Tilted Forum Project Discussion Community

Tilted Forum Project Discussion Community (https://thetfp.com/tfp/)
-   Tilted Technology (https://thetfp.com/tfp/tilted-technology/)
-   -   Firewalls and Viruses (https://thetfp.com/tfp/tilted-technology/62692-firewalls-viruses.html)

trache 07-16-2004 07:56 AM

Firewalls and Viruses
 
I'm a Network Administrator.

I've had it up to here *points past head* with viruses. I don't know why I hadn't thought of this before, and why large software companies haven't thought of this (yet?) either, but here it goes:

Considering that most viruses of this generation have an internal list of processes to kill (anti-virus or firewall programs), would it be an effective use of my time to try to rename my firewall and/or anti-virus program filenames?

What would I have to consider? The Windows registry, any configuration files (I suppose)? Would anyone have any idea if doing this would harm an installation of the software (ie, do any of the software programs reference a constant filename?) Does anyone have any experience doing this?

What if the large software companies that build these programs modified their build process so that during the installation all the references could be changed to reflect the new, randomly chosen filename?

hrdwareguy 07-16-2004 08:48 AM

Theoretically, you should be able to do that. However here are some problems.

Lets say you have an executable that you change the name of...no problem. Then that executable spawns another process. You can not change the name of this process.

Also, if that executable calls another executable, that name can not be changed either or the file won't run.

JohnnyRoyale 07-16-2004 01:19 PM

Renaming processes might work, but in the long run, it'd probably cause more problems than it would solve. If you're a network administrator, I'm guessing you have user's workstations to look after, and that's where the virii are coning in? You might want to look into limiting what your users can and can't do, via blacklists, policy files(for windows), proxy servers, and limiting permissions. In a network, you can setup all of these without worrying so much about programs not working.

zero2 07-16-2004 02:02 PM

Just to add, to what JohnnyRoyale above has said, 80 to 90% of the time viruses are coming from the outside.

Each security measure has a flaw. As I found out yesterday.

Antiviruses are only as good as the latest update. Any virus past that update, as well as new viruses pretty much renders your antivirus software useless.

Firewalls, can't prevent viruses, worms, or trojans from working their way through your network. If someone downloads a virus, trojan, or worm guess what, your firewall isn't going to save your @ss.

I think the solution, to most of the virus problems is that more time needs to be spent on education. If you give someone an idea what to look for and what to avoid, im pretty sure that you will spend less time dealing with viruses.

Also another thing that researchers are beginning to say is, "use another alternative to internet explorer". Mozilla, Opera, Avant, are all exceptional browsers.

Also another deathtrap is, Outlook Express, a great number of viruses are email viruses. Educate your users, to take precaution before opening attachments. In fact if possible avoid using outlook, instead use a web mail service, and let the mail service deal w/ the viruses.

Tell them also to avoid attachments w/ filenames w/ the following extensions, .exe, .vbs, .com

Another thing is if they bring work from an outside source, on a cd, usb drive, flash media, they should do a virus scan, before they bring it in.

hrdwrjnkie 07-16-2004 02:07 PM

Speaking from experience, renaming those executables is generallly a bad idea unless they are a single-executable program. Proggies like Norton and ZA or Black Ice will launch new processes that will still be named the same, and virii can still kill them.

Personally, I'm a fan of DeepFreeze. My users all have a shared server folder that all of their data is sotred in, and every workstation reverts to a prostine state when rebooted. Now instead of recovering a machine, I just have a user save their work and reboot.

trache 07-19-2004 07:19 AM

....
 
My point to having them renamed though is that when the viruses go through their internal list to kill a certain process, they'll skip over the running firewall/anti-virus executable because it is renamed.

In theory, any good program that references itself through its filename should in theory be able to store its running filename in memory (which may or may not be a bad thing) and pass it to whoever needs it.

Although I don't know if that function exists in (this example) the Windows APIs.

Slavakion 07-19-2004 07:57 AM

I see what you're saying. But what exactly do you want the filename to end up as? Say the firewall was called firewall.exe
Do you want it to be

1) firewall8.exe (prefix/suffix)
2) f1r3wall.exe (simple substitution)
3) happy.exe (completely different)
4) sgfsdyfg.exe (just random shit)

For any of them, the average user could look at their processes and not know what any of them are (less than usual) because instead of firewall.exe you have f1r3wall.exe(main), fyrewall5.exe(support), fir3wall3.exe(virus), fsdfsggsd.exe(nobody knows)

But, whatever. I see what you're saying, and it's not a bad idea


All times are GMT -8. The time now is 06:14 AM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360