MS Word, AVG 2011, Norton Online Family, IIS, Apache and some other compatibility issues are solved. Programming errors in protection are fixed.
1. Windows Vista/7 Scheduler issue solved
2. Windows Vista/7 login/logout issue solved
3. Overal protection level increased
Here is the list of additional DefenseWall switches. They all meant to be created into the HKEY_LOCAL_MACHINE\Software\SoftSphere Technologies\DefenseWall\Options registry key.
REG_DWORD:"init_start_menu"- if its value is zero, DW do not create "DefenseWall" sub-menu item into the "Start"->"Programs" menu.
REG_SZ:"force_hips" with empty string, if it's exists, DW is working in HIPS mode wherever your license is.
REG_SZ:"untrusted_list_add_folders" with empty string, if it's exists, DW adds folders, created by untrusted, into the "Untrusted Applications" list.
Just briefly tested DefenseWall 3.10 Beta and Ilya still hasn't done anything to address this vulnerability in DefenseWall:
Zaloguj lub Zarejestruj się aby zobaczyć!
Zaloguj lub Zarejestruj się aby zobaczyć!
It's a very simple bypass to reproduce (and this is just an example of a potentially malicious "attack vector"):
1. Install Adobe Reader and DefenseWall.
2. Download any PDF document and make sure it's "Untrusted".
3. Open Windows Task Manager - look for a process called "AcroRd32Info.exe" - if it's running, terminate it.
4. Hover your mouse cursor over the PDF document while watching for "AcroRd32Info.exe" to spawn in Task Manager.
5. Check DefenseWall to see if "AcroRd32Info.exe" is running "Untrusted". Since the PDF document is "Untrusted", we would expect DefenseWall to run anything related to it as "Untrusted" too.
6. Notice that "AcroRd32Info.exe" is actually running "Trusted"!
1. Tray menu re-built.
2. New popup dialog on new "Program Files" folder making by untrusted process.
3. "Untrusted Applications", "Rollback", "Firewall" and "Defense Excludes" dialog's lists are much faster.
4. Untrusted status visualization with Windows Explorer.
5. Whitelist is enhanced.
6. Two BSOD issues solved.
7. Minor security and compatibility issues solved.
Multiple kernel memory leaks issues are solved, as well as few BSOD ones.
The DefenseWall HIPS program license is Lifetime, however updates, email notifications and first-queue support expire after 1 year unless you renew (extend, prolongate) your license.