› Forums › VoodooShield Support Forum › VoodooShield Releases › VoodooShield 5.50
- This topic has 952 replies, 34 voices, and was last updated 6 months ago by
Dan.
- Post
-
- November 23, 2019 at 9:37 pm
Hey guys, we are getting very close! Here is the latest version… there are just a few things that I need to finish up, like the new artwork on the How It Works form, and I also need to finish the Windows Firewall feature. It is all ready to go, but I don’t want to actually automatically add rules until we are sure all of the bugs are fixed, because believe me, as many changes as there were in this version, there are most likely be a few small bugs.There are way too many changes under the hood and with the WLC implementation for me to describe, that it is probably best for you guys to just try it and see. A few small things though, I removed the Advanced Snapshot feature for a lot of reasons. First, we really need to get back to our roots and focus on VS’s proprietary tiny, customized whitelist… that really is what VS is all about. The whole goal is to offer the smallest attack surface in the industry. Also, there is no reason to analyze thousands of files with WLC.
Also, brand new whitelists will be automatically generated and scanned with WLC. Again, the whole goal is to keep the whitelist as small as possible. Then again, with WLC and the other features we have implemented the last year or so, unwanted blocks should be pretty much non-existent.
I hope to catch up on the posts here soon… it is great to see you “old guys” 😉.
And yes, I would uninstall the standalone version of WLC now 😉.
Thank you guys, have a great weekend!
VS 5.50 beta
https://voodooshield.com/Download/InstallVoodooShield550beta.exe
SHA-256: bd85bc201c7f70c9677edb89cad73a85d0e3ed55e1f92507e9f4178dee53bdd0VS 5.51 beta
https://voodooshield.com/Download/InstallVoodooShield551beta.exe
SHA-256: e05cb8ac0a89edaade7c3543c4717955c451efb2f953be3874f2bbad8e1cecdbVS 5.52 beta
https://voodooshield.com/Download/InstallVoodooShield552beta.exe
SHA-256: dba4fd21024a2bc2686f5ed4e70f1242b5fd24bf66c5ad0987b4cd4ed56abc48VS 5.53e beta
https://voodooshield.com/Download/InstallVoodooShield553ebeta.exe
SHA-256: 73770b6a1e9d9de5d506e0814fb8c2658b5d9f04c1d6fb572a62bcd046b9d410VS 5.54F beta
https://voodooshield.com/Download/InstallVoodooShield554Fbeta.exe
SHA-256: 68441b9c1cdb871cd0181ead2b6fecd441582fccb6bbd4b3d144e72ec746186dVS 5.54G beta
https://voodooshield.com/Download/InstallVoodooShield554Gbeta.exe
SHA-256: 60efd004a377393d69583abbfefdc7f6c7deef28893df832e9dedbf50e6baba7VS 5.54H beta
https://voodooshield.com/Download/InstallVoodooShield554Hbeta.exe
SHA-256: 9391f87595681e03f37b23f20692b049d303f6e6a11cc2d36291daac6d1d43d5VS 5.54I beta
https://voodooshield.com/Download/InstallVoodooShield554Ibeta.exe
SHA-256: 03c1f22ba2e9d73b96cf6133b4bf9da711bddd73063b7d2ab4859e304ad2c615VS 5.54K beta
https://voodooshield.com/Download/InstallVoodooShield554KBeta.exe
SHA-256: b8c87fae09ebc75ea96c65fa6537643b6e2dad43f41df206ed127edc7a976051VS 5.55
https://voodooshield.com/Download/InstallVoodooShield.exe
SHA-256: 40e42b086f7cc587fd5c31d92fcae22272838dbe285a0f187bb5bd26d417ac2aVS 5.56 beta
https://voodooshield.com/Download/InstallVoodooShield556beta.exe
