<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; cw sandbox</title> <atom:link href="http://www.ghacks.net/tag/cw-sandbox/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 09:52:46 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Analyse Software In A Remote Secure Environment</title><link>http://www.ghacks.net/2009/03/29/analyse-software-in-a-remote-secure-environment/</link> <comments>http://www.ghacks.net/2009/03/29/analyse-software-in-a-remote-secure-environment/#comments</comments> <pubDate>Sun, 29 Mar 2009 13:01:30 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[antivirus]]></category> <category><![CDATA[computer security]]></category> <category><![CDATA[cw sandbox]]></category> <category><![CDATA[malware protection]]></category> <category><![CDATA[online virus scan]]></category> <category><![CDATA[remote secure]]></category> <category><![CDATA[sandbox]]></category> <category><![CDATA[software analysis]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2009/03/29/analyse-software-in-a-remote-secure-environment/</guid> <description><![CDATA[Several remote services are available to analyze submitted software programs or files for malicious contents like computer viruses or trojans. Among them are Virus Total which uses more than a dozen different antivirus engines to scan submitted files. All of them have one thing in common: They scan and analyze the files using signature databases [...]]]></description> <content:encoded><![CDATA[<p>Several remote services are available to analyze submitted software programs or files for malicious contents like computer viruses or trojans. Among them are <a
href="http://www.ghacks.net/2008/03/14/virus-total-uploader/ ">Virus Total</a> which uses more than a dozen different antivirus engines to scan submitted files. All of them have one thing in common: They scan and analyze the files using signature databases and maybe heuristic methods which means that they might miss malicious code. The benefit of a security scan in a remote secure environment is that the uploaded files or computer software programs get executed and analyzed.</p><p>CW Sandbox is a web service with a similar looking frontend like all the other online virus scanners. What sets it apart is the remote secure environment that it uses to execute and analyze the files that get uploaded. It uses a sandbox to execute the file and will log all system activity that is connected to the file launch. The file analysis contains a summary but also detailed changes to the file system, the Windows Registry and network activity plus a technical summary with additional information.</p><p>Each report is divided into different categories. The File Changes for example contains categories that list newly created, opened and deleted files and a summary that lists all file operations in chronological order. The network activity analysis will detail connections that have been established including host names, IP addresses and if data has been posted to one of those addresses.</p><p><span
id="more-11524"></span><img
src="http://www.ghacks.net/wp-content/uploads/2009/03/remote_secure_software_analysis-499x233.jpg" alt="remote secure software analysis" title="remote secure software analysis" width="499" height="233" class="alignnone size-medium wp-image-11523" /></p><p>The submit form on the website of the project accepts files with a maximum size of 16 Megabytes. Zip files with up to 50 files can be uploaded to the service as well if the password is set to &#8220;infected&#8221;. A link to the file analysis will be send to the email address that the user enters when submitting the files.</p><p><a
href="http://www.sunbeltsoftware.com/Malware-Research-Analysis-Tools/Sunbelt-CWSandbox/">CW Sandbox</a> is an excellent online service that provides an in depth analysis of submitted files. The only drawbacks are the 16 Megabyte file size limit and that the reports are send to an email address with an undefined wait time. A ticket system on the website directly detailing the place in queue and the estimated wait time would be really helpful for users who are submitting files to the service.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/03/29/analyse-software-in-a-remote-secure-environment/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> </channel> </rss>
