Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 18, 2010, 02:00:48 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
372500
Posts
41297
Topics
93953
Members
Latest Member:
Aleksa
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Discontinued Products
Comodo Firewall
Bug Reports
Some keylogging methods are not detected with ThreatFire (V3.0.14 - .21 X32)
« previous
next »
Pages:
[
1
]
2
Author
Topic: Some keylogging methods are not detected with ThreatFire (V3.0.14 - .21 X32) (Read 14356 times)
MrBrian
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 410
Some keylogging methods are not detected with ThreatFire (V3.0.14 - .21 X32)
«
on:
February 26, 2008, 08:55:14 PM »
Some types of keylogging are no longer detected by v3.0.18.309 on Windows XP SP2. All 7 keylogging methods from AKLT (
http://www.firewallleaktester.com/aklt.htm
) were detected in older CFP versions - such as v3.0.14.276 - but with v3.0.18.309 some of the methods are no longer detected.
Since I was testing this in a virtual machine, perhaps somebody can try to replicate these results on a physical machine, just to make sure it wasn't an issue with virtual machines only or an interaction with new software I have installed recently.
Version: v3.0.18.309
CPU: 32 bit
OS: Win XP SP2
Other security programs running: NOD32, ThreatFire
Defense+ Security Level: Paranoid Mode
Firewall Security Level: Custom Policy Mode
«
Last Edit: March 29, 2008, 08:33:23 AM by MrBrian
»
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 501
COMODO Volunteer DEModerator
Re: Some keylogging methods are not detected anymore (V3.0.18 X32)
«
Reply #1 on:
February 27, 2008, 12:17:55 AM »
Everything is fine here (comodo detected and stopped all keyloging and screenshoting tries) on "physical" machine (non virtual):
Version: v3.0.18.309
CPU: 32 bit
OS: Win XP SP2 Pro
Defense+ Security Level: Train with Safe Mode
Other security programs: Kaspersky IS (without FW and Proactive Defense-behavior blocker components), Comodo Memory Firewall.
Tested aklt v.3 with focus (while typing) on notepad, see screenies of warnings beneath...
Logged
XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
MrBrian
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 410
Re: Some keylogging methods are not detected anymore (V3.0.18 X32)
«
Reply #2 on:
February 27, 2008, 01:25:10 AM »
Thanks for the feedback salmonela
I looked at your screenshots. I could not tell if, for every one of the AKLT tests, you actually did receive an alert for low-level keyboard access or global hook (for keylogging tests) or an alert for reading the screen directly (for the screen reading tests). Some of your screenshots showed other types of alerts, which don't matter for the purposes of this type of testing. Do you remember if you received the proper alert for each of the tests, salmonela?
«
Last Edit: February 27, 2008, 01:33:59 AM by MrBrian
»
Logged
vignesh
Comodo Member
Offline
Posts: 44
Re: Some keylogging methods are not detected anymore (V3.0.18 X32)
«
Reply #3 on:
February 27, 2008, 02:05:39 AM »
Hi,
I see that only the test 'screenshot2' failed.. but the tests you were mentioned are pass.
Please verify the attached snapshots.
CFP:3.0.18.309
OS:Win XP SP2 x32
Defense+:Train with safe
Firewall:Train with safe
«
Last Edit: February 27, 2008, 03:36:07 AM by hiddenstar
»
Logged
Regards,
Vicky.
MrBrian
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 410
Re: Some keylogging methods are not detected anymore (V3.0.18 X32)
«
Reply #4 on:
February 27, 2008, 04:39:42 AM »
Quote from: hiddenstar on February 27, 2008, 02:05:39 AM
I see that only the test 'screenshot2' failed.. but the tests you were mentioned are pass.
Please verify the attached snapshots.
Thanks hiddenstar
Just to make sure, I tested this again inside a virtual machine. Same results as I got before. I also have the latest version of ThreatFire installed in the VMware v5.5.5 virtual machine. Perhaps it's failing due to interaction with ThreatFire. Or maybe it's because the test was done inside a virtual machine. Has anybody else done the AKLT tests with v3.0.18.309?
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 501
COMODO Volunteer DEModerator
Re: Some keylogging methods are not detected anymore (V3.0.18 X32)
«
Reply #5 on:
February 27, 2008, 10:33:51 AM »
Ok, 2nd screenie popped up on execution of AKLT and all two screenshoting attempts from AKLT failed.
screenie 4 affect "GetKeyState", "GetAsyncKeyState", "GetKeyboardState" and "GetRawInputData"
screenie 5,6 blocked "DirectX" from keyloging
screen 7 blocked "LowLewel Hook" and "JournalRecord Hook"
Note: retested again, method by method (tested one method, closed AKLT, open AKLT, tested second method...) and also while pop up windows (warnings) from CFP stays unanswered on screen...
All AKLT tests are passed by CFP
«
Last Edit: February 27, 2008, 10:35:57 AM by salmonela
»
Logged
XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
MrBrian
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 410
Re: Some keylogging methods are not detected anymore (V3.0.18 X32)
«
Reply #6 on:
February 27, 2008, 11:51:13 AM »
I tested this issue inside a virtual machine with v3.0.14.276, and got the same results, namely some AKLT keylogging tests gave no appropriate alert. Then I uninstalled ThreatFire in the virtual machine and rebooted. All of the keylogging tests in AKLT then triggered appropriate alerts in CFP.
I then tested on my physical machine with v3.0.14.276 and ThreatFire v3.0.14.16. Again, some of the AKLT keylogging tests failed, namely GetKeyState, GetAsyncKeyState, and GetRawInputData. ThreatFire also did not warn of keylogging during any of these 3 tests. The other four tests - GetKeyboardState, DirectX, LowLevel Hook, and JournalRecord Hook - triggered appropriate alerts in CFP.
