ZeroVulnerabilityLabs ExploitShield

Discussion in 'other anti-malware software' started by sbwhiteman, Sep 28, 2012.

Thread Status:
Not open for further replies.
  1. Feandur

    Feandur Registered Member

    Joined:
    Jun 15, 2005
    Posts:
    429
    Location:
    Australia
    Excellent... :thumb:

    thanks ZeroVulnLabs

    -cheers,
    feandur
     
  2. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,871
    Location:
    New York City
    Running version 0.8.1. Stopping protection via the context menu stops protection correctly but label on menu remains "Running".
    WSA 8.0.2.96, IE 9, Windows 7 32 bit
     
  3. guest

    guest Guest

    Are any of the incompatibilities with other security software already solved?
    Trusteer Rapport, Comodo...
     
  4. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Yes, known issue #6:
    http://www.zerovulnerabilitylabs.com/forum/viewtopic.php?f=2&t=147

    Haven't heard anything back from them. Comodo reports a hotfix in a couple of weeks so if we're lucky the fix will be included there.
     
  5. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Webroot says they fixed it and will be released in their next beta. I've heard the new Comodo 6 hotfix also fixes the incompatibility with ES, but I haven't had time to test and verify it yet.
     
  6. popcorn

    popcorn Registered Member

    Joined:
    Apr 3, 2012
    Posts:
    239
    When the compatibility with CIS is fixed are they plans to add Comodo Dragon to the list of protected browsers ?
     
  7. Notok

    Notok Registered Member

    Joined:
    May 28, 2004
    Posts:
    2,969
    Location:
    Portland, OR (USA)
  8. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Yes we were aware of this one. In fact its the same as all the other Java-based FPs. Over 99% of the FPs by ExploitShield are due to Java apps which do things they shouldn't do in an ideal situation. Even though we've fixed a large portion of them, there are still some which we will take care of in future versions of ExploitShield.
     
  9. jo3blac1

    jo3blac1 Registered Member

    Joined:
    Sep 15, 2012
    Posts:
    739
    Location:
    U.S.
    Just curious. Does ExploitShield also protects against scripts?
     
  10. safeguy

    safeguy Registered Member

    Joined:
    Jun 14, 2010
    Posts:
    1,795
    I'm not ZeroVulnLabs but hope you don't mind...

    No it doesn't, at least not directly. ExploitShield was designed to stop payloads...which are an aftereffect of some malicious scripts.
     
  11. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Actually some of them it will, the ones that are abused by exploits. For example wscript.exe is shielded by default by ExploitShield even though it doesn't show up under the GUI SHIELDS tab. There are other "internal" shields which are part of the OS. If you're talking javascript for example, as safeguy says they are precursor of the exploit payload and those exploits will also be stopped by ExploitShield.
     
  12. jo3blac1

    jo3blac1 Registered Member

    Joined:
    Sep 15, 2012
    Posts:
    739
    Location:
    U.S.
    Interesting. Good to know.
     
  13. constantine76

    constantine76 Registered Member

    Joined:
    Dec 18, 2010
    Posts:
    191
    Some of the torrent sites I visit require javascript enabled, have not tried ES on the machine I use for torrents but on that machine I use the built-in Windows Firewall there. (Most of my pals also because a 3rd party firewall sometimes causes some slowdown during downloading/surfing at the same time). How can ES protect me there?
     
  14. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    If any of those sites is compromised to redirect to an exploit kit, or hosts a malicious javascript or malvertising which loads an exploit, then ExploitShield would protect you from that exploit.
     
  15. jo3blac1

    jo3blac1 Registered Member

    Joined:
    Sep 15, 2012
    Posts:
    739
    Location:
    U.S.
    Any chances on changing the tray icon into something more visually appealing? Someone else in here made a green shield, looked really good. Better yet, an option to hide icon in the first place. Zero Shield works in the background and there is no need to have it there in the first place.
     
  16. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Well under Vista and above you can configure the traybar to hide the icon easily, so really no need to develop something specific for that.
     
  17. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,237
    Location:
    USA
    Depends on what you mean by "hide". At the moment clicking the icon is the only way to access the settings.
     
  18. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello,

    I can confirm, on my system at least, with the latest beta (8.0.2.103) the compatibility problems with Webroot have been fixed.
     
  19. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Great news, thanks for posting this!!
     
  20. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    I'm not running Comodo at the moment, but have you verified if the incompatibilities have been fixed or not with this recent release?.

    It's been a while since you posted the above message, figured you may have some news for us by now.
     
  21. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Sorry, haven't had time to test this yet. I'll keep you posted as soon as we do.
     
  22. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Thank you :thumb:
     
  23. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
  24. Techwiz

    Techwiz Registered Member

    Joined:
    Jan 5, 2012
    Posts:
    541
    Location:
    United States
    :thumb: :thumb:

    Hopefully a pro version with similar functionality becomes available. It's hard for me to leave sandboxie, but I would definitely recommend this to friends that complain about using sandboxie. This seems less intrusive, and from what I've read offers a similar degree of protection. :thumb:
     
  25. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Yes, the last link I posted shows ExploitShield blocking this Acrobat Reader PDF zero-day.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.