Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #31  
Old 12-02-2017, 05:05
Z-Rantom Z-Rantom is offline
Friend
 
Join Date: Aug 2015
Posts: 13
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 36
Thanks Rcvd at 13 Times in 7 Posts
Z-Rantom Reputation: 0
One thing you should know, all AVs are going in the wrong direction (collecting signatures for malwares)... at least this is the best they have, for now!

From my personal experience in bypassing AVs, ESET and Kaspersky were pain in the a** until you figure out how to do it
Reply With Quote
  #32  
Old 12-02-2017, 20:17
ionioni ionioni is offline
Friend
 
Join Date: Jul 2016
Posts: 80
Rept. Given: 8
Rept. Rcvd 3 Times in 3 Posts
Thanks Given: 92
Thanks Rcvd at 154 Times in 49 Posts
ionioni Reputation: 3
Best AV is ones common sense.
Reply With Quote
  #33  
Old 12-14-2017, 01:50
foosaa foosaa is offline
Friend
 
Join Date: Dec 2005
Posts: 106
Rept. Given: 36
Rept. Rcvd 13 Times in 11 Posts
Thanks Given: 163
Thanks Rcvd at 84 Times in 32 Posts
foosaa Reputation: 14
I use the following on my browsing PC (Win 7).

Firewall: TinyWall with lockdown mode. No incoming connections, all apps are blocked with only a small whitelisted ones. So outbound communication from any apps.

Always run as a normal user with elevation on need basis. Same is applicable for *nix and Windows OSes.

For development, I have another PC which contains Comodo Antivirus (Home / Edition - Freeware)

Won't open any downloaded executable files if found suspicious. Usually scan it with virustotal for safety if I feel fishy! (It's purely a gut feel, but has saved my **s many times!)

For most of the office documents, I've multiple universal viewers which can preview the file in read only mode. No VBScript / JScript executables.

Disabled the autorun on all removable drives.

No thumbnails stores enabled. A bit of lockdown and hardening on the windows side. Disabled most of the services which are not required / not used and manually enable them after enabling it using the Autoruns utility (from https://live.sysinternals.com).

So, mostly the services will be disabled and cannot be even run manually.

A bit of hardened and optimized TCP/IP Stack.

Being a reverser since school days (those who knew IBM DOS 4.0 / MS DOS 5.0 days!! ) also look for certain packed files / unpack them, run a quick analysis for infection / networking stuff, if I'm in a paranoid mode!

Apart from that as l don't run Antivirus!

Most of my mails are pure plain text, won't open html mails that easily.

Extra careful with attachments. Don't open attachments that easily even if it is from a known contact.

And no Java / JRE (though I have it on the dev. PC!), disable / remove all plugins (who uses it these days!! ) from the browsers.

Firefox Quantum with Noscript and Ghostery, Multiple Adblockers like Anti-Anti Adblock, AdGuard, URL Tracker removers like cleanurls) will help cutdown any web based malware infections.

Using Brave browser for some Google sites.

Mostly non-standard and smaller, portable applications (Complete set of apps from https://portableapps.com/) for most of the needs and doesn't trust MS, ADOBE, ORACLE, GOOGLE products that easily. Using alternates for most of their stuff.

Have multiple VirtualBox with a bit of patching with manually configured services and without networking and only read-only folders mapped for ingress file copying.

Regular backups of all documents, Photos to Backup HDDs and important ones to cloud with a container based encryption (I don't want Google, DropBox, Mega or whomsoever to peer at my files!)

For encryption, I mostly use command line OpenSSL toolkit (which is compiled in my system)

Never has a virus or malware attack ever since I stopped writing them (from 1999) and before got fried multiple times! (that's a learning process!! )

All in all, the take away is that a bit of feeling paranoid about security with a little common sense and some lean / less resource hungry firewall, CCleaner, MalwareBytes antimalware, Comodo Antivirus, Less privileged user and some working knowledge will get you a long way!)

If possible switch to Linux for most of the day-to-day activities / development and keep windows only for browsing and some casual stuff and for reversing.

Hope it helps!!! Though the above being lot of off-topic stuff, just wanted to share what I do partially for staying safe!!

