topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Wednesday April 24, 2024, 7:42 am
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - Lusher [ switch to compact view ]

Pages: prev1 [2]
26
Prevx Computer Security Investigator (CSI)

Our FREE Prevx CSI scanner allows you to benefit from the knowledge gained from our vast community of users. Prevx CSI scanner is click-and-go, requires no installation or reboot, which means it's quick and easy to use. Its small size allows you to take it anywhere and use it as many times as you like, and even copy it to your friends.

http://www.prevx.com/freescan.asp

27
No. No. Wilders is not affected at all. That is a link to the discovery and discussion on Wilders security forum. Wilders does not host AVAST forums.. You can visit the link i posted without problems..

The affected site is on AVAST's own servers...

Hi everyone,


I'm a former active member of the avast! forum and I just want to clear some stuff up regarding about the mess Alwil had to deal with:

Finally some attempt at damage control.

Neither Alwil nor avast! were hacked by this exploit. 

A half truth. Hint look at the domain name.... The fact is Alwil was responsible for the forum and they screwed up.

It was the forum software that was hacked. 

No one implied otherwise.


28
I know of this one. But is the snapshot manager as good as the one in vmware workstation?

29
What's the Best? / Re: Anti-Virus Package
« on: September 09, 2007, 02:27 AM »
In my view Panda is *greatly* underestimated. It should be up there with BitDefender, KAV and NOD32, Avaria etc.

A piece of crap that no-one should use is Comodo AV. There's way too much hype about it, it's buggy even for a beta and has low detection rates and they try to cover it with "HIPS". But It's "HIPS" is basically only a glorified white list of processes.

People get carried away with thinking Comodo is god, their firewall is decent yes (and even then only in the silly leak tests), but making a good AV is degrees of magintitude harder.

31
Actually Darwin, the site also fed a different exploit if you were using firefox or opera.

32
Thanks Lusher - just to confirm, this affects only the Avast forums hosted on wilderssecurity, not all wilderssecurity hosted threads, right? Didn't want to click on the link, just in case, and don't want to risk visiting the forums at them moment!

No. No. Wilders is not affected at all. That is a link to the discovery and discussion on Wilders security forum. Wilders does not host AVAST forums.. You can visit the link i posted without problems..

The affected site is on AVAST's own servers...

33
BTW guys visiting AVASt! forum in the last 24-48 hours should be careful, apprently the forum was hacked and it was trying to infect people via a iframe and security exploit...

http://www.wildersse...wthread.php?t=183634

Do a full scan just in case.

34
I think Gimzo is overrated when it comes to giving advise about security software, but that's just me.

35
So this is the security software thread??? shouldn't there be seperate threads for different classes of security?

36
truth be told i'm wary of all of these executable-wrapper protection tools, and prefer using a full virtual machine tool like vwware or virtualpc.
Yeah, it's more secure. Anything based on API hooking shouldn't be too hard to circumvent. BufferZone does sound a bit interesting, though, in that it uses a kernel mode filter driver instead of simple ring3 API hooking.


Actually most of the good ones implement drivers but it doesn't mean that 100% of the implementation is ring zero.

I think it doesn't provide as much protection as running a flow blown vmachine (not that those are 100% protection either) of course, but it
provides reasonable protection. While they don't stop zero days from say browsers from starting, they can prove to be fairly effective in mitigating the damage and preventing it from spreading , and in most cases,  clearing the sandbox will remove everything


37
- and do you like it? Anything special to remember?

(see attachment in previous post)

Conflict of interest , so I prefer not to comment.

38
Besides full-blown Virtual machines (VirtualPC, VMware server is free) there are application level virtualization sandboxes..

Sandboxie is perhaps the most famous - http://www.sandboxie.com/

A recent new entry is SafeSpace (beta/freeware) - http://www.artificia...gister-personal.aspx

BufferZone as already being mentioned (freeware for single app), GreenBorder has being sold to google and might be released free in the future.

Another one  lesser known is Virtual Sandbox  - http://www.fortresgrand.com/

There's also http://www.vappware.com/vapp/ but I don't recommend it.

There are other sandboxes that are "policy control type sandboxes" , they don't virtualize the file system but just sandbox programs and prevents them from carrying out certain potentially dangerous actions.