SHA-256: 7aba5acd48efb2c9343fe5b3c3c43314f3855f623e6969d7d6a617a8766c16c0VS 5.58 beta
https://voodooshield.com/Download/InstallVoodooShield558beta.exe
SHA-256: 38c96247d45a094cf071be91a747ec38e20683707cbd84ccbb962e28a457dd48VS 5.59c
https://voodooshield.com/Download/InstallVoodooShield559c.exe
SHA-256: a2ddd543bbf1dc5226c4e9e224672e2021e8325e3461c11e3c3871b744df0e13VS 5.60 Public Release
https://voodooshield.com/Download/InstallVoodooShield.exe
SHA-256: a08d9ae8c78c9ce9c51bee96ed7ab369eab668e053d80af7f01f86d76792d3cdVS 5.61 beta
https://voodooshield.com/Download/InstallVoodooShield561beta.exe
SHA-256: d8bf406a6ff060a38e727eee3540d07b26dd08851780cd54b460eaf644b053faVS 5.62 beta
https://voodooshield.com/Download/InstallVoodooShield562beta.exe
SHA-256: 19c0be7e18dc80b9a9aa576d9816ef7e5387027dd3d312b7fbbea3ed56a820b5VS 5.63 beta
https://voodooshield.com/Download/InstallVoodooShield563beta.exe
SHA-256: 2261a89dbcd4d843c6b5e925b8b641a8ed8b0b3e82f6ae85b8f33f79439878ecVS 5.64 beta
https://voodooshield.com/Download/InstallVoodooShield564beta.exe
SHA-256: 76efbfb0607892910c2e7da352a9789c1281933683e9818802696680ca40032dVS 5.66 beta
https://voodooshield.com/Download/InstallVoodooShield566beta.exe
SHA-256: c07e996191d93630e4219f6accc6b7633f10f5c8a38f258ac7d2bd7667c59813VS 5.71
https://voodooshield.com/Download/InstallVoodooShield571.exe
SHA-256: 2df489a3882511d602431f5573a33965a41eb91d8f494f3f4187c790d26b55e4VS 5.73
https://voodooshield.com/Download/InstallVoodooShield573.exe
SHA-256: 0d8c5dbb2ff04cd3a055214421bb2f0b833b33c2ba3642a0cef858b3a25c9f56VS 5.75
https://voodooshield.com/Download/InstallVoodooShield575.exe
SHA-256: 13728cde64f3173369ab2c34f6c3cb0a947cdf0c3c3f63a8768ca28b010e553dVS 5.76
https://voodooshield.com/Download/InstallVoodooShield576.exe
SHA-256: e121fdec62f822cde8bedd03e71e1d717bcc543e4bdaf4a8da636bfcab351119VS 5.77
https://voodooshield.com/Download/InstallVoodooShield577.exe
SHA-256: 790b19411c32365206955d54e45e17d18a976cb3551e910258504dd213038739-
This topic was modified 1 year, 1 month ago by
Dan.
-
This topic was modified 1 year, 1 month ago by
Dan.
-
This topic was modified 1 year, 1 month ago by
Dan.
-
This topic was modified 1 year, 1 month ago by
Dan.
-
This topic was modified 1 year, 1 month ago by
Dan.
-
This topic was modified 1 year, 1 month ago by
Dan.
-
This topic was modified 1 year, 1 month ago by
Dan.
-
This topic was modified 1 year, 1 month ago by
Dan.
-
This topic was modified 1 year, 1 month ago by
Dan.
-
This topic was modified 1 year, 1 month ago by
Dan.
-
This topic was modified 1 year, 1 month ago by
Dan.
-
This topic was modified 1 year, 1 month ago by
Dan.
-
This topic was modified 1 year, 1 month ago by
Dan.
-
This topic was modified 1 year ago by
Triple Helix.
-
This topic was modified 1 year ago by
Dan.
-
This topic was modified 1 year ago by
Dan.
-
This topic was modified 1 year ago by
Dan.
-
This topic was modified 1 year ago by
Dan.
-
This topic was modified 1 year ago by
Dan.
-
This topic was modified 1 year ago by
Dan.
-
This topic was modified 1 year ago by
Dan.
-
This topic was modified 1 year ago by
Dan.
-
This topic was modified 1 year ago by
Dan.
-
This topic was modified 1 year ago by
Dan.
-
This topic was modified 11 months, 4 weeks ago by
Dan.
-
This topic was modified 11 months ago by
Dan.
