Help - Search - Members - Calendar
Full Version: Defense Excludes question
Gladiator Security Forum > SoftSphere Technologies Support Forums > DefenseWall HIPS
demoneye
HI

i just add some folder to "Defense Excludes" and what i see is when i download files from firefox (set as trusted and run like that) all files become "untrusted" from some reason , i try moving files insides my "Defense Excludes" folder , and files remain trusted as it was in the first place

any idea if its normal?


cheers
Ilya Rabinovich
I just don't understand something. You added some folders into the "File and registry protection excludes" and now, saving into the folder makes the files untrusted? Do you save with untrusted process or trusted?
demoneye
QUOTE (Ilya Rabinovich @ Sep 1 2009, 09:24 AM) *
I just don't understand something. You added some folders into the "File and registry protection excludes" and now, saving into the folder makes the files untrusted? Do you save with untrusted process or trusted?


yes , as i wrote , i uses firefox as trusted (trsuted process).
Ilya Rabinovich
It means, malware can modify files you download from within trusted zone. Not really good choice from the security point of view.
demoneye
i think you didnt understand my question so i ask it again like that

1. firefox.exe run as "TRUSTED" (i disable it from run untrusted)
2. i add folder c:\my stuff to "File and registry protection excludes"
3.i download some files from the net to c:\my stuff (using TRUSTED firefox.exe)
4. all files in c:\my stuff became "UNTRUSTED" (even firefox.exe is disabled and run TRUSTED)

according to to DW manual

The Defense Excludes List contains files that are allowed to be Modified by Untrusted applications or processes.

.........i don't understand what is going on , since all files downloaed to c:\my stuff been d/l by TRUSTED firefox.exe
why DW make them untrusted?

can u check this and explain?

10x alot
Ilya Rabinovich
First, you have to check if the folder itself is trusted. Or the drive itself.
demoneye
10x ilya , i solved the riddle eventually
TheSentinel
Hi demoneye

QUOTE (demoneye @ Sep 2 2009, 08:36 AM) *
10x ilya , i solved the riddle eventually


can you please share your solution with all others in here? I guess there might be other users dealing with the same or similar problems.

Thanks in advance for your help
B. Udo
demoneye
the way i overpower it was simple my mistake , i mean i forgot i add c:\sanbox in "untrusted " list (add it manually) and what ever downloaded by firefox (i set him trusted) became "untrusted" and it OK :)

cheers
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.