Advice Request Does Voodooshield protect you more when used rather than just having UAC on and a limited user account?

Please provide comments and solutions that are helpful to the author of this topic.

RoboMan

Level 35
Verified
Top Poster
Content Creator
Well-known
Jun 24, 2016
2,400
>Does VoodooShield protect more than a limited account (say Standard)?
Yes. A Standard User Account is a good security measure, but it's not an bulletproof one. We've seen malware not needing administrator permissions, exploiting vulnerabilities to escalate to admin rights without the user's explicit consent. Remember VoodooShield is a lock for the system, meaning all program's execution (parent and child) will be blocked unless clearly whitelisted, since it uses a blacklist rather than a whitelist to protect you (see differences between blacklist type of software and whitelist type of software (traditional).

>Does VoodooShield protect more than UAC?
Yes. User Access Control must always be enabled, but it is a second line of defense. You should rely on it after you've confirmed the file you're launching is secure. Remember this will not tell you wether the file is malware or safe, it will just prompt you for administrator privileges. UAC can be bypassed, and also malware may not require admin permissions (privilege escalation). The most safe practice is the blacklist protection, meaning nothing at all can run in your system, unless explicitly allowed to.
 

ng4ever

Level 17
Thread author
Verified
Feb 11, 2016
802
>Does VoodooShield protect more than a limited account (say Standard)?
Yes. A Standard User Account is a good security measure, but it's not an bulletproof one. We've seen malware not needing administrator permissions, exploiting vulnerabilities to escalate to admin rights without the user's explicit consent. Remember VoodooShield is a lock for the system, meaning all program's execution (parent and child) will be blocked unless clearly whitelisted, since it uses a blacklist rather than a whitelist to protect you (see differences between blacklist type of software and whitelist type of software (traditional).

>Does VoodooShield protect more than UAC?
Yes. User Access Control must always be enabled, but it is a second line of defense. You should rely on it after you've confirmed the file you're launching is secure. Remember this will not tell you wether the file is malware or safe, it will just prompt you for administrator privileges. UAC can be bypassed, and also malware may not require admin permissions (privilege escalation). The most safe practice is the blacklist protection, meaning nothing at all can run in your system, unless explicitly allowed to.
Thank you.
 
  • Like
Reactions: oldschool

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top