The New ReHIPS Is Out

Lenny_Fox

Level 22
Verified
Top Poster
Well-known
Oct 1, 2019
1,120
One important change for writing rules more easily: added wildcard ** support (y)

One very annoying user interface issue still exists. When you enter a program in two groups it simply tells tou that a rule for that program already exists, WITHOUT TELLING YOU WHERE THAT RULE IS. You have search the user and system and user unbound groups for that program (n)(n)(n)
 
Last edited:

Lenny_Fox

Level 22
Verified
Top Poster
Well-known
Oct 1, 2019
1,120
Okay gave it a spin, running it in permissive mode (default allow unless rules are defined). User interface is quirky. To add a group I had to make a unbound program isolated. Only when you make a program isolated it is possible to assign a group name. When you change the leader program in that group to allow (in stead of allow isolated), the group remains. Next add the additional programs in that group (which you have to delete when they are specified in some other group). The list below shows which groups I have added/changed.


1624892400961.png

In the free version only up to 10 monitored (isolated?) programs are allowed, which is just enough to run Firefox isolated. I have further tightend by using a user.js and setting uBlock in easy medium mode (link) using Kees1958 setup and blocklist and my own blocklists :).

1624892608929.png
 
Last edited by a moderator:

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Okay gave it a spin, running it in permissive mode (default allow unless rules are defined). User interface is quirky. To add a group I had to make a unbound program isolated. Only when you make a program isolated it is possible to assign a group name. When you change the leader program in that group to allow (in stead of allow isolated), the group remains. Next add the additional programs in that group (which you have to delete when they are specified in some other group). The list below shows which groups I have added/changed.


View attachment 259373

In the free version only up to 10 monitored (isolated?) programs are allowed, which is just enough to run Firefox isolated. I have further tightend by using a user.js and setting uBlock in easy medium mode (link) using Kees1958 setup and blocklist and my own blocklists :).

View attachment 259374
Comments and suggestions will be most effective if you make them on the ReHIPS forum

There are free licenses available for use in VM, if you are interested. If you can't find them on the forum, PM me.
 

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Hello shmu26 ,the freee licenses are for VM only?THks
Correct. The licenses won't work on a real system, only in VirtualBox or VMware.
There is a free demo license that is granted automatically whenever you install ReHIPS on any system. The only limitation, as mentioned by @Lenny_Fox , is the number of isolated processes that you can run in a given session. Otherwise, it is fully functional.
If you don't feel the need to isolate your multi-process browser, you probably can use the demo license without feeling the limitation at all.
 
Last edited:

Lenny_Fox

Level 22
Verified
Top Poster
Well-known
Oct 1, 2019
1,120
@shmu26

Thanks for the offer, but the HIPS does allow to restrict data access on group level and execution access on program level (with option to allow on vendor signatures when you choose inspect).

The HIPS offers sufficient flexibility, I only use the sandbox mode for Firefox which feels like using it unrestricted.
 

Zartarra

Level 7
Verified
Well-known
May 9, 2019
349
Anyone testing RC1 in here? I had some issues with it. So I tried to disabled the service and got a nice blue screen. I tried to uninstalled it and again blue screen. I could only uninstalled it through safe mode. Installed back version 2.4.0 and I got no issues with the same config.
 
  • Like
Reactions: oldschool

shmu26

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Anyone testing RC1 in here? I had some issues with it. So I tried to disabled the service and got a nice blue screen. I tried to uninstalled it and again blue screen. I could only uninstalled it through safe mode. Installed back version 2.4.0 and I got no issues with the same config.
What OS? I was unable to install it on Windows 7, and I did not have the issue you mentioned on Windows 10.
By the way, the best way to get support for ReHIPS is on the ReHIPS forum.
 
  • Like
Reactions: oldschool

Zartarra

Level 7
Verified
Well-known
May 9, 2019
349
What OS? I was unable to install it on Windows 7, and I did not have the issue you mentioned on Windows 10.
By the way, the best way to get support for ReHIPS is on the ReHIPS forum.
I use W10 21H1. I am going to test in further on a VM to see if i get the same issue. Also it is easier to take screenshots ;).
 
  • Like
Reactions: ng4ever and shmu26

Zartarra

Level 7
Verified
Well-known
May 9, 2019
349
The issue is "resolved". I enabled a Windows policies to mitigate certain processess. When the policy is not configured, Rehips services are running fine.
 
  • Like
Reactions: shmu26

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top