On CHOW: How to avoid dirty looks at cafes
BNET Business Network:
BNET
TechRepublic
ZDNet

May 1st, 2006

New security program to prevent exploits -- it works!

Posted by Suzi Turner @ 10:29 pm

Categories: Security and prevention

Tags:

SocketShield is a new security application just launched by Exploit Prevention Labs, founded by two veterans of the anti-malware/anti-spyware business, Bob Bales and Roger Thompson, both former executives of Pest Patrol which was bought by Computer Associates two years ago.

SocketShield is designed to stop exploits and block malware at the gate. Since we’ve seen several zero-day exploits this year already, I think this application can really help prevent the massive trashing of machines as we’ve seen with the WMF exploit and the CreateTextRange exploits that were used and are still being used, in fact.

The program is still in beta and is now available for public download. I downloaded and tested SocketShield Beta tonight on a virtual machine running a totally unpatched version of Windows XP, no service packs. I went to a website known for running exploits. The last time I was there the site was running 3 exploits actually, the WMF exploit, the CreateTextRange exploit and a JavaScript exploit, all of which have been patched by Microsoft. Tonight the site was using "only" one exploit, the CreateTextRange, along with some iframes leading to other malware sites. You can see a screenshot of the first alert of a CreateTextRange exploit from SocketShield here. WARNING — Do Not go to the IP addresses shown in the screenshots using Windows, patched or not, unless you’re in a virtual machine. SocketShield also blocked malicious code in an iframe, as seen below.

expl2.jpg

I went to another site known for exploits and got a few more attempted exploits as shown in the screenshot here. SocketShield did not prevent a couple of adware programs from downloading without notice and consent, however. The machine was still very functional, whereas if I had not been using SocketShield when I went to those sites, I guarantee the machine would have been taken over with malware — trojans, keyloggers and a ton more adware, to the point where it would have been unusable. You can read all the features of SocketShield at the website http://www.socketshield.com. The SocketShield Beta is a free download and the program will be $29 for a one  year subscription when released.

  • Talkback
  • Most Recent of 21 Talkback(s)
RE: New security program to prevent exploits -- it works!
I'm not sure if SocketShield is comparable to McAfee Site Advisor which I have on my machine? I went to Socket Shield Lite for installation inf and opened User Guide but would only load to page 7 256... (Read the rest)
Posted by: donnyboy1@... Posted on: 11/25/08 You are currently: a Guest | | Terms of Use
Yawn  toadlife | 05/02/06
no...  Suzi_z | 05/02/06
Yes, I do know what an exploit is. Do you?  toadlife | 05/02/06
that's right...  Suzi_z | 05/02/06
A link for you  toadlife | 05/02/06
yep  Suzi_z | 05/03/06
tested Avast  Suzi_z | 05/04/06
Thanks Suzi  toadlife | 05/04/06
Did I miss the write up?  muzztobe | 05/07/06
Not quite  zappahey | 05/03/06
ok  Suzi_z | 05/03/06
Diseases spread best...  Anton Philidor | 05/02/06
right  Suzi_z | 05/02/06
to toadlife  Suzi_z | 05/04/06
SocketShield is anti exploit not anti virus  rogert30062 | 05/05/06
HI Roger  toadlife | 05/05/06
question about admin privileges  muzztobe | 05/06/06
answer  toadlife | 05/06/06
Thank you...  muzztobe | 05/07/06
I've been using it for a while  ucsdirect@... | 05/13/06
RE: New security program to prevent exploits -- it works!  donnyboy1@... | 11/25/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline