Testing bifrost against various HIPS/sandboxes...

Discussion in 'other anti-malware software' started by aigle, Oct 18, 2007.

Thread Status:
Not open for further replies.
  1. gangABang

    gangABang Registered Member

    Joined:
    Oct 12, 2007
    Posts:
    19
    Re: what a hell APPdefend is INSECURE

    @aigle ok i will download it thank you.
     
  2. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Re: what a hell APPdefend is INSECURE

    Pls let us know of ur results. NG beta 3 has some install problems, so during install before you reboot, mark all ur security software as trsuted to avoid any problems.

    Were you able to know the problem of ur testing with EQS? Are u testing in VM/ shadow/ real system?
     
  3. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Tried NG beta 3 under ShadowMode of SS. It seems to pass the test.

    Examined SSDT using RKU. On my system under sahadow mode, it showed 33 hooks by NG.

    1- I executed server.exe, NG gave execurion pop up- allowed
    2- NG gave baloon alert from tray area that server.exe is stopped from accessing memory directly( direct memory access is denied by NG for any executable by default without any popup).
    3- NG gave popup that server.exe is trying to modify memory of explorer.exe- denied

    Nothing more and server.exe was dead.

    Again launched RKU and examined SSDT.All the hooks were in place, no unhooking at all.

    As before I am posting results as text files, so u can examine. These are 2 text files.

    1- Base-line SSDT in ShadowMode before running server.exe
    2- SSDT after running server.exe against EQS

    If I allow direct memory access to server.exe via NG, it removes 7 hooks of NG on my system.

    Thanks
     

    Attached Files:

Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.