-
This topic was modified 11 months ago by
Dan.
-
This topic was modified 10 months, 3 weeks ago by
Dan.
-
This topic was modified 9 months ago by
Dan.
-
This topic was modified 9 months ago by
Dan.
-
This topic was modified 8 months, 2 weeks ago by
Dan.
-
This topic was modified 8 months, 2 weeks ago by
Dan.
-
This topic was modified 8 months, 1 week ago by
Dan.
-
This topic was modified 8 months, 1 week ago by
Dan.
-
This topic was modified 8 months, 1 week ago by
Dan.
-
This topic was modified 7 months, 1 week ago by
Dan.
-
This topic was modified 7 months ago by
Dan.
60
- Replies
-
- November 29, 2019 at 1:29 am
Triple Helix: Do we have to check the Boxes in the Firewall list in WLC?
Good question from my POV. I only have v4.70 (which works bloody beautifully Dan 🙂 ), but I’d assume the boxes are to insert rules for Windows Firewall. My assumption would be that you need to check the boxes to make the rule.
I did look very hard at Glasswire, but they were not considering multi-user boxes at the time, and I was pointed to WFC which I now use. So I don’t know what Glasswire’s default ruleset is. You need to establish what the default Glasswire ruleset is, whether “deny outbound” or “deny inbound” (which is also the MS default). IF I was using WLC, I would check the outbound boxes for those that actually need outbound (which most don’t) and let WFC look after the rest.
And yes, I do think Dan could add a clarification to the VS GUI on this matter, or put it into “How Whitelist Cloud works”…
_________________________________
Understanding the scope of the problem is the first step on the path to true panic. [Florence Ambrose, "Freefall"]00- November 29, 2019 at 3:38 am
I think the WLC firewall rules only block access to non-whitelisted files. WLC doesn’t create ‘Allow’ rules.Just wondering… Could it be a slow connection between me and the WLC servers causing the WLC scan to take so long?
_______________________________________________________- Windows 10 x64 20H2
- Mint Cinnamon 20.1
00- November 29, 2019 at 4:05 am
Hey guys, I am hoping we are almost there. If for some reason the scan is still taking forever, please email me your DeveloperLog.log and DeveloperServiceLog.log from the C:\ProgramData\VoodooShield folder. The initial scan should take less than 10 minutes, and all subsequent scans should take a second or two.If you were not experiencing issues with 5.51, then you can install over the top. Otherwise, I would uninstall VS, reboot the computer and install 5.52.
I also included an automatic cleanup of the following folders, which runs right before each snapshot scan. I personally think it is a great feature to add to VS anyway, but if there is a reason we should not automatically clean up the temp files, please let me know. BTW, it automatically skips any files that are in use.
C:\Windows\Temp
C:\Users\User\AppData\Local\Temp
Also, I read a suggestion somewhere that was really cool… if you are still having issues with the WLC, please try the standalone version of WLC and let me know how it does. The code is essentially the same at this point, but it is a smart troubleshooting step either way. You can download it here:
https://www.whitelistcloud.com/Download/InstallWhitelistCloud.exe
BTW, there should not be a conflict between the standalone version of WLC and VS, so it should be safe to run them along side each other. Although there is obviously not a reason to do so now, with WLC being fully integrated into VS. I have to admit, I miss the tiny WLC standalone app though 😉.
Please let me know how it goes, thank you guys!
https://voodooshield.com/Download/InstallVoodooShield552beta.exe
SHA-256: dba4fd21024a2bc2686f5ed4e70f1242b5fd24bf66c5ad0987b4cd4ed56abc48
20- November 29, 2019 at 4:16 am
Telos: Another very clean warning (also under D: \Program Files\)
This should actually work if you set your Program Files Windows environment variable to D:\Program Files, but until you do, VS just thinks it is just another folder on the drive ;). Or you could always create a VoodooShield Rule. I am actually shocked that a lot of people do not use the Rules feature… it is one of VS’s best features in my opinion.
