Help - Search - Members - Calendar
Full Version: How can i test defensewall myself?
Gladiator Security Forum > SoftSphere Technologies Support Forums > DefenseWall HIPS
Killer22
Guys is there any way i can test defensewall against malware? I know the malware will be untrusted but how do i know they are being restricted?
darthsideous666
I do not believe that anyone is going to post any direct links to malware for you to infect yourself, nor do I believe that the forum would allow it! With that said, I am sure if you searched the internet yourself you would find what you are looking for in a short period of time, just becareful what you wish for! You can also reference this site for some independent malware test results as well.
Killer22
U don't understand my question. I'm not asking for malware links or samples I already have them.
My question is: how do i know the malware samples are being restricted?
Ilya Rabinovich
Simple- just make a folder, add it into the untrusted group and place the samples there. You can check it with right-click-"DefenseWall HIPS"-"File properties".
Killer22
QUOTE (Ilya Rabinovich @ Jul 19 2009, 06:52 PM) *
Simple- just make a folder, add it into the untrusted group and place the samples there. You can check it with right-click-"DefenseWall HIPS"-"File properties".

I know that. I meant something like in real-time. i.e. i'm surfing and a drive by comes, it downloads malware etc. That malware will be allowed to run in untrusted but how can I tell that its being restricted?
When it is allowed to run as untrusted it is still allowed to connect to the internet, so if there is a trojan dropper, it can download more trojans, so how can i tell they (the trojans or malware) can't harm my system?
Ilya Rabinovich
QUOTE (Killer22 @ Jul 19 2009, 04:25 PM) *
I know that. I meant something like in real-time. i.e. i'm surfing and a drive by comes, it downloads malware etc. That malware will be allowed to run in untrusted but how can I tell that its being restricted?

If it is running untrusted, it's already under the rights restrictions.

QUOTE (Killer22 @ Jul 19 2009, 04:25 PM) *
When it is allowed to run as untrusted it is still allowed to connect to the internet, so if there is a trojan dropper, it can download more trojans, so how can i tell they (the trojans or malware) can't harm my system?

Yes, currently they are able to connect Internet and call home. With upcoming V3 Persponal Firewall this will be covered.
To check out if malware could penetrate defense or not, use special tools like AVZ.
Killer22
Dude i can See you getting away with it without really answering my question. Oh well, i haven't gotten anything through my current setup anyway.
If i disable defensewall, first line is NOD32, then comodo. Only 1-3% have gotten through NOD32 and nothing through comodo.
And for DefenseWall v3, will the HIPS for the firewall be the same or will it ask questions like comodo, online armor?
And will the skin in v2.43 and earlier brought back or a new one is coming up?
Ilya Rabinovich
QUOTE (Killer22 @ Jul 19 2009, 07:03 PM) *
Dude i can See you getting away with it without really answering my question.

I did answers the way I could understand your questions. Don't forget that my English is not native.

QUOTE (Killer22 @ Jul 19 2009, 07:03 PM) *
And for DefenseWall v3, will the HIPS for the firewall be the same or will it ask questions like comodo, online armor?

The HIPS part is always the same, there will be just one type of popup window added- running a program from within "Download Areas" folder as untrusted will cause DW to ask user if he/she wants to run it as trusted. Very suitable feature.

Its firewall part will be very different from anything you ever saw (for example, DW V3 PF doesn't have so-called "learning mode").

QUOTE (Killer22 @ Jul 19 2009, 07:03 PM) *
And will the skin in v2.43 and earlier brought back or a new one is coming up?

I hope so. Skinning class in in work by a freelancer.
andro
QUOTE (Ilya Rabinovich @ Jul 19 2009, 11:57 PM) *
there will be just one type of popup window added- running a program from within "Download Areas" folder as untrusted will cause DW to ask user if he/she wants to run it as trusted. Very suitable feature.

Yes.
Will this feature be in DW?
Chachazz
QUOTE
How can i test defensewall myself?


QUOTE (Ilya Rabinovich @ Jul 19 2009, 10:32 AM) *
To check out if malware could penetrate defense or not, use special tools like AVZ.
Ilya Rabinovich
QUOTE (andro @ Jul 19 2009, 09:16 PM) *
Will this feature be in DW?

This feature will be in both version of the program.
Killer22
Ilya:I did answers the way I could understand your questions. Don't forget that my English is not native.

Forget it man, I wasn't talking about your English.

Ilya:The HIPS part is always the same, there will be just one type of popup window added- running a program from within "Download Areas" folder as untrusted will cause DW to ask user if he/she wants to run it as trusted. Very suitable feature.

Great, can't wait to see it yourock.gif


andro
QUOTE (Ilya Rabinovich @ Jul 20 2009, 09:30 AM) *
This feature will be in both version of the program.

OK, thanks.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.