Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 30, 2009, 01:20:44 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
338658
Posts
37477
Topics
85069
Members
Latest Member:
johnlaikp
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Anti Virus/Malware Products/Other Security products
Rootkits
« previous
next »
Pages:
[
1
]
Author
Topic: Rootkits (Read 3095 times)
Rotty
Global Moderator
Comodo's Hero
Offline
Posts: 898
http://www.venganza.org/ - Noodly Appendage
Rootkits
«
on:
October 04, 2006, 08:47:11 PM »
I am not so certain that COMODO can detect a rootkit calling out to the net. (Depending on the rootkit, IE Kernal level, TCP/IP stack interference etc).
This is why installing COMODO or any product as Administrator and then using the computer as a Limited User makes it 99.99% impossible for this problem to occur.
If you run as a limited user and catch a rootkit, alot of them will just not install. Some will try and exploit the OS to gain Administrator rights (PATCH WINDOWS to avoid this). If a User Mode rootkit installs it will run under the Limited user rights (Can't access your system files (AT ALL), can't load drivers or services as the Administrator account)
Passwording your administrator accounts with a simple but strong password is worth doing too.
When you install the Firewall has the Administrator user rights which trumps out the rootkit running under a limited user rights.
cheers, rotty
«
Last Edit: October 04, 2006, 09:21:59 PM by justin1278
»
Logged
The opinions expressed in my posts are my own.
They do NOT necessarily represent or reflect the views of my employer.
Júštiñ™
Global Moderator
Comodo's Hero
Offline
Posts: 2868
Re: Rootkits
«
Reply #1 on:
October 04, 2006, 08:51:46 PM »
It may not be able to stop it (yet) however it can render the rootkit useless by blocking all of its activities
«
Last Edit: October 04, 2006, 09:23:15 PM by justin1278
»
Logged
When the power of love, overcomes the love of power, the world will know peace.
~Jimi Hendrix
Rotty
Global Moderator
Comodo's Hero
Offline
Posts: 898
http://www.venganza.org/ - Noodly Appendage
Re: Rootkits
«
Reply #2 on:
October 04, 2006, 08:59:06 PM »
You can't tell me that COMODO can stop a rootkit. I will have to test this myself some day, it is a bit of a big claim.
Unless COMODO is running at the Kernal level, and has it's self a (GOOD) rootkit (-:
cheers, rotty
«
Last Edit: October 04, 2006, 09:23:30 PM by justin1278
»
Logged
The opinions expressed in my posts are my own.
They do NOT necessarily represent or reflect the views of my employer.
comicfan2000
Guest
Re: Rootkits
«
Reply #3 on:
October 04, 2006, 09:17:51 PM »
Quote from: Rotty on October 04, 2006, 08:59:06 PM
You can't tell me that COMODO can stop a rootkit. I will have to test this myself some day, it is a bit of a big claim.
Unless COMODO is running at the Kernal level, and has it's self a (GOOD) rootkit (-:
cheers, rotty
If you want to test, just throw in a Sony music CD, lolll.
Paul
«
Last Edit: October 04, 2006, 09:23:47 PM by justin1278
»
Logged
Júštiñ™
Global Moderator
Comodo's Hero
Offline
Posts: 2868
Re: Rootkits
«
Reply #4 on:
October 04, 2006, 09:18:39 PM »
Comodo can stop any type of program that tries to modify, or report back to a source online, if the program is not in the allow list, or safe applications list. Since a rootkit would not be in either of those I am assuming since a rootkit is nothing more then an application (that hides deeply in your system) it would have to go through the same steps with Comodo Personal Firewall. And even if the Rootkit were to try and hide by making itself look like a regular system process Comodo would detect the changes made and still ask you to Allow or Deny it. But this is all in
theory
. Egemen or one of the other Comodo staff would be able to answer this better.
P.S. I have split these posts from the original article by Mike so we do not pollute his topic.
«
Last Edit: October 04, 2006, 09:26:11 PM by justin1278
»
Logged
When the power of love, overcomes the love of power, the world will know peace.
~Jimi Hendrix
Rotty
Global Moderator
Comodo's Hero
Offline
Posts: 898
http://www.venganza.org/ - Noodly Appendage
Re: Rootkits
«
Reply #5 on:
October 04, 2006, 09:39:10 PM »
Ok, i'll wait to see if it is true.
I would really like it to be true, don't get me wrong. Comodo is trying to plug a very leaky boat (Windows) (-:
cheers, rotty
Logged
The opinions expressed in my posts are my own.
They do NOT necessarily represent or reflect the views of my employer.
Júštiñ™
Global Moderator
Comodo's Hero
Offline
Posts: 2868
Re: Rootkits
«
Reply #6 on:
October 04, 2006, 10:18:14 PM »
Quote from: Rotty on October 04, 2006, 09:39:10 PM
Ok, i'll wait to see if it is true.
I would really like it to be true, don't get me wrong. Comodo is trying to plug a very leaky boat (Windows) (-:
cheers, rotty
Indeed they are, and I think they are doing a very good job so far
.
Logged
When the power of love, overcomes the love of power, the world will know peace.
~Jimi Hendrix
Rotty
Global Moderator
Comodo's Hero
Offline
Posts: 898
http://www.venganza.org/ - Noodly Appendage
Re: Rootkits
«
Reply #7 on:
October 04, 2006, 11:04:17 PM »
Personally the only sure way is to stop a rootkit from installing at the same rights level as your security software is. This is the best solution.