Also, WLC did not auto allow this because I changed the very first / top setting in the WhitelistCloud settings tab in VoodooShield Settings. I wanted the auto allowing of Safe WLC files to be more flexible, so I changed it from a binary text box / option to a drop down box with 3 different options. I set the default / middle option to still block WLC files when VS is ON… you know me, I still insist the computer should be locked when it is at risk ;). The odds of someone bypassing WLC is extremely small. Although a couple of weeks ago, someone was testing WLC and one of the malware files was signed with an EV cert. What a waste of $600 ;). Just kidding, I am quite sure they were just testing WLC, although I might look into it just to make sure. Anyway, that malware file bypassed pretty much everything, including SmartScreen, and I believe it was mainly because of the EV cert.
00- November 29, 2019 at 4:21 am
Dan: … we will also have to figure out what to do about temp folders. As we all know, malware loves to hide in these folders, and the problem is so do legitimate apps, and a lot of these legitimate apps do not have a Safe file reputation.
Unfortunately there is no simple answer for temp folders, especially %appdata\local\temp%. We won’t go into the reasons here, there are too many of them, all bad. The most useful idea I have seen is to alter the permissions on all %user\temp% so nothing can execute from them and only ever use the Admin account to do Admin-type stuff. My own ruleset uses the “Block Silently”, but given that so many people have …legitimate (?) softs that operate from %user\temp%, it would be better to force decision-making with a non-silent “Block” action.
It is important to also include c:\Program Data\ in the ruleset, as nothing should ever execute from this location. Again, lazy devs.
I reiterate my policy of feedback to the publishers involved, criticising their poor security practices, also letting them know I have deleted their products from my box in favour of better-behaved programs.
Talking about restricting oneself to your LUA, I use and recommend SuRun, an adaptation of the *nix Sudo. This securely elevates privileges in the LUA context rather than the Admin context. It means I only need the Admin account for system-wide operations.
I hear you on this one, you should see the medical and tax software that are on our client machines, they break every security rule in the book and do not even bother signing their binaries. And these are not small software companies, some of them are multi billion dollar companies and they completely ignore sound security practices. And then everyone wonders why hospitals are smashed with ransomware. Cybersecurity should be a community effort and everyone needs to do their part. Until this happens, there will always be breaches.
00- November 29, 2019 at 4:26 am
Triple Helix: Do we have to check the Boxes in the Firewall list in WLC?
The inbound and outbound boxes will automatically be checked when a WLC Not Safe file is encountered. When the user verifies the item as safe, the firewall rules are automatically removed, so the boxes are then unchecked. As you guys use these new features, please let me know if we need to tweak anything. For example, maybe we do not want the boxes to become unchecked when the user verifies the item as Safe. That is just an example, but you get my point.
Anyway, the inbound and outbound boxes can also be used to block internet access for Safe items. A couple of people have requested a similar feature in the past because they wanted to block certain safe apps from accessing the internet. Anyway, it’s pretty cool because you can do exactly that with these checkboxes ;).
00- November 29, 2019 at 4:33 am
Krusty: I think the WLC firewall rules only block access to non-whitelisted files. WLC doesn’t create ‘Allow’ rules.
Just wondering… Could it be a slow connection between me and the WLC servers causing the WLC scan to take so long?
Well, the main SQL server is a super fast Microsoft Azure cloud database, and 90% + of the results will come directly from this server. Unless you are rocking a dialup connection in Australia, I imagine this is probably not an issue. We can actually replicate the SQL server to several different locations around the world, which will speed things up even more. What kind of speeds do you guys get down under? ;).
I am guessing that there is / was a bug in the code somewhere that is hopefully fixed now… especially since it was taking longer than 10 minutes. I think WLC was somehow stalling when it was trying to analyze files that it is not capable of analyzing, like .dat files. This should be fixed now, but if not, please let me know and also send me your 2 logs, and we will get it fixed in a jiffy ;).
Sorry if I skipped a few posts… its been a long few weeks and I am dying to get away from the computer for a while ;).
Thank you guys, have a great weekend!
10- November 29, 2019 at 4:41 am
Installed 5.52 over the top 5.51. No issue to report.Have a great weekend too.
-
This reply was modified 1 year, 1 month ago by
VecchioScarpone.
"Today is yesterday's future - Carpe diem"
00- November 29, 2019 at 4:45 am
Hey Dan,I hope you’re well and can get plenty of time away from the PC over the weekend.
FYI, I get about 50 mb/s download speed here. Not great but better than many.
If I see the long scan times again I’ll be sure to send you the logs.
Cheers,
Krusty_______________________________________________________- Windows 10 x64 20H2
- Mint Cinnamon 20.1
00- November 29, 2019 at 4:51 am
Gandalf: Dan, can you add the new chromium based Edge to the web apps?
“C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe”
I have now added it myself through auto detect additional running web apps.
I thought I did ;). It should be under the Edge icon and it covers both the old Edge and new Edge… if it is not working correctly please let me know, thank you!
It’s not working for me. I have to use auto detect additional running web apps to add MSEDGE.
How odd… I am trying it now as we speak and it is working for me. Is this working or not working for anyone else?
00- November 29, 2019 at 5:00 am
How or where do I check Edge Chrome or regular edge is working on VS.I know how to manual add it on webapps.
-
This reply was modified 1 year, 1 month ago by
VecchioScarpone.
"Today is yesterday's future - Carpe diem"
00- November 29, 2019 at 5:20 am
I did work it out:I have to manually add EdgeChrome. Without that no joy… I meant no show.
FYI I run EdgeChrome Stable (leaked) I do not have old Edge anymore.
-
This reply was modified 1 year, 1 month ago by
VecchioScarpone.
-
This reply was modified 1 year, 1 month ago by
VecchioScarpone.
"Today is yesterday's future - Carpe diem"
00- November 29, 2019 at 7:05 am
Running 5.52beta and haven’t encountered any problems yet. Did a fresh install.Good work Dan
I’m using KIS, I like how you can block internet incoming/outgoing traffic for not safe files feature. It doesn’t work for Kaspersky Firewall though. Would Windows Firewall be recommended to use and disable Kaspersky’s instead of manually doing it myself?
I do want to use the blocking feature.What settings should I change to harden Windows Firewall?
00- November 29, 2019 at 7:11 am
late to the (v5.50) party. But so far so good. Still not sure I’m up to speed, I just installed 5.52beta. Is that current or is Dan on 5.53?Was running VS 5.04 + WLC 1.04. I uninstalled 5.04 but kept logs and settings. Uninstalled WLC 1.04 everything. Then installed VS 5.52beta. It “remembered” my pro registration (must be that VAi feature 😉 and with WLC icon in systray — total happiness! WLC found 1 expected NOT SAFE and got that popup as I had tweaked in settings, whitelisted that, and it all seems to be running 5×5 — it’s behaving the way I “logically” expected it to work. Kool! The WLC integration is seemingly perfecto so far, at least on this win10_vm test box.
Now can one of you win10 experts tell me why Edge is always connected (apparently online) or why VS always sees it in yellow as connected? Long weekend, perhaps time to dig deeper into the network… Just running windows defender with Andy Ful’s configuredefender tweaks and VS. Edge browser, with Brave on the side for testing.
Dan disregard PM re 5.04, obvious “fix” ref openvpn as a webapp.
I hope y’all had a happy thanksgiving.
00- November 29, 2019 at 9:44 am
Hi DanHope that you are well. Thanks for 5.52Beta. Now clean installed and running.
Funny thing though. On both my systems with 5.51.Beta…initially all was as you stated it should be…initial scan some 5-10 minutes and then very quick follow on scans…but then after a while the follow on scans started extending in terms of duration to the point that nothing was being found but VS was still desperately trying to find somrthing .
Anyway, with 5.52Beta installed all is running as it should but will keep an eye on it over then weekend because if the issue is still about it will not manifest itself until Saturday or later today, Friday.
Generally, have to say for the zillionth time…what an app…and I just wonder what more greatness you are thinking of for putting into it. Do you ever rest? Or is the draw of Vegas still strong in you? ;o)
Respect, Baldrick
-
This reply was modified 1 year, 1 month ago by
Baldrick.
20
- You must be logged in to reply to this topic.