Hips and ADS

Discussion in 'other anti-malware software' started by _kronos_, Feb 14, 2009.

Thread Status:
Not open for further replies.
  1. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    As far as I know, GesWall has no special rules for ADS. It just isolates them like any other isolated files so they can,t damage the system.

    Moreover recent version was supposed to make ADS visible in GW File Scanner. However I have not tried it yet whether it is implemented/ working or not.
     
  2. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    I would prefere the Comodo warning.
     
  3. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    That was what I intended to post, with GW there are no extra rules needed, GW protects against ADS based intrusions out of the box (=no extra rules needed to configure)

    See Aigle "they" have to ask you (or Henk1959), your posts concerning GW are much clearer :p
     
  4. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Hmm..... thanks but really i have very little knowledge excpet for hit n trial while on the other hand it,s your own field.
     
  5. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    I know many of the members here don't bat an eye at EQSecure anymore because of it's lack of official support and/or lack of interest from it's developer, but they left behind here a real solid Jewell.

    EQS with an ads rule completely refuses any adding of an alternate data stream and if like me, you created one for your own research or other purposes, it's LOCKED OUT from activating anything.

    Just some food for thought. This HIPS covers the gambit, left behind or not, it's exceptionally formidable and versatile in that you can AT-WILL make your own coverage rules and set them to alert or block completely in that respect. In addition, it immediately SUSPENDS any signaling to your system untill you either give it the go ahead or terminate the source offending communication to the system, effectively rendering any attempt to tap the file system, INERT!

    EASTER
     
  6. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Can u post a pic of this rule?

    Thanks
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.