VoodooShield discussion

Status
Not open for further replies.

gorblimey

Level 2
Verified
Aug 30, 2017
99
I am not a web security expert,

Nor am I. But the difference between "web" security and "app" security is that one makes it easier to do things safely, the other makes it harder to do things. Completely unintuitive, yes. But locking "app" security down too tightly makes it impossible to do anything at all, while locking "web" security down too tightly is almost impossible but will allow people to so much more easily do things safely. The best example on "web" security is encryption: some lazy or otherwise challenged web hosts don't allow secure renegotiation of encryption protocols, which means that this renegotiation must be done without a rainjacket as it were. Good secure browsers will expose a method of forcing that requirement on a web server and throwing an "exception" if it's not present: essentially blocking an unsafe site. Bad browsers let the test fail silently...

"Web" security is all about following the current standards, there are no standards for "app" security.

:)
 

madirish

Level 1
Sep 13, 2017
14
Un-installed 4.0.6b rebooted and installed 4.0.7b,registered rebooted and everything running good (browsers,e-mail,VLC Player,Sandboxie).Great job danb-well done !:)
 
  • Like
Reactions: VecchioScarpone

boredog

Level 9
Verified
Jul 5, 2016
416
Hmmm, this means that for some reason VS cannot communicate with the internet. Do you have a firewall that is blocking VS? What happens if you try to execute a non-whitelisted file when this happens? Do you get the same message? Thank you!

Firewall off , All other security software off except for Windows Defender. Get same message when clicking on non whitelisted file. Only thing that has changed is a newer build of Windows Insider.
 

Attachments

  • ScreenHunter_88 Oct. 12 12.05.jpg
    ScreenHunter_88 Oct. 12 12.05.jpg
    37 KB · Views: 359

silfmus

Level 1
Oct 11, 2017
6
VoodooShield v4.07b.
Tried to install VS with all security applications disabled. The installer stops working and shows a error window: https://i.imgur.com/qKvjuWI.png
If I try to close the installer, it somehow finishes the installation and the usual registration and welcome screen appears: https://i.imgur.com/ChuG9L2.png
I thought it was a incompatibility with Bitdefender Free, as reported by users here, but now I don't think so.

It's not a bug, but the only way to remove this shield icon when playing videos is paying, right? https://i.imgur.com/PmA6tde.jpg
VS is pretty expensive here (Brazil). As it is a international purchase (with taxes), one must pay ~R$76 for a 1 year license. To compare with popular products, Kaspersky AV 2017 costs R$19 and Kaspersky IS 2017, R$44 (1 year license to both).
Do you have plans to have official resellers here and in other countries as well?
 
  • Like
Reactions: vtqhtr413

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Here is VS 4.07b. All of the command line issues should be completely fixed.

I think we are getting close, but if I have overlooked a bug that one of you guys posted on here, please let me know, thank you!

www.voodooshield.co/Download/InstallVoodooShield407beta.exe
I did a clean install, it works impressively well, even with the infamous HP officejet printer.
During installation I got an error message that the installation failed (all other security softs were disabled) but immediately afterward, VS started up. As far as I can tell, it is behaving normally. I get the right alert windows, it learned a command line, etc.

If there is something I can do to test it, to make sure the installation is up to snuff, please tell me what to do.
 

Gandalf_The_Grey

Level 76
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,624
Here is VS 4.07b. All of the command line issues should be completely fixed.

I think we are getting close, but if I have overlooked a bug that one of you guys posted on here, please let me know, thank you!

www.voodooshield.co/Download/InstallVoodooShield407beta.exe
Did a clean install of the new version and it seems that the regional issues are resolved (y)
I had only 1 error in the beginning after VS was just installed:
[10-12-2017 18:47:12] [INFO ] - Snapshot taken
[10-12-2017 18:47:12] [DEBUG] - DriverCommunicationService::Connect 10 threads
[10-12-2017 18:47:12] [DEBUG] - ->DriverCommunication.ctor
[10-12-2017 18:47:12] [DEBUG] - DriverCommunicationService::Enter main loop
[10-12-2017 18:48:17] [DEBUG] - DriverCommunicationService::Client disconnected
[10-12-2017 18:48:17] [DEBUG] - DriverCommunicationService::Disconnect
[10-12-2017 18:48:17] [DEBUG] - DriverCommunicationService::Exit main loop
[10-12-2017 18:48:17] [ERROR] - Wait For response error 0x00000000
[10-12-2017 18:48:17] [DEBUG] - DriverCommunicationService::Disconnected
[10-12-2017 18:48:17] [INFO ] - VoodooShieldService.OnSessionChange: SessionLogoff
[10-12-2017 18:48:30] [INFO ] - User Log Initialized
[10-12-2017 18:48:30] [INFO ] - Snapshot file Initialized
[10-12-2017 18:48:30] [INFO ] - Service started
[10-12-2017 18:48:30] [INFO ] - Driver communication service started
[10-12-2017 18:48:32] [INFO ] - VoodooShieldService.OnSessionChange: SessionLogon
[10-12-2017 18:48:39] [DEBUG] - DriverCommunicationService::Connect 10 threads
[10-12-2017 18:48:39] [DEBUG] - ->DriverCommunication.ctor
[10-12-2017 18:48:39] [DEBUG] - DriverCommunicationService::Enter main loop
 

