3 ms·
One way to do it is to whitelist all binaries in the system, and sandbox all applications (to prevent chances of a malicious PDF/image/etc abusing a buggy appli
by icebraining 6y ago
One way to do it is to whitelist all binaries in the system, and sandbox all applications (to prevent chances of a malicious PDF/image/etc abusing a buggy application).
- 2Gkashmiri 6y agocan you do that on windows? every single exe, every process?
- icebraining 6y agoYeah, the security policies let you do that. I think the current mechanism is called AppLocker. Note that there may be still ways to bypass it if you're an attacker sitting at the computer, rather than a hapless user.