SECURITY OVERFLOWhttp://kareldjag.over-blog.com/2005-03-23T22:25:18Zover-blog.com Atom 1.0 Generatorhttp://accel6.fdata.over-blog.com/99/00/00/01/img/avatar.pngactualité de la sécurité informatiquehttp://kareldjag.over-blog.com/article-6649283.htmlHARDENING WINDOWS HOST Part 4: ACCOUNTS AND RIGHTS MANAGEMENTS2007-09-17T17:55:24Z2007-05-20T19:14:37Zkareldjaghttp://www.over-blog.com/profil/blogueur-348295.html<img src="http://idata.over-blog.com/0/03/91/26/2007/psoftodits.jpg" />IntroductionWith the release of Vista, many home users are certainly wondering if the migration from XP to Vista is absolutely necessary.As claims the VOX POPULI : "Vista is an evolution, not a revolution".Hardening the system makes XP as secure as Vista.Since the hardware<a href="http://kareldjag.over-blog.com/article-6649283.htmlhttp://kareldjag.over-blog.com/article-3470338.htmlPERSONAL HIPS: THE TOP LIST2007-09-17T17:55:24Z2006-08-07T22:32:03ZKareldjaghttp://www.over-blog.com/profil/blogueur-348295.htmlThe greater part of these products have already been linked in the previous article.Therefore, only products that have not been listed yet are linked.As it often changes (freewares become paid), only paid softwares with or without a free limited versions are notified (P/FLV).When a product is<a href="http://kareldjag.over-blog.com/article-3470338.htmlhttp://kareldjag.over-blog.com/article-2381843.htmlIDS For HOME USERS2007-09-17T17:55:22Z2006-04-08T16:00:45ZKareldjaghttp://www.over-blog.com/profil/blogueur-348295.html
Intrusion detection is a large subject, and concerns mostly organizations.It's also important to note that IDS are supplanted by IPS/NIPS.Therefore we'll focus here only on IDS available for home users and Windows systems.First of all, the user must consider the need or not of an IDS on his line defense.It's also important to note that a<a href="http://kareldjag.over-blog.com/article-2381843.htmlhttp://kareldjag.over-blog.com/article-2150489.htmlHIPS tests news2007-09-17T17:55:20Z2006-03-14T19:57:30ZKareldjaghttp://www.over-blog.com/profil/blogueur-348295.htmlI've quite finished the methodology.I've decided to choose a real-life infection approach; and consequently, it means more time for searching malwares and less time for blogging...In the first part of the methodology, the self-protection is tested (process, service and driver)<a href="http://kareldjag.over-blog.com/article-2150489.htmlhttp://kareldjag.over-blog.com/article-1925750.htmlVolunteers for HIPS tests2007-09-17T17:55:20Z2006-02-20T00:00:00ZKareldjaghttp://www.over-blog.com/profil/blogueur-348295.htmlI'm looking for volunteers for testing HIPS white list such as DefenseWall, GesWall, AntiExecutable and PrevX (as Zorro PC Protector is in french language only, then i've choosed it for the test). The volunteers (2 per product is enough) must:-have an<a href="http://kareldjag.over-blog.com/article-1925750.htmlhttp://kareldjag.over-blog.com/article-1841115.htmlAN OVERVIEW OF PERSONAL DESKTOP/HOST IPS 22007-09-17T17:55:22Z2006-02-13T18:40:00ZKareldjaghttp://www.over-blog.com/profil/blogueur-348295.htmlOther similar productsThese products monitors some system's area like the registry in order to detect malwares behaviours.They're not integrated (for most of them) at the core of the system (kernel) and then do not operate at a low level: except for specialized registry products (RegRun, RegDefend, Principal antivirus)<a href="http://kareldjag.over-blog.com/article-1841115.htmlhttp://kareldjag.over-blog.com/article-1693696.htmlAN OVERVIEW OF PERSONAL DESKTOP/HOST IPS2007-09-17T17:55:22Z2006-02-12T00:43:00ZKareldjaghttp://www.over-blog.com/profil/blogueur-348295.htmlAN OVERVIEW OF PERSONAL DESKTOP/HOST INTRUSION PREVENTION SYSTEMS We have seen previously that a line defense with only a firewall and an antivirus is not enough in consideration of the evolution of threats.Products are available to palliate scanners weaknesses and to combat malwares by their behaviour.Theses<a href="http://kareldjag.over-blog.com/article-1693696.htmlhttp://kareldjag.over-blog.com/article-1649851.htmlWHY YOU SHOULDN'T RUN ONLY WITH AN ANTIVIRUS + FIREWALL AND WHY A PROACTIVE PROTECTION IS NECESSARY2007-09-17T17:55:21Z2006-01-25T00:00:00ZKareldjaghttp://www.over-blog.com/profil/blogueur-348295.html<img src="http://idata.over-blog.com/0/03/91/26/repertoire1/keylog.jpg" />In this first article we’ll just show that the couple scanner
(antivirus/antitrojan/antispyware) + Firewall is not sufficient to mitigate security
risks for home users.
Then we'll review and list available Desktop/Host<a href="http://kareldjag.over-blog.com/article-1649851.htmlhttp://kareldjag.over-blog.com/article-1482539.htmlADVANCED INTEGRITY CHECKERS2007-09-17T17:55:21Z2006-01-13T00:22:00Zkareldjaghttp://www.over-blog.com/profil/blogueur-348295.html<img src="http://idata.over-blog.com/0/03/91/26/septembre/sentinel.jpg" />In a previous article, we've reviewed some free integrity checkers.On this article, we'll focus in advanced ones (paid for most of them).Integrity checking for change detection is an important feature for security softwares, especially in<a href="http://kareldjag.over-blog.com/article-1482539.htmlhttp://kareldjag.over-blog.com/article-1148950.htmlABUSE SHIELD2007-09-17T17:55:18Z2006-01-12T00:00:00Zkareldjaghttp://www.over-blog.com/profil/blogueur-348295.html<img src="http://idata.over-blog.com/0/03/91/26/septembre/testdiv2/absettings.jpg" /> AbuseShield" Globesoft AbuseShield" is a comprehensive tool for monitoring and controlling your desktop or server environments so that only the software you specify can run.AbuseShield also monitor file system activities.This means that even if you, by misstake, allow a mallicious program to run, you can still see<a href="http://kareldjag.over-blog.com/article-1148950.html