Security Basics
Re: Re: Malware detection Jul 19 2012 10:50AM
Savvy95 gmail com (1 replies)
Re: Malware detection Jul 23 2012 04:31AM
Vic Vandal (vvandal well com) (2 replies)
Question: very slow wiresless with ath9k on latest arch linux kernel Oct 01 2013 12:01PM
err000r (err000r mail ru) (1 replies)
Re: Question: very slow wiresless with ath9k on latest arch linux kernel Oct 01 2013 08:32PM
Luis Lezcano Airaldi (luislezcair gmail com)
Re: Malware detection Jul 24 2012 01:31PM
Jeffrey Walton (noloader gmail com) (2 replies)
Re: Malware detection Jul 26 2012 02:53PM
Vic Vandal (vvandal well com) (1 replies)
RE: Malware detection Jul 26 2012 04:55PM
David Gillett (gillettdavid fhda edu) (3 replies)
RE: Malware detection Jul 26 2012 11:13PM
Glenn Duquette (gduquette midmark com) (1 replies)
Re: Malware detection Jul 26 2012 11:34PM
haZard0us (hazard0us pt gmail com)
Re: Malware detection Jul 26 2012 08:41PM
haZard0us (hazard0us pt gmail com) (1 replies)
Re: Malware detection Jul 26 2012 09:30PM
Jeffrey Walton (noloader gmail com)
Re: Malware detection Jul 26 2012 05:39PM
haZard0us (hazard0us pt gmail com)
RE: Malware detection Jul 24 2012 04:23PM
Eric Krumm (ekrumm commercemicro com)
Indeed, from my experience, MSSE runs far more efficiently than any of the popular/well marketed AV clients (Kaspersky, AVG, Symantec, Trend). Because of this, removing a competing product and replacing with MSSE vastly improves system performance (old or new). No toolbars/BHO, NDIS, "identity protection" or any other gimmicks is very appealing.

Also, on many occasions we have seen MSSE detect and successfully remove new malware that other products didn't even detect until their signatures included these programs - sometimes days later.

-----Original Message-----

From: listbounce (at) securityfocus (dot) com [email concealed] [mailto:listbounce (at) securityfocus (dot) com [email concealed]] On Behalf Of Jeffrey Walton

Sent: Tuesday, July 24, 2012 9:32 AM

To: Vic Vandal

Cc: security-basics (at) securityfocus (dot) com [email concealed]

Subject: Re: Malware detection

On Mon, Jul 23, 2012 at 12:31 AM, Vic Vandal <vvandal (at) well (dot) com [email concealed]> wrote:

> Quotes and responses:

>

> In closing, MS Security Essentials is not your best bet for identifying and defeating said malware.

>

Interestingly, Security Essentials has one of the better architectures with respect to ipc and process counts. For example, MSSE generally uses two processes (1 userland, 1 privileged) and has a minimal amount of handles shared between the two). It makes it difficult to attack the privileged component through userland via shared handles (Events, Mutexes, File, etc).

Other AV, such as TrendMicro or McAfee, can have 8, 10, or 12 processes in a system, and handle sharing was like an orgy. We found it very easy to attack privileged components through shared handles.

For example, we would accidentally shut down the firewall and update service while testing the scanner.

packetstormsecurity.org/files/100564/Old-Dogs-and-New-Tricks.pdf

Jeff

> ----- Original Message -----

> From: Savvy95 (at) gmail (dot) com [email concealed]

> To: security-basics (at) securityfocus (dot) com [email concealed]

> Sent: Thursday, July 19, 2012 6:50:44 AM

> Subject: Re: Re: Malware detection

>

> My 2 cents.....

>

> If you are not looking for a "large robust solution" and you have

> Windows, try a mixed solution of Microsoft Windows Security Essentials

> for servers and workstations to detect and eliminate,

>

> Windows inherent AppLocker for Windows 2008/Windows 7/Vista for whitelisting authorized apps.

>

> For Windows XP, try Microsoft SteadyState to "freeze" the machine configuration and any changes are automaticallly removed on reboot. Note: It's been discontinued since 2011 and support for XP will be too in the near future.

>

> I hope you don't have Windows 98/ME/NT/2000 in your environment as

> there is no hope for you. ;-)

>

> Security

> Essentials:http://www.microsoft.com/en-us/download/details.aspx?id=520

> 1

>

> Applocker (How to Guide):

> http://technet.microsoft.com/en-us/library/dd723686(v=WS.10).aspx

>

> SteadyState (search for the download) there is also a reference

> document for all settings in SteadyState here:

> http://windowsteamblog.com/windows/b/springboard/archive/2010/09/27/st

> eady-state-for-windows-7.aspx

>

> You could use Microsoft System Center to what you want and more.

>

> Good Luck

>

> Glen Victor

> CISSP, ITIL, CEH, MCT

>

> ----------------------------------------------------------------------

> -- Securing Apache Web Server with thawte Digital Certificate In this

> guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

>

> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4

> 42f727d1

> ----------------------------------------------------------------------

> --

>

------------------------------------------------------------------------

Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442
f727d1

------------------------------------------------------------------------

This e-mail and any files transmitted with it are for the

sole use of the intended recipient(s) and contain

information that may be privileged and confidential. Any

unauthorized review, use, disclosure or distribution is

prohibited. If you are not the intended recipient of this

e-mail, please delete this e-mail and any files transmitted

with it and notify the sender immediately.

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus