Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #31  
Old 12-02-2017, 05:05
Z-Rantom Z-Rantom is offline
Friend
 
Join Date: Aug 2015
Posts: 13
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 36
Thanks Rcvd at 13 Times in 7 Posts
Z-Rantom Reputation: 0
One thing you should know, all AVs are going in the wrong direction (collecting signatures for malwares)... at least this is the best they have, for now!

From my personal experience in bypassing AVs, ESET and Kaspersky were pain in the a** until you figure out how to do it
Reply With Quote
  #32  
Old 12-02-2017, 20:17
ionioni ionioni is offline
Friend
 
Join Date: Jul 2016
Posts: 80
Rept. Given: 8
Rept. Rcvd 3 Times in 3 Posts
Thanks Given: 124
Thanks Rcvd at 154 Times in 49 Posts
ionioni Reputation: 3
Best AV is ones common sense.
Reply With Quote
  #33  
Old 12-14-2017, 01:50
foosaa foosaa is offline
Friend
 
Join Date: Dec 2005
Posts: 112
Rept. Given: 36
Rept. Rcvd 14 Times in 11 Posts
Thanks Given: 179
Thanks Rcvd at 93 Times in 34 Posts
foosaa Reputation: 14
I use the following on my browsing PC (Win 7).

Firewall: TinyWall with lockdown mode. No incoming connections, all apps are blocked with only a small whitelisted ones. So outbound communication from any apps.

Always run as a normal user with elevation on need basis. Same is applicable for *nix and Windows OSes.

For development, I have another PC which contains Comodo Antivirus (Home / Edition - Freeware)

Won't open any downloaded executable files if found suspicious. Usually scan it with virustotal for safety if I feel fishy! (It's purely a gut feel, but has saved my **s many times!)

For most of the office documents, I've multiple universal viewers which can preview the file in read only mode. No VBScript / JScript executables.

Disabled the autorun on all removable drives.

No thumbnails stores enabled. A bit of lockdown and hardening on the windows side. Disabled most of the services which are not required / not used and manually enable them after enabling it using the Autoruns utility (from https://live.sysinternals.com).

So, mostly the services will be disabled and cannot be even run manually.

A bit of hardened and optimized TCP/IP Stack.

Being a reverser since school days (those who knew IBM DOS 4.0 / MS DOS 5.0 days!! ) also look for certain packed files / unpack them, run a quick analysis for infection / networking stuff, if I'm in a paranoid mode!

Apart from that as l don't run Antivirus!

Most of my mails are pure plain text, won't open html mails that easily.

Extra careful with attachments. Don't open attachments that easily even if it is from a known contact.

And no Java / JRE (though I have it on the dev. PC!), disable / remove all plugins (who uses it these days!! ) from the browsers.

Firefox Quantum with Noscript and Ghostery, Multiple Adblockers like Anti-Anti Adblock, AdGuard, URL Tracker removers like cleanurls) will help cutdown any web based malware infections.

Using Brave browser for some Google sites.

Mostly non-standard and smaller, portable applications (Complete set of apps from https://portableapps.com/) for most of the needs and doesn't trust MS, ADOBE, ORACLE, GOOGLE products that easily. Using alternates for most of their stuff.

Have multiple VirtualBox with a bit of patching with manually configured services and without networking and only read-only folders mapped for ingress file copying.

Regular backups of all documents, Photos to Backup HDDs and important ones to cloud with a container based encryption (I don't want Google, DropBox, Mega or whomsoever to peer at my files!)

For encryption, I mostly use command line OpenSSL toolkit (which is compiled in my system)

Never has a virus or malware attack ever since I stopped writing them (from 1999) and before got fried multiple times! (that's a learning process!! )

All in all, the take away is that a bit of feeling paranoid about security with a little common sense and some lean / less resource hungry firewall, CCleaner, MalwareBytes antimalware, Comodo Antivirus, Less privileged user and some working knowledge will get you a long way!)

If possible switch to Linux for most of the day-to-day activities / development and keep windows only for browsing and some casual stuff and for reversing.

