Returnil's anti-execution component

ssj100 at 16h04
19
Jul
2010
Returnil's anti-execution component

It appears that Returnil will only block executables not already on the REAL system. Therefore, wouldn't malware potentially be able to use "scripting" executables to bypass this component and infect the REAL system (like those rootkits)? What I mean is, if you don't block eg. command prompt execution or vbscript execution, wouldn't this leave a hole that could be exploited?

This was one reason why I stopped using Faronics
About
This topic belongs to the forum
  • Numbers of topics : 437
  • Numbers of messages : 3880
  • Numbers of users : 180
  • Numbers of points : 199
Similar topics
Received via PM and I've been given the green light to reproduce/post it: Coldmoon wrote:Hi ssj100, I want you to understand that I am not astroturfing and my response to whether we reverse engineer competitor's products is true. We don't as this is
BE MY AGELESS MENCARI EJEN YANG BOLEH MEMASARKN PRODUK! Leng Lui (Pretty Gal) from Singapore also say Hovid's health supplement GOOD!!! http://sgblogs.com/entry/health-hovid/238947 Ageless Bio-Optima: Mengandungi 50mg
17K last price na.... RFS: Downgrade MOBO: Intel DX58SO Extreme CPU: i7 920 2.66 mhz 8mb cache COOLER: Corsair H50 hydo series RAM: 2x1gb DDR3 Kingstone 1333mhz Powercolor PCS+ HD5870 1GB = + 14.5k Call or text: 09228788228 /
http://www.sandboxie.com/phpbb/viewtopic.php?t=9281 Looks like great work. Tested it against a couple of commercial keylogging applications and it blocked them. Passes the Spyshelter keylogging test component too. Fails the Zemana keylogging tool on
Hi all, Leading on from this topic I asked about: /shadow-defender-f3/file-exclusions-in-shadow-defender-t274.htm I'm after a software that is like Returnil/Shadow Defender - always on mode. Where I can exclude certain files & registry
Forums from same category
See also
more_less
Informations

5 Replies For the topic :
"Returnil's anti-execution component"

This topic has been viewed 784 times.

Last message :
19/07/2010 at 16h04 by "ssj100"