GesWall 2.6.Beta2 released

Discussion in 'other anti-malware software' started by aigle, Feb 21, 2007.

Thread Status:
Not open for further replies.
  1. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    Have any of you tried Geswall 2.6 beta on Windows Vista? Is it stable?

    dja2k
     
  2. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,564
    Location:
    New York City
    Is there a new Beta available that fixed the Keylogger Test problem?

    Thanks.
     
  3. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    As far as I know still no new beta.
     
  4. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    So no one has tried to run Geswall 2.6 Beta2 on Vista? I tried to installed it but keeps telling me, "the installer was interrupted before completion, please restart installer". Maybe I should report that to Geswall.

    dja2k
     
  5. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    That,s the right thing to do.
     
  6. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    They responded back and its a know issue with a temporary workaround but will get resolved by final version.

    dja2k
     
  7. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    That,s good. Were u able to install?
     
  8. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    Haven't tried the procedure yet, but I'll let you know. Probably do it today.

    UPDATE:

    The following procedure worked.

    1) copy geswall.2.6.freeware.beta2.updated.msi into c:\windows\system32
    2) in Windows Explorer open c:\windows\system32
    3) select cmd.exe
    4) click right mouse button and select "Run as Administrator"
    5) an UAC window will appear, click on OK to proceed
    6) as result non-UAC instance of cmd.exe is started
    7) type: msiexec.exe /i geswall.2.6.freeware.beta2.updated.msi

    I didn't know it had to do with the UAC, but now I know. I wonder if you have UAC off, if this procedure is necessary.

    dja2k
     
    Last edited: Mar 27, 2007
  9. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
  10. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,564
    Location:
    New York City
    The Anti-Keylogger Tests are now working correctly (Beta 3). Is Brian aware that Geswall failed the latest Windows cursor vulnerability?
     
  11. zopzop

    zopzop Registered Member

    Joined:
    Apr 6, 2006
    Posts:
    642
    @thankful

    which geswall failed the latest windows cursor vulnerability? the latest beta (2.6 R3) or geswall 2.5.1?

    ps. you tested this yourself? is there a site with the vulnerability that you can pm me so i can test it?
     
  12. Lucy

    Lucy Registered Member

    Joined:
    Apr 25, 2006
    Posts:
    404
    Location:
    France
  13. zopzop

    zopzop Registered Member

    Joined:
    Apr 6, 2006
    Posts:
    642
    IE did indeed crash. but i checked the geswall log and everything was either "isolated" or "redirected". if the registry is intact and all the files created/downloaded are isolated, aside from the annoyance of shutting down IE, what damage can this exploit cause? geswall doesn't stop IE from crashing, but the rest of the system would still be safe no?
     
  14. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    http://zert.isotf.org/tests/testani.htm
     
  15. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Not sure. If u have tested, it will be a good idea to post on their forum or mail them.
     
  16. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,564
    Location:
    New York City
  17. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
  18. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Hi zopzop, the thread is here.

    https://www.wilderssecurity.com/showthread.php?t=170165
     
  19. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    U might be correct. Actually I can be sure only after testing it against a real exploit.
     
  20. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
  21. zopzop

    zopzop Registered Member

    Joined:
    Apr 6, 2006
    Posts:
    642
    i brought this up with the folks over at geswall aigle and they confirmed the system isn't compromised.
     
  22. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Thanks, I was expecting so. I did post a thread at their forums too.
     
  23. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    So here is the complete list about what,s new in latest beta.

    They are still unsure about sporadic Explorer isolation. It could be fixed
    but due to tough repro they cannot confirm this yet.
     
  24. zopzop

    zopzop Registered Member

    Joined:
    Apr 6, 2006
    Posts:
    642
    aigle, what's the explorer isolation issue? this is the first i've heard of it.
     
  25. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Hi zopzop, see this post and related posts.

    https://www.wilderssecurity.com/showpost.php?p=955425&postcount=27

    There are two bugs, occassional episodic isolation of explorer in current non-beta, it is very rare and they are not able to reproduce.

    Isolation of explorer in current beta is known and reproducable and still to be fixed.

    I can confirm that this second bug is still there in latest beta.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.