3 days in a row? I think I will stick to My Lockbox Free.
     
  8. ichito

    ichito Registered Member

    Joined:
    Jan 14, 2011
    Posts:
    1,997
    Location:
    Poland - Cracow
    Perhaps some regional issue...I can open its page normaly.
     
  9. No it installs a driver and filters disk access. It just returns the same error as ACL.
     
  10. 142395

    142395 Guest

    Ah, I got it, Thanks!:)

    I wondered if ACL is for Everyone how subject bypass this, but now it solved.
     
  11. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    certeap.sys LoL
     
  12. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
  13. ArchiveX

    ArchiveX Registered Member

    Joined:
    Apr 7, 2014
    Posts:
    1,501
    Location:
    .
    4.jpg It's getting worse...
     
  14. I have send installation program to last freeware version website
     
  15. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Given you don't know who is behind them, and now the website, do you guys really trust this? Just curious
     
  16. Untitled.png YEP, see pic,not black listed on VT, no suspicious calling home
     
  17. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Safe and sound. Funny how this sooo reminds me of when I used to confiscate those malware rootkit hider drivers from the bad guys and instead turn them around to hide my own alternate security measures and even in ADS ;)
     
  18. blacknight

    blacknight Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    3,351
    Location:
    Europe, UE citizen
    I'm not sure to understand: so you trust it ?
     
  19. CGuard

    CGuard Registered Member

    Joined:
    Mar 2, 2012
    Posts:
    145
    I had a couple of questions so i e-mailed the developer. Interesting info:

    1. The anti-exe protection applies to any file extension.
    2. A new version will probably be released this summer.
    3. A per file/folder "Trusted Applications" feature will be considered (for the upcoming version?). I'm curious as to how it will be implemented (if). Hope it is feasible.
     
  20. RejZoR

    RejZoR Lurker

    Joined:
    May 31, 2004
    Posts:
    6,426
    Nice find! Looks like an excellent way to prevent data leakage or ransomware.

    For example you can set that only browser can access it's password storage files, for the rest of the system it wouldn't even exist! Or allowing images to only be visible to image preview and your favorite image editor.

    EDIT: Would be nice if you could specify exactly what app can access what, to make it even more secure. But also have the existing global trusted apps.
     
  21. No don't know how they implement it. I uses a driver. When you run a trusted programs as admin, it loses its access rights. The pop-up is the popup you gett when manually changing ACL of folders/drivers, so it looks like:
    a) It is user based (denying it to everyone and run trusted programs as another user)
    b) It uses Windows ACL mechanisms to do the actual protection (maybe also the reason why it uses less overhead)

    All and all a smart application as Rezjor says, with many applications, like
    - set your data folders as read only
    - give windows explorer, office and media aps access, deny all others

    You can also set the folders of the trusted programs themselves as no-execution, this will run the trusted programs in a LUA container.
     
  22. RejZoR

    RejZoR Lurker

    Joined:
    May 31, 2004
    Posts:
    6,426
    I've just protected my browser so only browser EXE can access user profile folders. So no other app can dig through stuff that is stored there. And it works!

    But the problem is with global trust apps, that kinda exploit one another just by being global and not per folder/rule. For example I need explorer.exe on Trusted list for being able to copy protected image files, but consiquentially, this also negates browser protection rules, because browser user folders are again visible because of it.
     
  23. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Not such a bad app either. It seems to be compatible and 100% stable running alongside my testings of Bouncer just fine. My box is a Win 8.0 64bit.

    MBAE free version with SD in tray and also Sandboxie. Seems like these third party types offer a degree of satisfaction I've yet to discover in plain jane security apps yet again. After all this time these little inventions trump the big boy packages as always for me.
     
  24. RejZoR

    RejZoR Lurker

    Joined:
    May 31, 2004
    Posts:
    6,426
    I wonder how this app affects folders if you have 2 partitions, you protect data on non-system partition and reinstall the system. Will protection rules remain or not? I mean, does it use NTFS permissions also or not?
     
  25. CGuard

    CGuard Registered Member

    Joined:
    Mar 2, 2012
    Posts:
    145
    @RejZoR: As Windows_Security's (nice find, indeed :thumb:) last post implies, SF's protection rules are enforced by its driver. As for your concern about Trusted Applications indiscriminately accessing SF protected files/folders, that was my rationale behind proposing a per file/folder setting.

    @Kees: Are you sure about running Trusted Applications as another user? I thought the same (haven't researched it yet), but SF's author's response to my request (quoted: "Will note your feature request and possibly implement it") has left me in doubt.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.