codswollip

Level 23
Content Creator
Well-known
Jan 29, 2017
1,201
This is why in your last Chrome example from above... Windows Explorer will launch 7 zip, and this is because it is whitelisted. But when you have a risky executable web app like Chrome trying to open a child executable, you have to be very careful, otherwise, the end user will end up in tears, as CS would say.
OK (and thanks for schooling me here)... I follow (somewhat) your concern with having Chrome open a child executable. But why is it that when I select "Allow" to permit Chrome to load the zip/pdf/mp4/other file in its associated program (7Zip/Adobe Reader/Potplayer), that the "Allow" is not remembered by the whitelist. As my video demonstrated, I can repeatedly launch/allow the same file from Chrome, and it is accompanied by a notification each time. Just curious.
 

Mr.Gump

Level 1
Sep 6, 2017
11
It is definitely best to leave most of the settings as their default values, and change only what needs to be changed. VS's settings interact with each other, and if you change tons of settings, it is difficult to say what will happen. Then again, you can experiment with it and see what works for you. Thank you!
well i just want a lock on my computer, no scanning and checking foreign lists etc..

also, i see my the shield blinking but see no record of anything blocked in command lines or user log. Is that normal?
 
  • Like
Reactions: shmu26

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
also, i see my the shield blinking but see no record of anything blocked in command lines or user log. Is that normal?
What were you doing at the time? With VS 3, I used to see that behavior sometimes, for instance, when printing a doc. The solution was to put VS in training mode, and then run a print job. If you know you are doing a safe action, use training mode, and VS will probably learn the command line.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
I did a clean install, it works impressively well, even with the infamous HP officejet printer.
For some reason, today it is not playing nicely with my HP printer when I try to send a fax. It throws an alert every time for the command line, and refuses to learn the command line, even in training mode. If I try to make a rule, it only agrees to make a global rule for all files that match certain parameters.
 
  • Like
Reactions: Sunshine-boy

danb

From VoodooShield
Verified
Top Poster
Developer
Well-known
May 31, 2017
1,674
Oops, I recently found and fixed a bug that was probably causing some issues all along, so I wanted to release a new version that fixes this.

Do you guys remember when I was talking about adding the parent process check to VS? I added this check, but did forgot that before VS adds something to the whitelist, it checks to see if the item is in the whitelist or not… but the parent process check was not added to this check. So some items were not added to the whitelist, because VS already whitelisted that item with a different parent process.

Anyway, it is fixed now, sorry about that. FYI, VS does process name, process path, SHA-256 hash and parent process path comparison to check to see if the file is whitelisted or not. I would also add file size, but it can take a while to calculate file sizes for big files, and there are occasions when the file sizes do not match.

www.voodooshield.co/Download/InstallVoodooShield408beta.exe

Thank you guys, have a great weekend!
 

codswollip

Level 23
Content Creator
Well-known
Jan 29, 2017
1,201
I added this check, but did forgot that before VS adds something to the whitelist, it checks to see if the item is in the whitelist or not… but the parent process check was not added to this check. So some items were not added to the whitelist, because VS already whitelisted that item with a different parent process.

Anyway, it is fixed now, sorry about that. FYI, VS does process name, process path, SHA-256 hash and parent process path comparison to check to see if the file is whitelisted or not. I would also add file size, but it can take a while to calculate file sizes for big files, and there are occasions when the file sizes do not match
I don't know if this is related, but Chrome now launches downloaded zip files without complaining. I just downloaded 2 different zips and both came up without a notification. Out of curiosity, I tried an mp4 download, and it too launched without interruption. Guess I'll find out tomorrow if an overnight reboot changed things, but right now this looks good even with many of my installed programs sitting on "D drive". :cool:(y)
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top