Windows Vista, will make this alot easier of a task. On the topic of windows vista, third-party security software will not be needed as they are including a outbound/inbound firewall the only need will be antivirus.
To use the Vista properly, turn the outbound protection on
Create an administrative account in vista
Edit Local Security Policy Settings.
It is more of a work around then other ways, but it is free and effective.
cheers, rotty
Logged
The opinions expressed in my posts are my own.
They do NOT necessarily represent or reflect the views of my employer.
Júštiñ™
Global Moderator
Comodo's Hero
Offline
Posts: 2868
Re: Rootkits
«
Reply #8 on:
October 05, 2006, 02:48:08 PM »
Personaly I would
never
trust the built in Windows Firewall, even with Windows Vista, it is not as configurable as Comodo is as well, so overall I would rather pay a few MB of space for a much better firewall.
Logged
When the power of love, overcomes the love of power, the world will know peace.
~Jimi Hendrix
Rotty
Global Moderator
Comodo's Hero
Offline
Posts: 898
http://www.venganza.org/ - Noodly Appendage
Re: Rootkits
«
Reply #9 on:
October 06, 2006, 01:18:59 AM »
I personally think it will be a very strong firewall. The reason Linux is such as strong operating system is because it is a no-brainer to run as a "Safe" or "Limited" user and not the "Root" account. Microsoft have acheived this, the implementation they now have will be VERY secure and the windows firewall will serve just fine in vista because of the ability and ease running as a limited user has in vista.
Third Party firewalls are going to have to offer more protection, IE. Better traffic analyisis (Stats recording), (I would love this) and other nifty features to seperate themselves from Microsoft's signicant improvement. Rootkit's will be a thing of the past if you do not run as the Administrator!, and antivirus programs will be able to be installed as the root account, the user then logs of that and uses the limited account since the antivirus has "SYSTEM" level access and the virus is only able to install and run under silly "Limited user" rights, the antivirus can boot the virus allot easier.
cheers, rotty
Logged
The opinions expressed in my posts are my own.
They do NOT necessarily represent or reflect the views of my employer.
Júštiñ™
Global Moderator
Comodo's Hero
Offline
Posts: 2868
Re: Rootkits
«
Reply #10 on:
October 06, 2006, 08:43:54 AM »
Rotty,
What protection does the Vista Firewall offer that Comodo doesn't? The Vista Firewall is
fine
for the simple user who doesn't know much about security but those who do know more and would like to protect themselves (imo) the Vista Firewall is not for them, I know how the Vista firewall works, in fact at this very moment I am typing from Windows Vista with the Windows Firewall enabled. Comodo offers the same protection and much more then the Vista firewall probobly ever will.
Logged
When the power of love, overcomes the love of power, the world will know peace.
~Jimi Hendrix
Rotty
Global Moderator
Comodo's Hero
Offline
Posts: 898
http://www.venganza.org/ - Noodly Appendage
Re: Rootkits
«
Reply #11 on:
October 06, 2006, 10:54:55 PM »
Mmm, you are in a better spot to say, so what are the list of differences between COMODO and Windows Vista Firewall?
cheers, rotty
Logged
The opinions expressed in my posts are my own.
They do NOT necessarily represent or reflect the views of my employer.
Júštiñ™
Global Moderator
Comodo's Hero
Offline
Posts: 2868
Re: Rootkits
«
Reply #12 on:
October 08, 2006, 02:50:32 AM »
Lets just say it is basicaly the same thing as the XP firewall except it somewhat protects you from outbound threats. It doesn't show current connections or log anything, it does not show internet traffic, there is no indication that there is even a firewall on, the only indicator you get is the little popup asking you to block or unblock some applications, however you can go to the Control Panel and add blocked or allowed programs. In all honesty I wouldn't trust it more then I trust the current XP firewall. I will post some screenshots later of it.
Logged
When the power of love, overcomes the love of power, the world will know peace.
~Jimi Hendrix
Rotty
Global Moderator
Comodo's Hero
Offline
Posts: 898
http://www.venganza.org/ - Noodly Appendage
Re: Rootkits
«
Reply #13 on:
October 08, 2006, 03:51:53 AM »
It may be good, it may not. But i feel more confident personally in a third-party firewall. I don't care what anyone says but Security through Obscurity is a valid line of defence (Among others). Having a exploit in 1 product that will effect 90% of computer uses is just to tempting for a hacker to gain fame.
cheers, rotty
Logged
The opinions expressed in my posts are my own.
They do NOT necessarily represent or reflect the views of my employer.
Júštiñ™
Global Moderator
Comodo's Hero
Offline
Posts: 2868
Re: Rootkits
«
Reply #14 on:
October 09, 2006, 10:50:02 AM »
Quote from: Rotty on October 08, 2006, 03:51:53 AM
It may be good, it may not. But i feel more confident personally in a third-party firewall. I don't care what anyone says but Security through Obscurity is a valid line of defence (Among others). Having a exploit in 1 product that will effect 90% of computer uses is just to tempting for a hacker to gain fame.
cheers, rotty
Thats why we use Comodo and not the built in XP firewall
Logged
When the power of love, overcomes the love of power, the world will know peace.
~Jimi Hendrix
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.045 seconds with 17 queries.
Powered by SMF 1.1.10
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com