Simplewall - A tool to configure Windows Filtering Platform

Discussion in 'Other Security for Windows' started by Mr.X, Aug 23, 2017.

  1. SHvFl

    SHvFl Level 32
    Content Creator Trusted

    Nov 19, 2014
    2,153
    16,410
    Supermodel for McDonald's
    Europe
    Windows 10
    Emsisoft
    I will test on vm later. Can't do it on main machine because they break completely and i need to reset all store apps forcing me to have to remove the useless again and again. I already did it 3 times with same results to see that it was 100% simplewall.
     
    given, Sunshine-boy, Weebarra and 3 others like this.
  2. Deletedmessiah

    Deletedmessiah Level 15

    Jan 16, 2017
    716
    6,588
    SSD
    Windows 8.1
    Emsisoft
    I went back and forth between simplewall 2.0.16 and 1.6.5 like 7-8 times so definitely understand.
     
  3. henrypp

    henrypp Level 1

    Aug 24, 2017
    23
    117
    Nowhere
    simplewall and Windows Firewall works different.
    - Windows Firewall have low-level driver callback which freeze connection until you are decide what you do with him (allow/block).
    - simplewall have user-mode level and no drivers installs and cannot freeze connections for wait your decision.

    Thats why simplewall do not remove notifications cache. New version comes with some patches on this logic, but notifications still on cache until you do not do anythig with blocked application.

    Are "Allow listen connections for all" is checked? "Stealth mode" enabled? You see logs? Whats applicaions blocked? Do you checked this apps?
    In near future i will pass some tests with Windows Store and create "System rule" which allows it to working.
     
  4. SHvFl

    SHvFl Level 32
    Content Creator Trusted

    Nov 19, 2014
    2,153
    16,410
    Supermodel for McDonald's
    Europe
    Windows 10
    Emsisoft
    Allow listen connections for all=on
    Stealth mode= off
    All default store apps stop working(don't launch) and you have to reinstall them. Not default store applications work just fine.
     
    given, venustus, Sunshine-boy and 2 others like this.
  5. Mr.X

    Mr.X Level 6

    Aug 2, 2014
    289
    878
    PC Tech
    Mexico
    simplewall v2.0.17 (12 October 2017)
    simplewall
    Download (Installer + portable)
    Changelog
    sha256 checksum
     
    given, rockstarrocks, henrypp and 4 others like this.
  6. Mr.X

    Mr.X Level 6

    Aug 2, 2014
    289
    878
    PC Tech
    Mexico
    given, henrypp, SHvFl and 1 other person like this.
  7. Mr.X

    Mr.X Level 6

    Aug 2, 2014
    289
    878
    PC Tech
    Mexico
    simplewall v2.0.18 (19 October 2017)
    simplewall
    Download
    Changelog
    sha256 checksum
     
    given, rockstarrocks, henrypp and 4 others like this.
  8. Sunshine-boy

    Sunshine-boy Level 22

    Apr 1, 2017
    1,184
    5,226
    IRAN
    Windows 10
    ESET
    @henrypp
    Do you have any plan to sign your tools?I noticed that mem reduct is also not signed.
    What does disable notification mean?does it mean the simple wall will auto allow the connection for the specific process since the user disabled the notification?
     
    given, rockstarrocks, henrypp and 2 others like this.
  9. Deletedmessiah

    Deletedmessiah Level 15

    Jan 16, 2017
    716
    6,588
    SSD
    Windows 8.1
    Emsisoft
    #109 Deletedmessiah, Oct 23, 2017
    Last edited: Oct 23, 2017
    Signing the software is quite costly from what I know so probably not unless he gets a lot of donations.
    It depends on the settings, if set to deny connections by default, the connection will be blocked and you won't be notified when you disable notification.
     
    given, rockstarrocks, henrypp and 3 others like this.
  10. Sunshine-boy

    Sunshine-boy Level 22

    Apr 1, 2017
    1,184
    5,226
    IRAN
    Windows 10
    ESET
    Ye, I just tried it for 2 days and saw that deny by default.
    How SW decide to allow or block by default?
     
  11. Deletedmessiah

    Deletedmessiah Level 15

    Jan 16, 2017
    716
    6,588
    SSD
    Windows 8.1
    Emsisoft
    There's two working modes, black list and white list. If you select white list mode, every process will be blocked until you allow it.
     
  12. Sunshine-boy

    Sunshine-boy Level 22

    Apr 1, 2017
    1,184
    5,226
    IRAN
    Windows 10
    ESET
    Thanks for your explanation mate :) So my choice would be whitelisting mode.
    Good to see all of his tools has almost +4 score in Softpedia! wtf hacker:D
     
    given, rockstarrocks, henrypp and 3 others like this.
  13. Mr.X

    Mr.X Level 6

    Aug 2, 2014
    289
    878
    PC Tech
    Mexico
    #113 Mr.X, Oct 29, 2017
    Last edited: Oct 29, 2017
    @henrypp

    Lil typo, Ip instead of IP:

    typo.png


    "Find" function doesn't work at all:

    find.png
     
    given, rockstarrocks, henrypp and 2 others like this.
  14. Mr.X

    Mr.X Level 6

    Aug 2, 2014
    289
    878
    PC Tech
    Mexico
    simplewall v2.0.19 (1 November 2017)
    simplewall
    Download
    Changelog
    sha256 checksum
     
    XhenEd, given, rockstarrocks and 3 others like this.
  15. henrypp

    henrypp Level 1

    Aug 24, 2017
    23
    117
    Nowhere
    Authenticode needs money, and i have some money from donations - on blockchain ~50$ and some cash on paypal, if someone tell me where can buy certificate for this cost - i can use this money to buy certificate.
     
  16. Mr.X

    Mr.X Level 6

    Aug 2, 2014
    289
    878
    PC Tech
    Mexico
    LOL, my allowed/blocked apps appeared sorted alphabetically before. Now in version 2.0.19 they're sorted... scrambled?
     
    given, Deletedmessiah and henrypp like this.
  17. henrypp

    henrypp Level 1

    Aug 24, 2017
    23
    117
    Nowhere
    OH SHI~ Overlooked.
     
    given, rockstarrocks and Mr.X like this.
  18. Lockdown

    Lockdown From AppGuard
    Developer

    Oct 24, 2016
    2,712
    11,877
    AppGuard LLC Virginia, U.S.
    Duplicate alerts for programs that are already allowed needs to be fixed. It is a definite a bug. The solution is not to disable alerts for such programs. No firewall alert system works that way except for Simplewall.
     
    given, Opcode and Sunshine-boy like this.
  19. Mr.X

    Mr.X Level 6

    Aug 2, 2014
    289
    878
    PC Tech
    Mexico
    Haven't seen this, iirc. What scenario you have, for me to replicate this bug?
     
    given, rockstarrocks and Sunshine-boy like this.
  20. Lockdown

    Lockdown From AppGuard
    Developer

    Oct 24, 2016
    2,712
    11,877
    AppGuard LLC Virginia, U.S.
    svchost.exe is a just one example; henrypp doesn't consider multiple, duplicate alerts even though an allowed rule already exist for it a bug - the "workaround" is just to disable notifications for svchost.exe

    Just install and use Simplewall

    This issue has been reported since the very first version by many people
     
    given and Opcode like this.
Loading...