SECURITY OVERFLOW http://kareldjag.over-blog.com/ 2005-03-23T22:25:18Z over-blog.com Atom 1.0 Generator http://accel6.fdata.over-blog.com/99/00/00/01/img/avatar.png actualité de la sécurité informatique http://kareldjag.over-blog.com/article-6649283.html HARDENING WINDOWS HOST Part 4: ACCOUNTS AND RIGHTS MANAGEMENTS 2007-09-17T17:55:24Z 2007-05-20T19:14:37Z kareldjag http://www.over-blog.com/profil/blogueur-348295.html <img src="http://idata.over-blog.com/0/03/91/26/2007/psoftodits.jpg" />IntroductionWith the release of Vista, many home users are certainly wondering if the migration from XP to Vista is absolutely necessary.As claims the VOX POPULI : &quot;Vista is an evolution, not a revolution&quot;.Hardening the system makes XP as secure as Vista.Since the hardware<a href="http://kareldjag.over-blog.com/article-6649283.html http://kareldjag.over-blog.com/article-3470338.html PERSONAL HIPS: THE TOP LIST 2007-09-17T17:55:24Z 2006-08-07T22:32:03Z Kareldjag http://www.over-blog.com/profil/blogueur-348295.html The greater part of these products have already been linked in the previous article.Therefore, only products that have not been listed yet are linked.As it often changes (freewares become paid), only paid softwares with or without a free limited versions are notified (P/FLV).When a product is<a href="http://kareldjag.over-blog.com/article-3470338.html http://kareldjag.over-blog.com/article-2381843.html IDS For HOME USERS 2007-09-17T17:55:22Z 2006-04-08T16:00:45Z Kareldjag http://www.over-blog.com/profil/blogueur-348295.html Intrusion detection is a large subject, and concerns mostly organizations.It's also important to note that IDS are supplanted by IPS/NIPS.Therefore we'll focus here only on IDS available for home users and Windows systems.First of all, the user must consider the need or not of an IDS on his line defense.It's also important to note that a<a href="http://kareldjag.over-blog.com/article-2381843.html http://kareldjag.over-blog.com/article-2150489.html HIPS tests news 2007-09-17T17:55:20Z 2006-03-14T19:57:30Z Kareldjag http://www.over-blog.com/profil/blogueur-348295.html I've quite finished the methodology.I've decided to choose a real-life infection approach; and consequently, it means more time for searching malwares and less time for blogging...In the first part of the methodology, the self-protection is tested (process, service and driver)<a href="http://kareldjag.over-blog.com/article-2150489.html http://kareldjag.over-blog.com/article-1925750.html Volunteers for HIPS tests 2007-09-17T17:55:20Z 2006-02-20T00:00:00Z Kareldjag http://www.over-blog.com/profil/blogueur-348295.html I'm looking for volunteers for testing HIPS white list such as DefenseWall, GesWall, AntiExecutable and PrevX (as Zorro PC Protector is in french language only, then i've choosed it for the test).   The volunteers (2 per product is enough) must:-have an<a href="http://kareldjag.over-blog.com/article-1925750.html http://kareldjag.over-blog.com/article-1841115.html AN OVERVIEW OF PERSONAL DESKTOP/HOST IPS 2 2007-09-17T17:55:22Z 2006-02-13T18:40:00Z Kareldjag http://www.over-blog.com/profil/blogueur-348295.html Other similar productsThese products monitors some system's area like the registry in order to detect malwares behaviours.They're not integrated (for most of them) at the core of the system (kernel) and then do not operate at a low level: except for specialized registry products (RegRun, RegDefend, Principal antivirus)<a href="http://kareldjag.over-blog.com/article-1841115.html http://kareldjag.over-blog.com/article-1693696.html AN OVERVIEW OF PERSONAL DESKTOP/HOST IPS 2007-09-17T17:55:22Z 2006-02-12T00:43:00Z Kareldjag http://www.over-blog.com/profil/blogueur-348295.html AN OVERVIEW OF PERSONAL DESKTOP/HOST INTRUSION PREVENTION SYSTEMS We have seen previously that a line defense with only a firewall and an antivirus is not enough in consideration of the evolution of threats.Products are available to palliate scanners weaknesses and to combat malwares by their behaviour.Theses<a href="http://kareldjag.over-blog.com/article-1693696.html http://kareldjag.over-blog.com/article-1649851.html WHY YOU SHOULDN'T RUN ONLY WITH AN ANTIVIRUS + FIREWALL AND WHY A PROACTIVE PROTECTION IS NECESSARY 2007-09-17T17:55:21Z 2006-01-25T00:00:00Z Kareldjag http://www.over-blog.com/profil/blogueur-348295.html <img src="http://idata.over-blog.com/0/03/91/26/repertoire1/keylog.jpg" />In this first article we’ll just show that the couple scanner (antivirus/antitrojan/antispyware) + Firewall is not sufficient to mitigate security risks for home users. Then we'll review and list available Desktop/Host<a href="http://kareldjag.over-blog.com/article-1649851.html http://kareldjag.over-blog.com/article-1482539.html ADVANCED INTEGRITY CHECKERS 2007-09-17T17:55:21Z 2006-01-13T00:22:00Z kareldjag http://www.over-blog.com/profil/blogueur-348295.html <img src="http://idata.over-blog.com/0/03/91/26/septembre/sentinel.jpg" />In a previous article, we've reviewed some free integrity checkers.On this article, we'll focus in advanced ones (paid for most of them).Integrity checking for change detection is an important feature for security softwares, especially in<a href="http://kareldjag.over-blog.com/article-1482539.html http://kareldjag.over-blog.com/article-1148950.html ABUSE SHIELD 2007-09-17T17:55:18Z 2006-01-12T00:00:00Z kareldjag http://www.over-blog.com/profil/blogueur-348295.html <img src="http://idata.over-blog.com/0/03/91/26/septembre/testdiv2/absettings.jpg" /> AbuseShield&quot; Globesoft AbuseShield&quot; is a comprehensive tool for monitoring and controlling your desktop or server environments so that only the software you specify can run.AbuseShield also monitor file system activities.This means that even if you, by misstake, allow a mallicious program to run, you can still see<a href="http://kareldjag.over-blog.com/article-1148950.html