Peace and comments welcome!!
Reply With Quote
  #34  
Old 12-14-2017, 20:06
CodeCracker CodeCracker is online now
VIP
 
Join Date: Jun 2011
Posts: 466
Rept. Given: 27
Rept. Rcvd 407 Times in 134 Posts
Thanks Given: 21
Thanks Rcvd at 1,888 Times in 359 Posts
CodeCracker Reputation: 400-499 CodeCracker Reputation: 400-499 CodeCracker Reputation: 400-499 CodeCracker Reputation: 400-499 CodeCracker Reputation: 400-499
As antivirus I prefer Avira, because is free and don't consume that many computer resources.
Reply With Quote
  #35  
Old 12-29-2017, 01:38
Archer's Avatar
Archer Archer is offline
retired
 
Join Date: Aug 2005
Posts: 239
Rept. Given: 1
Rept. Rcvd 46 Times in 19 Posts
Thanks Given: 3
Thanks Rcvd at 387 Times in 57 Posts
Archer Reputation: 46
Antiviruses in their classical meaning are completely useless and by definition fall far back behind offensive side. And quite often they even increase attack surface, basically doing the opposite of what they're supposed to do.

My bet is on sandboxing/isolation. And since it may be tedious to start a full-fledged VM for every downloaded executable and bigger software tend to have more bugs including security ones, light and secure software relying on documented Windows principles like ReHIPS is my choice.
Reply With Quote
The Following User Says Thank You to Archer For This Useful Post:
p4r4d0x (12-29-2017)
  #36  
Old 12-29-2017, 20:26
cybercoder cybercoder is offline
Friend
 
Join Date: Aug 2005
Posts: 114
Rept. Given: 2
Rept. Rcvd 11 Times in 8 Posts
Thanks Given: 22
Thanks Rcvd at 46 Times in 31 Posts
cybercoder Reputation: 11
Hasn't this topic just been posted to death.. So many what do you use for protection posts...
Reply With Quote
  #37  
Old 01-01-2018, 18:14
JMP-JECXZ JMP-JECXZ is offline
Friend
 
Join Date: Mar 2017
Posts: 86
Rept. Given: 0
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 14
Thanks Rcvd at 102 Times in 48 Posts
JMP-JECXZ Reputation: 1
Quote:
Originally Posted by mr.exodia View Post
All antivirus is a scam
This, the best antivirus is Common Sense 2017, and now it's time to update to version 2018.
Reply With Quote
  #38  
Old 01-01-2018, 19:54
wassim_ wassim_ is offline
Friend
 
Join Date: Nov 2002
Posts: 104
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 14
Thanks Rcvd at 10 Times in 4 Posts
wassim_ Reputation: 2
sandoxie is the only "antivirus" you need, run the suspicious exe within and decide for yourself whether it's safe or not. Use restriction for full protection.
Reply With Quote
  #39  
Old 01-02-2018, 07:09
h8er h8er is offline
Friend
 
Join Date: Jan 2002
Posts: 43
Rept. Given: 45
Rept. Rcvd 7 Times in 6 Posts
Thanks Given: 140
Thanks Rcvd at 13 Times in 6 Posts
h8er Reputation: 7
Quote:
Originally Posted by wassim_ View Post
sandoxie is the only "antivirus" you need, run the suspicious exe within and decide for yourself whether it's safe or not. Use restriction for full protection.
good tip but you also have to take into account that some malware have anti sandboxie tricks and they don't reveal their malware behavior if they detect they are running under sandboxie
Reply With Quote
  #40  
Old 01-09-2018, 06:02
gigaman gigaman is offline
Friend
 
Join Date: Jun 2002
Posts: 87
Rept. Given: 0
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 14 Times in 11 Posts
gigaman Reputation: 4
Well if you run them only in the sandbox, it doesn't really matter, right?
If they don't trigger the payload, good for you
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Best Antivirus Engine mantovano General Discussion 102 02-16-2011 18:13
Antivirus API just4urim General Discussion 4 02-06-2005 02:49
Anti Antivirus = ? Virus ?? Trojan ?? drasd_20002 General Discussion 3 06-05-2003 00:03


All times are GMT +8. The time now is 15:42.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )