Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 25, 2013, 12:59:37 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
664065
Posts
70632
Topics
145262
Members
Latest Member:
EricNorris
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
Help - CIS
Defense+ / Sandbox Help - CIS
Memory Access protection
« previous
next »
Pages:
[
1
]
Author
Topic: Memory Access protection (Read 3142 times)
PhyxionNL
Comodo Loves me
Offline
Posts: 141
Memory Access protection
«
on:
February 12, 2012, 04:35:41 AM »
I'm curious regarding the memory access protection, how good does it work? For example, does it protect from reading an applications memory by ring0 drivers and/or low level API's like NtReadVirtualMemory? If not, it would be pretty useless as it would still be extremely easy to workaround that... I couldn't find a single thing about this in the documentation, so if someone can enlighten me, please do so
(Also posted in a subforum, but I *think* this is more in place here)
Logged
i4u1
Comodo Loves me
Offline
Posts: 108
My Personal Text
Re: Memory Access protection
«
Reply #1 on:
February 12, 2012, 06:47:35 AM »
Write a simple driver, then try to load it hehe and then check if it can access. What the question is about?
Logged
Win7x64SP1+, MSE and CIS latest (D+/FW Sec.only, sandbox off)
__
PhyxionNL
Comodo Loves me
Offline
Posts: 141
Re: Memory Access protection
«
Reply #2 on:
February 12, 2012, 07:01:01 AM »
Quote from: i4u1 on February 12, 2012, 06:47:35 AM
Write a simple driver, then try to load it hehe and then check if it can access. What the question is about?
Seems an aweful lot of trouble as I'm pretty sure someone here knows the answer to it
I want to protect an application by not allowing it's memory to be read from any another application.
Logged
Valentin N
Malware Research Group
Comodo's Hero
Offline
Posts: 2833
Usability Study Group
Re: Memory Access protection
«
Reply #3 on:
February 12, 2012, 08:08:51 AM »
Quote from: PhyxionNL on February 12, 2012, 07:01:01 AM
Seems an aweful lot of trouble as I'm pretty sure someone here knows the answer to it
I want to protect an application by not allowing it's memory to be read from any another application.
There is a a way, I am not sure though, but you'll need to added the wanted application with customized settings, by going ti d+ --> Computer Secuity --> add --> 1) application path, 2) customize --> which acess --> modify --> allow/blocked application.
I hope this helps
Logged
Skype: comodohelper (Personal)
CEVPN: Valentin N
CIS 5.9
Keep CTM alive by voting
PhyxionNL
Comodo Loves me
Offline
Posts: 141
Re: Memory Access protection
«
Reply #4 on:
February 12, 2012, 10:33:03 AM »
Quote from: Valentin N on February 12, 2012, 08:08:51 AM
There is a a way, I am not sure though, but you'll need to added the wanted application with customized settings, by going ti d+ --> Computer Secuity --> add --> 1) application path, 2) customize --> which acess --> modify --> allow/blocked application.
I hope this helps
Yeah, I already set it up like that, thanks
My question however is simple, how good is this protection: does it protect against ring0 drivers, and/or low level API's like NtReadVirtualMemory? Because if this is not the case the whole memory access protection would be useless.
Logged
Valentin N
Malware Research Group
Comodo's Hero
Offline
Posts: 2833
Usability Study Group
Re: Memory Access protection
«
Reply #5 on:
February 12, 2012, 01:45:37 PM »
Quote from: PhyxionNL on February 12, 2012, 10:33:03 AM
Yeah, I already set it up like that, thanks
My question however is simple, how good is this protection: does it protect against ring0 drivers, and/or low level API's like NtReadVirtualMemory? Because if this is not the case the whole memory access protection would be useless.
That I can't say. I hope a mod or a developer can tell you.
Logged
Skype: comodohelper (Personal)
CEVPN: Valentin N
CIS 5.9
Keep CTM alive by voting
PhyxionNL
Comodo Loves me
Offline
Posts: 141
Re: Memory Access protection
«
Reply #6 on:
February 13, 2012, 03:39:26 AM »
Yeah, I hope so. Haven't seen much developers/mods going around here lately though
Logged
Valentin N
Malware Research Group
Comodo's Hero
Offline
Posts: 2833
Usability Study Group
Re: Memory Access protection
«
Reply #7 on:
February 13, 2012, 04:44:20 AM »
Quote from: PhyxionNL on February 13, 2012, 03:39:26 AM
Yeah, I hope so. Haven't seen much developers/mods going around here lately though
You could try to ask Melih and egmen for more info. Jackob might also know something
Logged
Skype: comodohelper (Personal)
CEVPN: Valentin N
CIS 5.9
Keep CTM alive by voting
PhyxionNL
Comodo Loves me
Offline
Posts: 141
Re: Memory Access protection
«
Reply #8 on:
February 15, 2012, 04:23:44 AM »
I PMed Melih and egemen, couldn't find Jackob. Still haven't heard from them though.
Logged
Valentin N
Malware Research Group
Comodo's Hero
Offline
Posts: 2833
Usability Study Group
Re: Memory Access protection
«
Reply #9 on:
February 15, 2012, 05:57:26 AM »
Quote from: PhyxionNL on February 15, 2012, 04:23:44 AM
I PMed Melih and egemen, couldn't find Jackob. Still haven't heard from them though.
Jacob
- I added a k without seeing it.
Logged
Skype: comodohelper (Personal)
CEVPN: Valentin N
CIS 5.9
Keep CTM alive by voting
PhyxionNL
Comodo Loves me
Offline
Posts: 141
Re: Memory Access protection
«
Reply #10 on:
February 19, 2012, 04:39:48 AM »
PMed all of them, still no response. Any other person with insight into this? Thanks!
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16723
Re: Memory Access protection
«
Reply #11 on:
February 22, 2012, 01:46:43 PM »
The following still stands as I wrote in your duplicate topic:
Quote from: EricJH on February 19, 2012, 12:36:44 PM
With Ring0 you mean kernel mode access I assume. Once an application has kernel mode access it can do anything. As far as I understand CIS it cannot protect from actions initiated from kernel mode applications.
Quote from: EricJH on February 19, 2012, 04:52:19 PM
According to egemen, the head developer, once a program has kernel access it can do anything including attacking and taking down security applications.
That's why unknown applications are not allowed to install drivers or make services. CIS will help to prevent unauthorized access to kernel level.
In short CIS will prevent to let unknown programs, or gives the user the ability to prevent when using D+ and disabled sandbox, to load a driver (get kernel access). But once a program has kernel access it is end of exercise for each and every application when the program has malicious intent.
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
Valentin N
Malware Research Group
Comodo's Hero
Offline
Posts: 2833
Usability Study Group
Re: Memory Access protection
«
Reply #12 on:
February 22, 2012, 05:37:31 PM »
Thanks for the explanation Eric
Didn't know Ring 1 was the same as kernel mode access
Logged
Skype: comodohelper (Personal)
CEVPN: Valentin N
CIS 5.9
Keep CTM alive by voting
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.05 seconds with 22 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com