Popular examples are

GeSWall (free version), Coreforce (free), Defensewall, DriveSentry (free) etc

http://www.gentlesec....com/getstarted.html
http://www.drivesentry.com/index.htm
http://force.coresec...se&page=download

Next there are apps that use windows own built in policy management. They either make it easier to run all the time in none-admin accounts (Sudown) or conversely run selected programs like browsers with restricted rights (drop myrights).

http://sudown.sourceforge.net/
http://cybercoyote.o.../security/drop.shtml

There's also Altiris Software Virtualization Solution (free)- http://www.svsdownloads.com/ which I don't know how to classify but that one isn't meant as a sandbox/ for security purposes.

Lastly there is Retunril (free) , PowerShadow, Shadowsurfer, firstdefense, rollback rx, Windows SteadyState (free) which are often called virtualization, but are closer to rollback tools.

These software allow you to "freeze" the system partition (and sometimes other partitions). Once in this frozen stages (often called Shadow , virtualization or protected mode as well) any further file changes made to the partition during this period will only be temporary stored elsewhere (though it appears as normal to the user) and will be discarded once the system gets out of the frozen or protected state (typically at the next re-start).

There is 0% protection while in that state, malware is free to act as usual, but you are certain to restore back to pre-clean state.

Of course if you are the paranoid type and want to watch all programs and want granular control so you can give specific and indidivual permissions to each and every program as compared to sandboxing where the bunch of permissions of sandboxed processes are generally fixed, you should try out other HIPS like System Safety monitor or ProSecurity, but that's a whole other kettle of fish.


http://wiki.castleco...ization_-_Comparison
http://wiki.castleco...ticing_Safe_Installs
http://wiki.castleco...f_freeware_sandboxes
http://wiki.castleco...eware_virtualization







 


39
Already have it. :)

40
Started with Apple II as well.

Far from the oldest game I have played, but Master of Magic is a game that I still play occasionally.

There is no game like it, I prefer it to Master of Orion (though 1 & 2 were classics as well), Civilization , or pretenders to the throne like Age of Wonders (I,II,etc), Heroes of Might and Magic, Lords of magic etc..


Dominions is pretty cool, but isn't geared for Single Player and is I think overly complicated for my tastes.

If you have never played Master of Magic, you need to! The graphics are old (but I kinda of like the style), but the gameplay is among the deepest I have seen and yet engaging. (I think games like Space empires V, and Dominions are too complicated to be playable for all but 0.1% of players and I'm pretty hardcore!)


41
Just curious any of you come from Wilders Security, CastleCops, or similar security related forums like myself?

We tend to be pretty obsessed with this security software business, and some of us are even "experts" on the subject.  :)

42
Thanks for the welcome Mouser.

I'm also planning a mini-review/comparison between this and others like Hijackthis!, AutoRuns and a2squared Hijackfree.


43
I've being using it for a couple of months. But I use it more like a blog really, and to see how many new site on security software  I can put in quick before someone else does.

Quite fun really, to see how many fans you can get....

44
http://www.runscanner.net/


RunScanner is a completely free windows system utility which scans your system for all configured running programs. You can use runscanner to detect autostart programs, spyware, adware, homepage hijackers, unverified drivers and other problems. You can import and export your results and let other people help you to solve your problems.


Very comprehensive autostart list

*Scanning of 80+ hijack locations ,Host file editor

Covers everything from autoruns, HJT, silentrunners and more. Malware will find it harder than ever to hide.

Easier to use

*Online malware analysis of results

*Verification of file signatures (Microsoft signed, Other Signed, Whitelisted by online database )

*MD5 hash calculation of files + online file rating

*Online lookup of scanned entries. (Runscanner database + Google)

RunScanner makes it easier to determine which entries are likely to be malicious.

Log analysis made easy

*Saving and importing of text files (all information available)

*A user with problems can save the .run file, an expert can mark the items that need fixing and send the .run file back to the user

If you are really worried, RunScanner also exports a easily readable textfile of all finding that can be sent to an expert for checking.

Malware removal abilities and misc


*Powerful process killer
-Kill multiple processes at once
-Kill and rename
-Kill and delete
-Delete at next reboot
*Regedit jump
*Explorer jump
*Extended filters
*Marking of items.

45
Thanks for the comments. Blink Neighbourhood watch was indeed freeware which they replaced...

Blink  Personal Edition is not freeware, but does offer a one year free subscription for most  regions has correctly noted on the wiki.

Pages: prev1 [2]