Welcome, Guest. Please login or register.
March 21, 2010, 07:14:49 AM

Login with username, password and session length

373411 Posts
41421 Topics
94148 Members

Latest Member: Sebo77

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  News / Announcements / Feedback - CIS
| | | |-+  Wishlist - CIS
| | | | |-+  Poll: "Driver Installation" instead of "Registry Modification"
« previous next »
Poll
Question: Do you want this feature to be implemented?
Yes - 10 (100%)
No - 0 (0%)
Don't care - 0 (0%)
Total Voters: 10

Pages: [1] Go Down Print
Author Topic: Poll: "Driver Installation" instead of "Registry Modification"  (Read 926 times)
SS26
Comodo's Hero
*****
Offline Offline

Posts: 1666


« on: September 05, 2009, 03:37:03 AM »

update:

Thanks everybody who participated, but feature request is not consistent.  Mentioned registry access warnings for installing driver are used by D+ for both common techniques to install driver.  Despite these warnings do not explicitly indicate that driver is being installed (subject of another enhancement request), main D+ warnings for driver is being loaded are present in both cases.
It is just in Safe/Clean PC modes of D+ main warning when driver is being loaded by services.exe is autolearnt by D+ (under certain circumstances)  -  one of two common techniques to load driver.  However if driver is being loaded by other of two common techniques, warning is almost always there.
See this post and post by wj32 (which is linked to it).




-----  original post start here  -----

Currently Defense+ gives "Registry modification" alerts when driver is to be installed/loaded with definite technique. See screenshots from this post.
These alerts do not explicitly tell user that HKLM\SYSTEM\ControlSet???\Services registry branch is used to install/load drivers.

My feature request would be following: in described cases Defense+ would provide alerts which explicitly indicate that driver(s) is/are to be installed/loaded. This can be implemented by at least adding one more sentence under "Security Considerations" of D+ alerts.


Some of original reports inside original threads (i merely added a poll here):

Please read my comment on this in the PH thread:
Quote
There are two main ways a program can load a driver. One is by writing to the registry in HKLM\System\CurrentControlSet\Services and then calling NtLoadDriver. The other is by contacting the services controller (services.exe) and telling it to create a service to load the driver. In the first case, D+ correctly reports that a program is attempting to load a driver, and tells you the filename of the driver. The prompt is also in red (I think). In the second case however, D+ only prompts you about registry access (which most people will allow since it comes from services.exe) and then the driver is loaded. This is a HUGE problem with D+ and I hope the developers will fix it. Sad

I will elaborate on this. In the Wilders Security thread, gmer was shown with the correct CIS alert. That's because it uses the first technique I discussed (NtLoadDriver). Process Explorer and Process Monitor also use this method. Most other software uses the second technique, and the alerts are broken. I find it puzzling why we are alerted to registry access by services.exe but we are not alerted to services.exe calling NtLoadDriver...

Attached is a small test program demonstrating the two methods. You will be able to see how CIS responds to the two methods with different alerts...

I. On driver installations, do NOT mix in the alert with registry modifications. Separate the two so that users do not confuse trivial registry alerts with driver installs.
« Last Edit: October 09, 2009, 05:39:40 AM by SS26 » Logged
kronos
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 229


CIS - Comodo Italian Translator


« Reply #1 on: September 17, 2009, 10:23:25 AM »

+1
Logged
SS26
Comodo's Hero
*****
Offline Offline

Posts: 1666


« Reply #2 on: September 23, 2009, 12:34:06 PM »

Thread is locked and poll is closed (hopefully  Evil ).  See "update" paragraph in the first post.
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.049 seconds with 20 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com