Welcome, Guest. Please login or register.
October 08, 2008, 05:57:38 AM

Login with username, password and session length

198073 Posts
22794 Topics
54762 Members

Latest Member: idra

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Memory Firewall(Buffer Overflow Protection)
| | |-+  Feedback/Comments/Announcements/News
| | | |-+  Explanation of why CMF fails some buffer overflow tests
« previous next »
Pages: [1] Go Down Print
Author Topic: Explanation of why CMF fails some buffer overflow tests  (Read 1574 times)
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 329


« on: April 26, 2008, 10:44:05 AM »

There have been other topics in which the question of why CMF fails some buffer overflow tests is asked.  While Tyler Durden has stated that the exact operation of CMF is a secret, he has stated that CMF uses hooks.  Here is an interesting article titled 'Bypassing 3rd Party Windows Buffer Overflow Protection' (http://kd7yhr.org/bushbo/misc/phrack/phrack62/p62-0x05_Bypassing_Win_BufferOverflow_Protection.txt) that discusses how some buffer overflow protection products work.  Please note that the article discusses stack backtracing, which Tyler Durden has stated CMF does not use.  However, other insights from the article may be valuable.  I believe that the reason CMF fails some buffer overflow tests is that CMF detects buffer overflow only when hooked Windows API calls from the shellcode are used.  If I am mistaken, Mr. Durden, please correct me.

CMF doesn't backtrace stack frames, it just checks the page corresponding to it's internal page-buffer, so it doesn't vulnerable to fake frames. And again such tests doesn't use any shellcode at all, that's why CMF doesn't "detect" them.
Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 329


« Reply #1 on: April 26, 2008, 08:39:43 PM »

The full text of the article can be found at http://qodsec.blogspot.com/2004/07/phrack-bypassing-3rd-party-windows.html.  The link I gave in the previous post was missing the beginning.
Logged
3xist
Guest
« Reply #2 on: May 31, 2008, 04:18:23 AM »

Locked.

Reason: Out-Dated post.

Josh
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 1 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com