anyone heard of Online Armour?

Discussion in 'other anti-malware software' started by angarahad, Jun 8, 2005.

Thread Status:
Not open for further replies.
  1. MikeNash

    MikeNash Security Expert

    Ok, will have a look into this, and the hanging issue to see if I can reproduce it.
     
  2. sukarof

    sukarof Registered Member

    I might add that I use Bitspirit as a torrent client. I do not have this problem.
    Just for reference.
     
  3. Trooper

    Trooper Registered Member

    Mike just installed OA.

    Install went smooth. The only hang up was on the hosts file which I expected anways. I use Bluetack's HOSTS file and there are over 48,000 entries in it.

    The only things I have to ask so far are:

    • Are there plans in the future to accept all HOSTS file changes vs having to manually except each one?
    • Why is OA calling home upon restart? Is this for the anonymous information to be sent out?
    • What does Web Screen and Mail Screen actually do?

    These are just a few initial questions.

    Thanks for the trial key.

    Jag :)
     
  4. Atomas31

    Atomas31 Registered Member

    Hi,

    What is the difference between Safe'n'Sec and Online armor? Are they doing the same thing and the same way? Can they play nice together?


    Thanks,
    Atomas31
     
  5. MikeNash

    MikeNash Security Expert

    Install went smooth. The only hang up was on the hosts file which I expected anways. I use Bluetack's HOSTS file and there are over 48,000 entries in it.

    The only things I have to ask so far are:

    Are there plans in the future to accept all HOSTS file changes vs having to manually except each one?

    >> Because of the large number of files in there, it will take a long time to initially process it, but it should not hang. The result of that will be all automatically accepted.

    Why is OA calling home upon restart? Is this for the anonymous information to be sent out?

    >> The only reason why OA would call home is to check for automatic updates, or to anonymously send programs (once) to the central server. You can avoid this by setting the appropriate options on the "general" tab.

    What does Web Screen and Mail Screen actually do?

    >> Webscreen filters all web pages and looks for potentially dangerous objects, for example, ActiveX - or sites that use security exploits - for example, international domain names being used; some cross site scripting. The mail screen performs a similar function for POP3 and IMAP mail - checking for exploits that could be used to trick a user into visiting fake online banking sites (or other sites listed in protected sites tab)


    Hope that helps!

    Mike
     
  6. Trooper

    Trooper Registered Member

    Thanks for the reply Mike, it makes perfect sense. :D

    One thing I noticed today. I play games and some of them are through Steam, which is a Valve Software product. Go here for the installer.

    Anyway, when I clicked on Steam it opened up and allowed me to enter in my username and password for it. OA did not prompt me at all for this program.

    However, when trying to launch a game from within Steam, OA then prompted me for the Allow Block etc.

    I just thought you should know. ;)

    Jag
     
  7. MikeNash

    MikeNash Security Expert

    I hate to ask - but when OA scanned your start menu, did you allow anything and was the Steam product one of them?

    The way the OA program guard works is that once you approve something, you don't get asked again - and that includes if you approve in the SCW.


    Mike
     
  8. Trooper

    Trooper Registered Member

    Yes I did allow some programs, however Steam was not one of them. I should mention however that I have Steam installed on a separate partition on my hdd. Maybe that has something to do with it? o_O
     
  9. MikeNash

    MikeNash Security Expert

    No, that really should not matter - OA will even ask for execution of programs on network drives or CD/USB drives.

    I will have to have a check and let you know - it could already be on the central trusted application list.
     
  10. Trooper

    Trooper Registered Member

    That is what I was thinking myself. Thanks Mike. :)
     
  11. MikeNash

    MikeNash Security Expert

    Yep, I can confirm that Steam is a recognised app on the trusted list.

    Cheers

    Mike
     
  12. starfish_001

    starfish_001 Registered Member

    I use Opera - do you have a list of sites that would be good for showing off OA's web content protection?

    Or is it just IE related?
     
