Help - Search - Members - Calendar
Full Version: DW set explorer.exe as UNTRUSTED
Gladiator Security Forum > SoftSphere Technologies Support Forums > DefenseWall HIPS
Kael
Ilya Rabinovich:
Hello!
I just installed DW 2.0 and try to test,I notice after I add Firefox to Untrusted applications,DW will automatically run explorer.exe as UNTRUSTED,as well.That is why I have to kill explorer.exe when I terminate Firefox,or I disable Protection of DW.I just want to know if it is possible to run Firefox itself as UNTRUSTED cos I think terminate explorer.exe sometimes may bring problems when I work...
Thank you!!
plus:there isn't any "driver NOT loaded" Problems after I install 2.0 official release,GREAT JOB!!

Regards!!

Kael'thas
secret365
I thought firefox.exe is untrusted by default?

& explorer.exe is listed as trusted process by default?
Ilya Rabinovich
Hm, strange situation.
1. What is your Windows version?
2. How do you add FireFox application into untrusted group?

So, step-by-step explanation would really clarify the issue.
Kael
QUOTE (Ilya Rabinovich @ Aug 13 2007, 08:29 AM) *
Hm, strange situation.
1. What is your Windows version?
2. How do you add FireFox application into untrusted group?

So, step-by-step explanation would really clarify the issue.


Ilya Rabinovich,
Thank you for your reply!!
1 MY OS version:Microsoft Windows XP [Version 5.1.2600];
2 I add Firefox by process for the first time and add it through file/folder for the 2nd.I did NOT install Firefox cause I restroed my OS in the past few days, and the Firefox still can be used.That's why DW DID NOT add it as UNtrusted as default.
3 I utilise Kaspersky AV 7,SSM and TINY(w/o firewall) and COMODO PF as well,when I load Firefox I notice that Comodo tells me that firefox modified by DF through windows message in the first place.

Thank you!!


Regards!!

kael
Ilya Rabinovich
First of all- I don't understand how it is possible to use FF without installation. If it is a portable version?

OK, and what was the results in first and second attempts? I assume, first one added Explorer to untrusted?

Also, DefenseWall doesn't modify processes.
Kael
QUOTE (Ilya Rabinovich @ Aug 13 2007, 05:18 PM) *
First of all- I don't understand how it is possible to use FF without installation. If it is a portable version?

OK, and what was the results in first and second attempts? I assume, first one added Explorer to untrusted?

Also, DefenseWall doesn't modify processes.



Ilya Rabinovich,
I installed Firefox out of my OS partitions so I can use it by going to its home directory and double-clicking it, I assure you that Firefox can be use by copying its folder from another PC,as well.
In my first attempt I tried to set Firefox as UNTRUSTED by adding via Untrusted applications>Add>Add Process,mais,I got explorer.exe as Untrusted in "Trusted and Untrusted Process Details".So when I want to "Stop Attack" or disable DW's Protection I had to terminate Explorer.exe in parallel.
Secondly, I tried to add Firefox via Untrusted applications>Add>Add Application,but I got the same result.

Do you think other security softs brings me this problem? Or you would say Compactibility?

Thank you for your reply!!!

Regards!!!


kael
Kael
Ilya Rabinovich,
Hello!
I've found that if I diable all protecton of TINY,everything will be OK.Now I see they do not get along with each other in
harmony.DO you happen to know someway to make them live together without complains?--I've given DW all of the rihgts
that I can grant it via TINY.

Thanx!!
Regards!!!



kael
Ilya Rabinovich
I believe, you mean "Tiny Firewall"? If it is- I'll try to reproduce the issue under virtual machine.

Edited: couldn't make it work under virtual machine- it just made it absolutely unworkable. So, I need you:
1. Run all the protections you have switched off of TINY.
2. Clean up all the events within "Events log" sheet.
3. Add Firefox to untrusted.
4. Get an error with Explorer.
5. Terminate all the untrusted processes sand run Explorer again.
6. Find defensewalll_log.log file, zip it and send to support [at] softsphere [dot] com

Hope, this will help me to ckarify the situation with this issue.
Kael
QUOTE (Ilya Rabinovich @ Aug 15 2007, 08:51 AM) *
I believe, you mean "Tiny Firewall"? If it is- I'll try to reproduce the issue under virtual machine.

Edited: couldn't make it work under virtual machine- it just made it absolutely unworkable. So, I need you:
1. Run all the protections you have switched off of TINY.
2. Clean up all the events within "Events log" sheet.
3. Add Firefox to untrusted.
4. Get an error with Explorer.
5. Terminate all the untrusted processes sand run Explorer again.
6. Find defensewalll_log.log file, zip it and send to support [at] softsphere [dot] com

Hope, this will help me to ckarify the situation with this issue.



Ilya Rabinovich,
OK,I will follow your instruction to make it ,wait my log,thank you!


Regards!

kael
Kael
Ilya Rabinovich,

I've sent you all the informations you need,please check your box and tell me what is the problem or I make wrong rules
in TINY Firewall,Thank you!

Regards!!!

kael
Ilya Rabinovich
See my answer via e-mail- I haven't see the information I need as the log file is limited for 50 records. I may send you build that generates debug output.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.