BlackFog Privacy

Discussion in 'other anti-malware software' started by liba, Feb 2, 2018.

  1. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    @paulderdash The simplest way to solve that is to add "syncthing.exe" to the whitelist in the Enterprise console under Settings > Windows, since it is only relevant for Windows. Global works across all devices.
     
  2. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Thanks Darren, but how exactly, the Allow List is for Domain or IP? Unless you mean the IP address in my message?
    Apologies if I'm missing something really obvious!

    Edit: The only place I can see to enter a path is at Global>Windows Applications Allow>PowerShell Scripts?
    But that doesn't seem right ...
     
    Last edited: Nov 16, 2020
  3. acid king

    acid king Registered Member

    Joined:
    Jan 19, 2019
    Posts:
    104
    Location:
    europe
    I just installed WiseVector StopX and did an update in order to test with Blackfog
    No geolocation block for China ...
    What do you think about it Daren ?
    These 2 softwares can cohabit together or it will be necessary to deactivate the geolocalization for china one day?!
     
  4. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    WVSX has servers in other countries besides China and updates without issue here.
     
  5. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    @paulderdash It's actually a hidden feature that it will accept and executable name when whitelisting. It autodetects this within the app so it basically is able to whitelist all direct addresses from that app. We don't document it as it should be used with care. In the app itself you can just click on "Allow" and app "yourapp.exe". In the Enterprise console. Settings > Windows > Allow list > yourapp.exe.
     
  6. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    @acidking I don't see why it wouldn't coexist except if it is exfiltrating data it shouldn't. Seems like a lot of feature overlap thats all. But we are using different techniques based on exfiltration so really depends on what they are doing under the hood. At least you can keep the app honest by watching what it is doing.
     
  7. acid king

    acid king Registered Member

    Joined:
    Jan 19, 2019
    Posts:
    104
    Location:
    europe
    Thank you for your quick response Daren regarding WSX.
    It was just a test because I knew it was a Chinese application
    I'm using Malwarebytes Premium + BlackFog + GlassWire right now and that's more than enough ^^

    I tried to add "ARK Desktop Wallet.exe" under "allow - allowed sites" to exclude suspicious addresses from this application... but it says: "Invalid domain entered" ...
    Maybe I misunderstood your discussion with paulderdash!
    and I continue to disable "suspicious addresses" while using this application for a few minutes...

    br.
     
    Last edited: Nov 16, 2020
  8. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    @acidking No you are correct, but we caught it as invalid because the exe contains spaces...We are validating IP's Domains generally, and since this is a hidden feature no-one has used it with an exe like that. If you are using the enterprise console we can fix that without an update but if just the standard we will change the validation on exe name's in the next patch.
     
  9. acid king

    acid king Registered Member

    Joined:
    Jan 19, 2019
    Posts:
    104
    Location:
    europe
    Yes i use the Personal Edition. so i ll be waiting for the next patch.
    Thank you a lot for your great support.
    I hope the entire BlackFog team and your loved ones are doing well during this pandemic.

    best regards.
     
    Last edited: Nov 17, 2020
  10. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    Thanks @acidking. All well with the BlackFog team and families.
     
  11. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Thanks Darren - done! :thumb:
     
  12. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    @acidking We have updated to 4.7.3 now with the ability to add the exe with spaces.
     
  13. acid king

    acid king Registered Member

    Joined:
    Jan 19, 2019
    Posts:
    104
    Location:
    europe
    @Darren Williams

    It works when i allow "ark desktop wallet.exe"
    Thanks.

    the real name of the .exe is "ARK Desktop Wallet.exe" with some capital letters
    and it didn't work on the first try for your information

    br.
     
    Last edited: Nov 25, 2020
  14. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    I just tried to right click, then open BF from the sys tray icon but nothing happens. I shall restart the machine and try again.
     
  15. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    A system restart solved that problem.
     
  16. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    @acidking Nice pickup yes it has to be lower case because of the parsing we do here. Probably should allow both options but as a hidden feature we will add that in the future.
     
  17. acid king

    acid king Registered Member

    Joined:
    Jan 19, 2019
    Posts:
    104
    Location:
    europe
    just a blackfog reboot and it was good for me to really get to 4.7.3
     
  18. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    What is blackfog?
     
  19. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,180
    Location:
    Canada
  20. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    Nice maybe similar like returnil
     
  21. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,180
    Location:
    Canada
    I taught Returnil was some kind of virtualization Software?:doubt:
     
  22. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    It is :)
     
  23. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    Now I am lost sorry it's been long time
     
  24. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Interesting.

    I have one Firefox profile with only password manager extension, for extra security.

    Started getting this threat detection: 'Egress to restricted geography' every time I opened that profile ... :confused:
    Unsafe connection to ocsp.dcocsp.cn (47.246.7.227). Blocking. Region: China. Process -> firefox.exe Port -> 80 PID -> 41468
    which is definitely not what I would want there. :eek:

    Thought maybe I had visited some dodgy site - seems to be something to do with alibaba.com - though I don't recall knowingly visiting any site connected to that entity on this profile ...
    so cleared cookies and site data, but no difference.

    Deleted profile, recreated. Problem is gone.

    But at least BFP let me know! :thumb:
     
  25. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    Yes this was part of the extension itself @paulderdash. We have seen this before. They are getting rather sneaky at embedding profilers. We are always careful not to delete the extension itself. We will track down where it stores that info for a future update. At least it couldn't do anything nasty...
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.