  13. MikeNash

    MikeNash Security Expert

    It works for all browsers, even embedded so any site is good. Nasty sites that we are already aware of are entered in the central database - so when you visit them, you are not prompted and content is automatically blocked.

    Just as a demo, navigate to sites that use embedded activeX media players - it'll snip those fellas straight out.

    You can also visit secunia - some of the demos, for example local drive access, idn exploits, are already covered by OA


    Mike
     
  14. maddawgz

    maddawgz Registered Member

    gr8 work :)
     
  15. Tassie_Devils

    Tassie_Devils Global Moderator

    Yep... Just visited theinquirer site and get nice alert from OA [about ActiveX which I blocked] also my Firewall [Kerio] blocked some adverts. :D

    Great stuff, keep up the good work, I have been giving it a tryout/testing visiting some not so nice sites, warez, etc. just to see the alerting at work. :p

    Cheers, TAS
     

    Attached Files:

  16. Notok

    Notok Registered Member

    Yeah, sure.. :D :D
     
  17. Trooper

    Trooper Registered Member

    Thanks a lot Mike. Much appreciated. :D
     
  18. Trooper

    Trooper Registered Member

    It is definitely not IE related. I use FF (Moox version) as my only web browser. And even with using FF, I have been alerted about Active X on my yahoo mail acct as well as something like weather.com pages to view local weather. Since FF does not support Active X, it's a moot point but it is nice to see that OA is doing it's job and giving the user more control over what and what not to have run.

    HTH,

    Jag
     
  19. Tassie_Devils

    Tassie_Devils Global Moderator

    Oh ye of little faith. :p :p :p :cool: :cool: ROFL

    hmmm... one thing I did notice though, [unless a lot of sites have already been 'blacklisted' in OA's defs] is the very minor number of alerts I did get. I mean, I literally just clicked *anywhere* on any link I could see. I must have had at least 20 TABS opened in FF before I got even one alert about a 'dangerous object' which surprised me, and I ended up opening about 50 in total for around 4-5 alerts. [spent next 40 mins then doing scans by everything :cool: ]

    I never dreamed of just clicking anywhere like that before, and I certainly am not advocating now, but I suppose that even Warez sites have to be reasonaly clean for their 'clients' to get the stuff. One funny thing I saw, was a link to download Spybot "to get rid of spyware/malware from your system after visiting dubious sites", LOL.. :eek:

    TAS
     
  20. MikeNash

    MikeNash Security Expert

    There is a large-ish list of sites in OA's untrusted list by default - these will just silently block (although, if you really do want surf sidekick, add it as a trusted site and it will be allowed).

    This list will get reviewed fairly soon - Dog sent me a list of CWS sites, but, embarassingly, I ummm. lost them when I cleaned out my PM's :oops:

    I'm probably going to have a "submit dodgy site" feature, once we have more analysis of the elements that popup.

    Mike
     
  21. Trooper

    Trooper Registered Member

    Im glad you mentioned that Mike. I was going to suggest it to you but you obviously are on top of things at Tall Emu. ;)

    Regards,

    Jag
     
  22. Detox

    Detox Retired Moderator

    never ever delete stuff from Dog. he might seem like a poo-poo head but he is a Detox-approved-poopie-head. Thanks in advance for your anticipated cooperation.
     
  23. MikeNash

    MikeNash Security Expert

    Detox -
    From now on any PM I receive from Dog will be printed out and pasted at strategic locations around the office. I apologise to anyone who was offended by my not showing the appropriate reverence for the Detox-approved-poopie-head :D

    Mike
     
  24. Blackspear

    Blackspear Global Moderator

    You have that many toilets aye :eek: :D :cool: :ninja:
     
  25. Edwin024

    Edwin024 Registered Member

    OA seems to be a great programme. But it has a few odd problems. In my case it wouldn't work together with Tiny Firewall Pro. I hope this problem will be history soon. Tiny is just too expensive to keep in a folder but not using it...:)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice