Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
@Andy Ful, Most malware DLLs drop in Temp/AppData, while legitimate DLLs stay in System32/Program Files. Is it correct?
Would this method be useful against DLL hijacking? (If it functions properly in Comodo)
File Groups and Paths
Trusted DLLs Locations
C:\Windows\System32\*.dll
C:\Program Files*\*.dll
C:\Program Files (x86)\*.dll
Untrusted DLLs Policy
*.dll
Auto-Containment Rules
Ignore > File Group > Trusted DLLs Locations
Run Virtually > File Group > Untrusted DLLs Policy
malwaretips.com
I attempted to run the portable version of HDSentinel Pro from my PortableApps directory (C:\PortableApps), a program already on my system and in the Comodo whitelist. Comodo contained "detect.dl," a file listed in the Comodo File List as trusted. This method appears functional and could be useful for mitigating DLL hijacking, assuming minimal impact on usability.
You'll definitely enhance and complete it, I'm sure.This suggests that it works, although the whitelist looks too simplistic.![]()
You'll definitely enhance and complete it, I'm sure.![]()
Yes, Windows PowerShell.Can you run PowerShell console with those restrictions?
The "untrusted policy" prevents/virtualizes DLL execution from non-whitelisted locations. We can either expand the whitelist or use high-risk locations (remove *.dll) for the untrusted policy.Not soon. Currently, I do not use/test Comodo.
The DLL block rule (*.dll) looks very strong (can block Trusted DLLs), and many system DLLs are outside your whitelist. The usability of such restrictions will depend on the Comodo Profile and user whitelist. Depending on the Comodo Profile, different system and non-system locations can be whitelisted for DLLs.
You should copy the folder with HDSentinel to some other locations and check if the rules work as intended:
If the DLLs are blocked in those locations, almost all application installations/updates will fail.
- C:\ProgramData\
- C:\Users\*\AppData\Local\
- C:\Users\*\AppData\Local\Temp\
- C:\Users\*\AppData\Roaming\
I am not sure about Windows Updates.
I am not sure if the block rule is overridden for signed DLLs by whitelisting the vendor.
Yes, Windows PowerShell.
The "untrusted policy" prevents/virtualizes DLL execution from non-whitelisted locations. We can either expand the whitelist or use high-risk locations (remove *.dll) for the untrusted policy.
I'm also not sure about Windows updates, but checking for them works.
I only tried the stated containment rules to see if they work.
How about these locations for the whitelist?The crucial thing is the ability to override the general block DLL rule by the Trusted Vendors List. Otherwise, the general block DLL rule will be hard to manage in practice.
How about these locations for the whitelist?
C:\ProgramData\*
C:\Users\rashmi\AppData\Local\*
C:\Users\rashmi\AppData\Roaming\*
C:\Windows\Installer\*
C:\Windows\Temp\*
Oh yes, I can use your WHHLight whitelist for security and usability, right?It should be OK (I use similar whitelisted locations in the WHHLight WDAC and Hard_Configurator).
Oh yes, I can use your WHHLight whitelist for security and usability, right?
I won't just copy the WHHLight whitelist, but it's an excellent place to start.I am not sure how those rules can impact the Comodo Script Analysis settings (script, scriplet restrictions). But, there are high chances that the scripts and scriptlets will still be blocked. In WHHLight, the problem is solved by using different security layers for PE files and others.
Oh yes, I can use your WHHLight whitelist for security and usability, right?
Members who viewed this thread in the last 5 minutes