Serious Discussion Quick Play with McAfee

McAfee
262 Replies 47,080 Views
Why does McAfee allow a site that it has already flagged and blocked to download files in the first place? Doesn’t that kind of defeat the entire purpose of having web protection? Yes, I understand that McAfee will supposedly “block” the file afterward, but allowing a file to be downloaded from a site that its own web protection has already identified as malicious seems completely backwards.

If your web protection is confident enough to say, “This site is unsafe don’t go there,” then why is it perfectly happy to let that same site download a file onto my computer? Maybe I’m missing something, but having one security feature flag a site as dangerous while another feature essentially says, “Sure, go ahead and download the file anyway; we’ll worry about it afterward,” is a pretty confusing security model.

If the site is considered malicious, block the download at the source. That seems like a fairly basic expectation from a security product. Otherwise, what exactly is the point of blocking the site in the first place?
 
When McAfee WebAdvisor blocks a site as dangerous, it displays a warning page. If the user clicks the ‘Proceed anyway’ (or ‘Proceed to site’) button on this warning page, the add-on treats this as a conscious decision by the user. As a result of this action, the domain is added to the Whitelist: the add-on removes that domain from the blocked list and adds it to the local whitelist / trusted list; as the connection between the web browser and the site is no longer blocked, the site loads like any other web page and any automatic download scripts on the site may be triggered. I suspect this is where the problem lies.Why does McAfee allow a site that it has already flagged and blocked to download files in the first place? Doesn’t that kind of defeat the entire purpose of having web protection? Yes, I understand that McAfee will supposedly “block” the file afterward, but allowing a file to be downloaded from a site that its own web protection has already identified as malicious seems completely backwards.

If your web protection is confident enough to say, “This site is unsafe don’t go there,” then why is it perfectly happy to let that same site download a file onto my computer? Maybe I’m missing something, but having one security feature flag a site as dangerous while another feature essentially says, “Sure, go ahead and download the file anyway; we’ll worry about it afterward,” is a pretty confusing security model.

If the site is considered malicious, block the download at the source. That seems like a fairly basic expectation from a security product. Otherwise, what exactly is the point of blocking the site in the first place?
When McAfee WebAdvisor blocks a site as dangerous, it displays a warning page. If the user clicks the "Proceed anyway" button on this page, the extension interprets this as an intentional user decision. As a result, the domain is added to the exception list (whitelist): the extension removes the domain from the blocked list and adds it to the local exception/trusted list. Since the connection between the web browser and the site is no longer blocked, the site loads normally, and automatic download scripts on the site may be triggered. I believe the issue stems from this.
 
1791558108622.png

Version: 16.1.1.109 released. I created a script to make it easy to use McAfee's new interface and create a shortcut on the desktop.

@echo off
chcp 65001 > nul
setlocal enabledelayedexpansion

echo ============================================
echo Starting McAfee Automatic Launcher Setup...
echo ============================================

REM 1. Create Directory
set "TARGET_DIR=%LOCALAPPDATA%\McAfeeLauncher"
if not exist "%TARGET_DIR%" (
mkdir "%TARGET_DIR%"
echo [+] McAfeeLauncher folder created: %TARGET_DIR%
) else (
echo [*] McAfeeLauncher folder already exists.
)

REM 2. Create StartMcUI.ps1
set "PS_FILE=%TARGET_DIR%\StartMcUI.ps1"
echo [+] Creating StartMcUI.ps1...

(
echo # McAfee dynamically finds the latest version
echo $baseWps = "C:\Program Files\McAfee\wps"
echo $lnkPath = [Environment]::GetFolderPath("Desktop"^) + "\McAfee.lnk"
echo.
echo $versionFolders = Get-ChildItem $baseWps -Directory -ErrorAction SilentlyContinue ^| Where-Object {$_.Name -match '^\d+\.\d+\.\d+\.\d+'}
echo $useMcUi = $false
echo $exePath = ""
echo.
echo if ($versionFolders^) {
echo $latest = $versionFolders ^| Sort-Object {[version]$_.Name} -Descending ^| Select-Object -First 1
echo $mcui = Join-Path $latest.FullName "ui\mc-ui.exe"
echo if (Test-Path $mcui^) {
echo $exePath = $mcui
echo $useMcUi = $true
echo }
echo }
echo.
echo if(-not $useMcUi^){
echo $exePath = Join-Path $baseWps "mc-launch.exe"
echo }
echo.
echo $WshShell = New-Object -comObject WScript.Shell
echo $Shortcut = $WshShell.CreateShortcut($lnkPath^)
echo $Shortcut.IconLocation = "$exePath, 0"
echo $Shortcut.Save(^)
echo.
echo Start-Process $exePath -ArgumentList "/source:desktop_shortcut"
) > "%PS_FILE%"

REM 3. Create StartMcAfee.vbs
set "VBS_FILE=%TARGET_DIR%\StartMcAfee.vbs"
echo [+] Creating StartMcAfee.vbs...

(
echo Set sh = CreateObject("WScript.Shell"^)
echo Dim psPath
echo psPath = CreateObject("WScript.Shell"^).ExpandEnvironmentStrings("%%LOCALAPPDATA%%\McAfeeLauncher\StartMcUI.ps1"^)
echo sh.Run "powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -File """ ^& psPath ^& """",0
) > "%VBS_FILE%"

echo ============================================
echo [SUCCESS] All files created successfully!
echo ============================================
echo Now, all you need to do is:
echo Right-click the McAfee shortcut on your desktop, go to Properties,
echo and paste the following path into the Target field:
echo %LOCALAPPDATA%\McAfeeLauncher\StartMcAfee.vbs
echo ============================================
pause
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top