Help - Search - Members - Calendar
Full Version: Babylon doesn't work as untrusted
Gladiator Security Forum > SoftSphere Technologies Support Forums > DefenseWall HIPS
dyy
Hi, Ilya:

Babylon doesn't work if runs as untrusted. Please see the logs.

Thanks for assistance
Ilya Rabinovich
Please, download the latest pre-2.51 build, this should helps.
dyy
Now, Babylon can run as untrusted, but mouse activation of Babylon translation has no response. Please see the log.

Thanks
Ilya Rabinovich
Please, send me this file- C:\Program Files\Babylon\Babylon-Pro\Captlib.dll
dyy
send to support@softsphere.com.
dyy
another issue is that Clipmate can't quickpaste entry to Word, Notepad, or whatsoever, but it can do basic paste (ctrl+v). please see the log. It is not a big deal, please look at it. if it poses a risk in terms of security, you can keep blocking it.

Thanks
Ilya Rabinovich
Don't run Clipmate as untrusted, it can't operate properly under the restrictions.

About your Babylon issue- re-download pre-2.51 build.
dyy
QUOTE (Ilya Rabinovich @ Mar 5 2009, 03:55 PM) *
Don't run Clipmate as untrusted, it can't operate properly under the restrictions.

About your Babylon issue- re-download pre-2.51 build.


The reason why I run Clipmate as untrusted is that it is so chatty. You will find it try hard to access explorer.exe and iexplorer.exe from DefenseWall Events log. My firewall also denies its request to internet connection. Actually the installer of Clipmate can be run as untrusted as well, although it brings up the CPU usage of DefenseWall to 100%. If you exit and reopen DefenseWall, the CPU usage is down to less than 1%. So one of the most expected features of V3 is to allow programs to be installed in either restricted or unrestricted mode, both of which can be rolled back like a sandbox.

In addition, thanks for the great Babylon work. Many sources consider that dll of Babylon as suspicious, because it tries to manipulate other programs. I will test it later and get you posted.
Ilya Rabinovich
QUOTE (dyy @ Mar 5 2009, 04:22 PM) *
So one of the most expected features of V3 is to allow programs to be installed in either restricted or unrestricted mode, both of which can be rolled back like a sandbox.

In fact, with V3 I'm going to implement a zone control simplification tools.
dyy
Great work thumbsup.gif . Thanks a lot. Babylon issue has been fixed.

Would you please check this Clipmate problem to see if you can do anything about it? Attached please see the log. It surely doesn't have to be run as untrusted, but if it is possible, why not tuck it in a steel safe? evilgrin.gif Basically, I would like to untrust everything with the exception of antivirus and firewall.
Ilya Rabinovich
Nope, sorry. "module C:\Program Files\ClipMate7\ClipMate.exe, Attemps to send keyboard/mouse input into the window of the process C:\Program Files\Mozilla Firefox\firefox.exe.". It's a thing that manipulates other processes dangerous way. You have to run it as trusted.

dyy
QUOTE (Ilya Rabinovich @ Mar 6 2009, 01:41 PM) *
Nope, sorry. "module C:\Program Files\ClipMate7\ClipMate.exe, Attemps to send keyboard/mouse input into the window of the process C:\Program Files\Mozilla Firefox\firefox.exe.". It's a thing that manipulates other processes dangerous way. You have to run it as trusted.


Thanks for your advice.

If it is a dangerous behavior of Clipmate, isn't it nice to restrict it as much as possible rather than trust it without any limitation? I still would like to run it as untrusted even though its functions are crippled somewhat. Maybe a manual HIPS such as Mamutu could help with this problem since one can customize the application activities in a number of ways. I think it is a dilemma to have smart, nonintrusive, mighty and customization in a single product.
Ilya Rabinovich
Clipmate is using that technique in order to make its work properly. It's a legitimate activity, other hand it just won't work. It's a trusted application!
dyy
Yep, I got it. No offense, I remember that with Comodo D+ you can allow or deny one program to access memory or interface of another program. I haven't try Mamutu yet, and may try it sometime later. Clipmate might be a legitimate application, but if you do the default installation, you will find such changes made to the system. I don't think all like the idea of a toolbar in your neat taskbar.

http://www.siteadvisor.com/sites/thornsoft...loads/16289283/
How does it modify my system?

*The following programs were registered in our Add/Remove Programs:

ClipMate 7
*

Buttons, toolbars, or other modifications were made to our browser.
*

The following icons were added to our desktop:

ClipMate.lnk
*

The following programs were set to run everytime our system is started:

C:\Program Files\ClipMate7\clipmate.exe
dyy
Okey, I admit that I am confused by the logic. With all due respect, let me put it this way. Please excuse me and I will stop here if you feel it’s too much for a discussion.

It is blocked. Can you unblock it? No, because it is a dangerous way. If it’s dangerous, can I run as untrusted? No, because it's a legitimate activity and you need to trust it. In short, it is both a dangerous way and a legitimate activity (puzzled face). I am just thinking about how I can better use a smart HIPS to protect my clipboard from being tampered apart from going back to intrusive classical HIPS.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.