Jump to content

rugk

Most Valued Members
  • Posts

    1,716
  • Joined

  • Last visited

  • Days Won

    54

Posts posted by rugk

  1. Where do you find these preset policies in ESET?

    To revert any changes of the settings and use the default settings - which are already optimized with "maximum security" (at least in a way that it says this on the home screen), you can reset your settings in the bottom right corner in the settings).

    But there are no "settings packs" from which you could choose. So e.g. you can't choose "apply settings for balanced security" or "apply settings for lowest security".

     

    However what the settings for "maximum security" are is difficult to say. It strongly depends on much the user wants to get messages from ESS.

    But basically I would also agree with Marcos that ESET LiveGrid is an important thing which should be activated.

     

    Then there are some settings which aren't activated by default, because of bigger or smaller (even very small ;)) disadvantages they have. So read ion the in-product or in the ESET KB help about this and decide by yourself whether you want to activate this:

     
    At the end you may consider to use the HIPS interactive mode. But as this will most likely cause many (too many) messages, you'd better use the smart mode, which only monitors suspicious items. And you can also choose a firewall mode, like the interactive mode, which fits to you.

    But one note about the last two settings: Use them only when you have a basically knowledge about computers and Windows. If you enable them you will get questions from ESS asking you whether you want to allow some things. If you don't want this or already now that you wouldn't be able to answer this questions, let them as they are (on automatic mode) - this way you won't be "annoyed" by ESET.

  2. Okay, for case 1 it may be useful, but case 2 would be a "misuse" of ESET Anti-Theft. Because it's ESET Anti-Theft is - like the name says - an Anti-Theft service and not a "show me where he/she/it-is"-service. I think for locating by a friend or so you can also use other apps.

     

    BTW I'm not fully sure but I think that the device isn't blocked if you use the SMS commands (e.g. eset find).

  3. @Marcos

    But why are you writing this in this topic... :wacko:

    If I'm right the issue you're talking about was an issue about this was an issue about video stuttering or something similar. Unfortunately I cannot find the original topic now.

     

    However I can imagine to what you are referring...

    [they] often cite Eset's performance as being an issue

     

    No, no, I think he doesn't mean "they say ESET has performance issues"1, but "ESET has a good performance - that's an issue". Maybe they explain this in such disputable ways as "they scan very fast, so they scan cursorily..." - or maybe they say other reasons - but this doesn't matter now.

    Fact is that nobody talked about any performance issues in this topic. This topic is about a file detection (issue).

     

    1 And even this wouldn't mean they they talk about network performance issues. Performance issues could be... anything - okay, maybe not anything, but at least very different, because many things can "perform" more or less well...

  4. Now I found the thread: Forum specific: Mixed content

    You can also see that the source of this issues are the Twitter pictures, because not on every forum site appears this issue.

     

    So this issue is already known some months. @Marcos said they "have been considering possible solutions".

    But I never would have thought that this "solution" would be to remove the SSL/TLS encryption...

    The best, simplest (and maybe the only) solution is to adjust the Twitter integration in a way that it doesn't call hxxp://twimg.com/..., but https://twimg.com/...!

     

    And BTW if we're already talking about the TLS/SSL security of this forum, then please use SHA-2 for your next certificate and deactivate SSL v3. It would also be a nice idea to activate the support for TLS v 1.2.

  5. Not directly links but things included.

    I think I already reported this issue with mixed content. And I think the reason was mostly because of Twitter profile pictures from users who linked there account to Twitter.

    Why do you want to remove HTTPS support? That's strange. If you already have it and already have to pay for the certificate just leave it there.

  6. Look at all those test winning AV's picking up this unwanted file..

    Well... there are also many AVs which doesn't "pick it up". Also "test winning" is very much expansible and doesn't say many things...

    Additionally you don't know how virustotal tests the files. E.g. it's also interesting that OpenCandy is detected with ESET on virustotal, because the default settings for ESETs products is not to detect potentially unsafe applications.

    The same way it is of course also possible that a AV vendor listed there which isn't listed as detecting OpenCandy can - in a real usage - detect OpenCandy. That's one reason why VirusTotal shouldn't be used for things like AV comparison, like themselves say.

  7. Is there a PUA in that one as well ?  I have no idea what file that is.

    Well... this may also be a PUA. As uploaded.net is free to use they can make it similar like file-upload.net, which I used for some files recently...

    They added a download manager for these files which ESET blocked. This was the reason why I changed my links and use another file hoster now for the "alternative download links" I used somewhere.

     

    So, @str8arrow, does this happen with every file from uploaded.net? And can you provide us with an example link to a download please? (Or at least a screenshot of the message you get from ESS...)

  8. @SweX

    It's not "clean" and it's no FP. It's just a PUA...

    So all explanation why it is detected are already in this thread.

     

    What did the notifications say at the moment the download was terminated, what was it detected like ?

    You can simply reproduce it. Download FileMenuTools from the creator site (Lopesoft). Then you will see this message:

    post-3952-0-55313000-1425396930_thumb.png

     

    But note that...

    1. there is a "No action" button.
    2. the detection can simply be deactivated. (I feel like I already linked hundred times in this topic to this article...)
    3. and there are other nice ways to get around OpenCandy.
  9. @yongsua

    Yes that's the same which Marcos also said. And as you see ESS blocks it too.

    @str4arrow @Marcos

    Attention: It is detected as a potentially unsafe application. Usually we say PUA only for a potentially unwanted application. This are two different categories (and settings in ESS).

    More information about OpenCandy and some tips how to block it, while still installung the (wanted) software you can get here: https://forum.eset.com/topic/3701-block-pua-inside-installers-from-nero-burning-rom-orbit-downloader-imgburn-dvdvideosoft-install-them-without-opencandy/

  10. Great that it worked nicely for you. :)

    As an input file all text files are working great. Just use .txt or .lst. (normally .lst only means list and the content is a text file anyway...)

     

    And you could have leaved the headings there. All lines beginning with usual characters, which indicate comments, are ignored.

     

    I am assuming that being set to "off" implies that I would not see any breaches in a log file.

    Yes that's right. The log option is just the same option as you can see in the rules list later. By default it is disabled (in most predefined rules too). If it would be enabled then you could see the entries in "Tools → Logs → Personal Firewall".

     

    I guess I could always take one of the IPs and enter it into the browser to see what happens.

    Of course you can. However in your current configuration you won't get any notification (or log entry) if an application is connecting to these IPs.

     

    If any, I will first delete the existing rule in Smart Security and then run the updated list through the tool and reimport.

    Yes, that's the only possible way. Otherwise you would have two rules in ESS...

  11. Thank you very much for taking the time to test this on your own. How long did your test run?

    Surely 3 days... :D

    No seriously, if NOD32 would have such an option then it would surely be below 30 seconds and I think it would also be configurable.

     

    As both isn't the case I think there isn't such an option. But as a future suggestion this would be a neat idea.

     

    I thought ESET would have data available from their own development tests. Is this forum the proper place to ask for that type of data? If not here, do you know where I should ask?

    Well... there are many forum members (mods and "staff members") from ESET here - some are from ESET Slovakia, some from ESET NA and also a few from other countries.

    But as ESET is a huge company, nobody knows everything. Especially if this is such a detailed question like you asked.

    So maybe there are other forum members which can answer your question more certainly, but Marcos test is also a way to find the answer out... :D

×
×
  • Create New...