Hope it helps!!! Though the above being lot of off-topic stuff, just wanted to share what I do partially for staying safe!!

Peace and comments welcome!!
Reply With Quote
  #34  
Old 12-14-2017, 20:06
CodeCracker CodeCracker is offline
VIP
 
Join Date: Jun 2011
Posts: 905
Rept. Given: 68
Rept. Rcvd 660 Times in 278 Posts
Thanks Given: 64
Thanks Rcvd at 3,819 Times in 717 Posts
CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699
As antivirus I prefer Avira, because is free and don't consume that many computer resources.
Reply With Quote
  #35  
Old 12-29-2017, 01:38
Archer's Avatar
Archer Archer is offline
retired
 
Join Date: Aug 2005
Posts: 243
Rept. Given: 1
Rept. Rcvd 46 Times in 19 Posts
Thanks Given: 3
Thanks Rcvd at 387 Times in 57 Posts
Archer Reputation: 46
Antiviruses in their classical meaning are completely useless and by definition fall far back behind offensive side. And quite often they even increase attack surface, basically doing the opposite of what they're supposed to do.

My bet is on sandboxing/isolation. And since it may be tedious to start a full-fledged VM for every downloaded executable and bigger software tend to have more bugs including security ones, light and secure software relying on documented Windows principles like ReHIPS is my choice.
Reply With Quote
The Following User Says Thank You to Archer For This Useful Post:
p4r4d0x (12-29-2017)
  #36  
Old 12-29-2017, 20:26
cybercoder cybercoder is offline
Friend
 
Join Date: Aug 2005
Posts: 115
Rept. Given: 2
Rept. Rcvd 11 Times in 8 Posts
Thanks Given: 23
Thanks Rcvd at 46 Times in 31 Posts
cybercoder Reputation: 11
Hasn't this topic just been posted to death.. So many what do you use for protection posts...
Reply With Quote
  #37  
Old 01-01-2018, 18:14
JMP-JECXZ JMP-JECXZ is offline
Friend
 
Join Date: Mar 2017
Posts: 123
Rept. Given: 0
Rept. Rcvd 5 Times in 4 Posts
Thanks Given: 15
Thanks Rcvd at 150 Times in 69 Posts
JMP-JECXZ Reputation: 5
Quote:
Originally Posted by mr.exodia View Post
All antivirus is a scam
This, the best antivirus is Common Sense 2017, and now it's time to update to version 2018.
Reply With Quote
  #38  
Old 01-01-2018, 19:54
wassim_ wassim_ is offline
Friend
 
Join Date: Nov 2002
Posts: 105
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 15
Thanks Rcvd at 11 Times in 5 Posts
wassim_ Reputation: 2
sandoxie is the only "antivirus" you need, run the suspicious exe within and decide for yourself whether it's safe or not. Use restriction for full protection.
Reply With Quote
  #39  
Old 01-02-2018, 07:09
h8er h8er is offline
Friend
 
Join Date: Jan 2002
Posts: 43
Rept. Given: 45
Rept. Rcvd 7 Times in 6 Posts
Thanks Given: 154
Thanks Rcvd at 13 Times in 6 Posts
h8er Reputation: 7
Quote:
Originally Posted by wassim_ View Post
sandoxie is the only "antivirus" you need, run the suspicious exe within and decide for yourself whether it's safe or not. Use restriction for full protection.
good tip but you also have to take into account that some malware have anti sandboxie tricks and they don't reveal their malware behavior if they detect they are running under sandboxie
Reply With Quote
  #40  
Old 01-09-2018, 06:02
gigaman gigaman is offline
Friend
 
Join Date: Jun 2002
Posts: 87
Rept. Given: 0
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 14 Times in 11 Posts
gigaman Reputation: 4
Well if you run them only in the sandbox, it doesn't really matter, right?
If they don't trigger the payload, good for you
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Black Hat USA 2017 TechLord General Discussion 4 08-31-2017 12:48
Best Antivirus Engine mantovano General Discussion 102 02-16-2011 18:13
Antivirus API just4urim General Discussion 4 02-06-2005 02:49


All times are GMT +8. The time now is 20:27.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )