楼主: zwl2828
收起左侧

[原创] NortonUAC 小测+汉化

[复制链接]
jpzy
发表于 2008-8-25 12:06:18 | 显示全部楼层
提个问题。比如我现在运行regedit,或者explorer.exe向system32一个文件,那么UAC都会跳出来询问!

假如我用了这个工具,选择了记住我的回答。那么是不是以后这样的操作都不再提示了呢?

如果不是我运行热regedit,而是病毒调用regedit写注册表怎么办?如果不是我复制文件到system32,而是某个病毒插入了explorer,然后调用explorer向system32写文件怎么办?

UAC能分辨吗?貌似我记得我看过技术分析,UAC不能分辨。那选择了记住操作,岂不是降低了安全性?
zwl2828
 楼主| 发表于 2008-8-25 12:46:43 | 显示全部楼层
原帖由 jpzy 于 2008-8-25 12:06 发表
提个问题。比如我现在运行regedit,或者explorer.exe向system32一个文件,那么UAC都会跳出来询问!

假如我用了这个工具,选择了记住我的回答。那么是不是以后这样的操作都不再提示了呢?

如果不是我运行热rege ...

不知道,去问技术人员了。
http://community.norton.com/norton/board/message?board.id=uact&thread.id=31

[ 本帖最后由 zwl2828 于 2008-8-25 13:27 编辑 ]
zwl2828
 楼主| 发表于 2008-8-25 12:47:01 | 显示全部楼层
小小地修改了一下,润色了文字。
DistanceLove
发表于 2008-8-25 13:37:25 | 显示全部楼层
3楼是色狼。。。。。。。。。
zwl2828
 楼主| 发表于 2008-8-25 13:47:22 | 显示全部楼层
原帖由 Precious 于 2008-8-25 13:37 发表
3楼是色狼。。。。。。。。。

貌似我是三楼嘛
DistanceLove
发表于 2008-8-25 13:56:20 | 显示全部楼层

回复 55楼 zwl2828 的帖子

那你就是色狼
jpzy
发表于 2008-8-25 14:04:19 | 显示全部楼层
原来小夏的取向是…………
zwl2828
 楼主| 发表于 2008-8-25 22:13:50 | 显示全部楼层
特别感谢MINGLIHE
格林
发表于 2008-8-25 23:14:20 | 显示全部楼层
做的很漂亮么,楼主汉化的也不错
zwl2828
 楼主| 发表于 2008-8-26 06:26:56 | 显示全部楼层
原帖由 jpzy 于 2008-8-25 12:06 发表
提个问题。比如我现在运行regedit,或者explorer.exe向system32一个文件,那么UAC都会跳出来询问!

假如我用了这个工具,选择了记住我的回答。那么是不是以后这样的操作都不再提示了呢?

如果不是我运行热rege ...


Thanks for bringing this up,  the current implementation indeed is designed with this in mind, here is how.

In order for the tool to consider one particular action as the SAME action, we look at many attributes.  The attributes which identifies an action includes: the parent process (launching process) and all the modules loaded; target process (module); Associated windows name and class etc...   So for example launching regedit from the run cmd, will be a different action than launching it by double click on regedit.exe in the system32 directory (try it out).

We try to use many different attributes to asess a particular action, so that an action triggered by executable automatically will look a lot different than an action triggered by a user. So if a virus use "regedit" write a registry.  The tool should consider this as a different action.  1.  The parent executable is probably different, (this case will be the virus name).  2.  If explorer.exe is used, the launcher must be loaded in explorer.exe as a module, the action will be considered different if loaded modules are not the same.  3.  We also check the integrity of the executables, so if explorer.exe is some how infected, the binary difference will also trigger the action to be different. 4.  The associated windows also is a factor to identify an action. ("launching from task bar", "launching from cmd"...)

With that said, you are very right, it is important for the tool to identify an unique action correctly.  The current implementation is designed to do that.  But there might be flaws in the algorithm, or cases we did not think of.  That's why we want more people to use it and tell us the issues you find :), so we can fine tone the algorithms.
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-2 20:55 , Processed in 0.091004 second(s), 13 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表