Dan jak widać starał się mocno i po kilku dniach nieobecności ogłosił kolejną wersję - 2.77. Wprowadza oczekiwaną piaskownicę Cuckoo Sandbox, choć wie, że musi jeszcze nad nią popracować. Ta wersja niestety nie obsługuje Win XP, mam jednak nadzieję, że to przejściowy stan.
Cytat:I got a little carried away with the new features[Aby zobaczyć linki, zarejestruj się tutaj]
. The Cuckoo Sandbox is pretty much ready, although we will want to refine and tweak it a little in the next few days. There is still a little more work to do on the KMD, but it is getting there. I might even take a little break for a few days before finishing that up.
Here is the latest version with the Cuckoo Sandbox integration. So far I have not been able to get it to work with XP (and it may not ever), but it seems to work great with everything else. So if you are running XP, there is no reason to upgrade to this version.
This version is all about the Cuckoo Sandbox / Remote Sandbox. So either drag and drop a file, or have VS block a file, then choose “Sandbox”, then “Cuckoo”.
If you want to watch the analysis in real-time, in a remote desktop session, just make sure you check the option “Watch Cuckoo Sandbox analysis in a Remote Desktop session in real-time”, before you click the “Cuckoo” button. I was going to have it enabled by default, but I did not want to scare one of our other users that have no idea about the RDP features[Aby zobaczyć linki, zarejestruj się tutaj]
. Besides, the more bandwidth (among other things) we can conserve, the better.
[Aby zobaczyć linki, zarejestruj się tutaj]
I have not tested the Cuckoo server other than just running internal tests, but I think it will do quite well. It estimates that it can perform 13,000+ analysis per day (or 525+ per hour), but I guess we will see[Aby zobaczyć linki, zarejestruj się tutaj]
. For now I limited the RDP sessions to 1 every 5 minutes, just to make sure I did not overlook something... and we end up crashing the server[Aby zobaczyć linki, zarejestruj się tutaj]
. There are a lot of "moving parts" between VS and the Cuckoo Sandbox, and a lot of things that could potentially go wrong, but I think everything is pretty darn stable at this point. Hopefully there will not be any firewall issues, but I think since it is just a standard RDP, it should be fine.
Hopefully I will be able to catch up on the posts I have missed this weekend... then after these last few features are finished, hopefully things will go back to normal. Thank you, talk to you soon!
[Aby zobaczyć linki, zarejestruj się tutaj]
"Bezpieczeństwo jest podróżą, a nie celem samym w sobie - to nie jest problem, który można rozwiązać raz na zawsze"
"Zaufanie nie stanowi kontroli, a nadzieja nie jest strategią"
"Zaufanie nie stanowi kontroli, a nadzieja nie jest strategią"