Thus, it seems that there is an interaction issue between Comodo Firewall and ThreatFire that prevents some keylogging methods from being detected. There is a thread at ThreatFire forum about this issue -
http://www.pctools.com/forum/showthread.php?t=50792
.
«
Last Edit: February 27, 2008, 12:32:09 PM by MrBrian
»
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: Some keylogging methods are not detected when ThreatFire installed (V3.0.18 X32)
«
Reply #7 on:
February 27, 2008, 05:59:03 PM »
I don't know much about TF but it looks like a HIPS thus conflict is inevitable. I guess you should use CFP firewall only to install TF.
«
Last Edit: February 27, 2008, 06:06:55 PM by gibran
»
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
MrBrian
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 410
Re: Some keylogging methods are not detected when ThreatFire installed (V3.0.18 X32)
«
Reply #8 on:
February 27, 2008, 09:38:40 PM »
Quote from: gibran on February 27, 2008, 05:59:03 PM
I don't know much about TF but it looks like a HIPS thus conflict is inevitable. I guess you should use CFP firewall only to install TF.
I do realize that both are HIPS products but there are good reasons to use both instead of just one. This is the only issue I've seen so far in the week or so that I've had ThreatFire installed. I'm hoping it can be fixed by one of the vendors. If not, then perhaps the installer for CFP should warn about the issue if ThreatFire is already installed.
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: Some keylogging methods are not detected when ThreatFire installed (V3.0.18 X32)
«
Reply #9 on:
February 28, 2008, 12:47:11 AM »
Quote from: MrBrian on February 27, 2008, 09:38:40 PM
I do realize that both are HIPS products but there are good reasons to use both instead of just one. This is the only issue I've seen so far in the week or so that I've had ThreatFire installed. I'm hoping it can be fixed by one of the vendors. If not, then perhaps the installer for CFP should warn about the issue if ThreatFire is already installed.
Ok. understood.
if you disable keyboard in Advanced\D+ settings\Monitor settings Does TF catch keyloggers?
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
MrBrian
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 410
Re: Some keylogging methods are not detected when ThreatFire installed (V3.0.18 X32)
«
Reply #10 on:
February 28, 2008, 02:13:51 AM »
Quote from: gibran on February 28, 2008, 12:47:11 AM
Ok. understood.
if you disable keyboard in Advanced\D+ settings\Monitor settings Does TF catch keyloggers?
No - not in physical machine. In virtual machine, if I recall correctly, ThreatFire catches keyloggers without changing this setting.
«
Last Edit: February 28, 2008, 02:17:15 AM by MrBrian
»
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: Some keylogging methods are not detected when ThreatFire installed (V3.0.18 X32)
«
Reply #11 on:
February 28, 2008, 03:04:16 AM »
Quote from: MrBrian on February 28, 2008, 02:13:51 AM
No - not in physical machine. In virtual machine, if I recall correctly, ThreatFire catches keyloggers without changing this setting.
You never mentioned this before. So did you actually tested this too?
Does TF has a setting like CFP that allow to disable a protection monitor?
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
MrBrian
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 410
Re: Some keylogging methods are not detected when ThreatFire installed (V3.0.18 X32)
«
Reply #12 on:
February 28, 2008, 03:54:07 AM »
Quote from: gibran on February 28, 2008, 03:04:16 AM
Does TF has a setting like CFP that allow to disable a protection monitor?
No
Quote from: gibran on February 28, 2008, 03:04:16 AM
You never mentioned this before. So did you actually tested this too?
Yes. Comodo Firewall behaves the same in VMware virtual machine as with physical machine in regards to the AKLT keylogging tests when ThreatFire is installed. But in a virtual machine with Comodo Firewall 3 installed, ThreatFire catches a subset of the AKLT keylogging tests, while in a physical machine ThreatFire catches none of them, if I recall correctly. Your results of course may vary....
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5063
A bad workman always blames his tools
Re: Some keylogging methods are not detected when ThreatFire installed (V3.0.18 X32)
«
Reply #13 on:
February 28, 2008, 04:36:38 AM »
Quote from: MrBrian on February 28, 2008, 03:54:07 AM
Yes. Comodo Firewall behaves the same in VMware virtual machine as with physical machine in regards to the AKLT keylogging tests when ThreatFire is installed. But in a virtual machine with Comodo Firewall 3 installed, ThreatFire catches a subset of the AKLT keylogging tests, while in a physical machine ThreatFire catches none of them, if I recall correctly. Your results of course may vary....
Yep I understood your test case but I proposed a variation,
that is if you disable keyboard in Advanced\D+ settings\Monitor settings CFP will not catch those keylogging leaktests but it should enable TF to catch them in physical machine
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
MrBrian
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 410
Re: Some keylogging methods are not detected when ThreatFire installed (V3.0.18 X32)
«
Reply #14 on:
February 28, 2008, 08:35:49 PM »
Quote from: gibran on February 28, 2008, 04:36:38 AM
Yep I understood your test case but I proposed a variation,
that is if you disable keyboard in Advanced\D+ settings\Monitor settings CFP will not catch those keylogging leaktests but it should enable TF to catch them in physical machine
Sorry if my previous answer of "No - not in physical machine" was unclear. I meant that I did try this variation in the physical machine, but it made no difference in ThreatFire's ability to catch keyloggers. Thanks for the good suggestion though.
Logged
Tags:
threatfire
CFP 3.0.18 BUG
keylogging
CFP 3.0.14 BUG
CFP 3.0.15 BUG
CFP 3.0.16 BUG
CFP 3.0.17 BUG
CFP 3.0.19 BUG
CFP 3.0.21 BUG
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.274 seconds with 18 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com