Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 22, 2010, 07:21:36 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373653
Posts
41473
Topics
94220
Members
Latest Member:
milanas
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products & Services
Comodo Internet Security - CIS
News / Announcements / Feedback - CIS
Add sandbox feature into CIS
« previous
next »
Pages:
1
2
3
[
4
]
Author
Topic: Add sandbox feature into CIS (Read 5273 times)
salmonela
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 501
COMODO Volunteer DEModerator
Re: Interview with Sandboxie author
«
Reply #45 on:
July 13, 2009, 01:00:06 PM »
Quote from: 00hmh on July 10, 2009, 05:39:50 PM
So, I mean, this is a huge concern for the people who love Sandboxie because they want Sandboxie in the future, in fully patched Windows 64 or in Vista 64. But there just isn't - there is not a way to do it. I mean, it's just oil and water. You cannot make them cohabitate.
Eh, I guess you have never heard about margarine,
emulsifier
is the keyword for oil and water...
BTW that brings another question, CIS already now uses user mode hooks in D+ for 64bits OSes, so is it CIS now strong on 64bits OSes as on 32bits where it hooks kernel or ring0?
btw. this is one of my first questions when I become registered uzer of Comodo forum, till today my question stays unanswered
https://forums.comodo.com/hips_host_intrusion_prevention_systems/please_feel_free_to_ask_any_questions_to_learn_all_about_computer_security-t4916.0.html;msg97695#msg97695
«
Last Edit: July 13, 2009, 01:06:45 PM by salmonela
»
Logged
XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
evil_religion
Malware Research Group
Comodo's Hero
Offline
Posts: 372
Re: Interview with Sandboxie author
«
Reply #46 on:
July 13, 2009, 01:07:47 PM »
Quote from: salmonela on July 13, 2009, 01:00:06 PM
BTW that brings another question, CIS already now uses user mode hooks in D+ for 64bits OSes, so is it CIS now strong on 64bits OSes as on 32bits where it hooks kernel or ring0?
No, it's not as strong. Matousec SSTS can send window messages, set global hooks and can keylog what you write -> D+ is bypassed. I've mentioned that many many times but nothing happened, egemen didn't tell if they will improve that
Outpost is much better there (but has other weak points).
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 501
COMODO Volunteer DEModerator
Re: Interview with Sandboxie author
«
Reply #47 on:
July 13, 2009, 01:17:21 PM »
Quote from: evil_religion on July 13, 2009, 01:07:47 PM
No, it's not as strong. Matousec SSTS can send window messages, set global hooks and can keylog what you write -> D+ is bypassed. I've mentioned that many many times but nothing happened, egemen didn't tell if they will improve that
Outpost is much better there (but has other weak points).
I think it is matter of implementation only, if Matousec modify little his user mode unhooker it will bypass Outpost too, it is nature of user mode hooks it can be unhooked easy...
Did you tried that technique "send window messages" with another keylogger which do not unhook?
P.S. sorry I know very little about matter and my English is weak too, and I don't have 64bits capable processor
«
Last Edit: July 13, 2009, 01:25:56 PM by salmonela
»
Logged
XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
evil_religion
Malware Research Group
Comodo's Hero
Offline
Posts: 372
Re: Interview with Sandboxie author
«
Reply #48 on:
July 13, 2009, 01:43:39 PM »
Quote from: salmonela on July 13, 2009, 01:17:21 PM
I think it is matter of implementation only, if Matousec modify little his user mode unhooker it will bypass Outpost too, it is nature of user mode hooks it can be unhooked easy...
Would be sad if that was true
Is there no strong method to avoid ring 3 hooks getting unhooked?
Are the new APIs which came along with Vista SP1 a real alternative?
Quote from: salmonela on July 13, 2009, 01:17:21 PM
Did you tried that technique "send window messages" with another keylogger which do not unhook?
I meant the ddetest leaktest. It sends window messages to remote control other processes (with window).
Logged
Rambaldi
Newbie
Offline
Posts: 10
Re: Add sandbox feature into CIS
«
Reply #49 on:
July 16, 2009, 08:59:42 AM »
Quote from: andyman35 on July 12, 2009, 10:04:44 PM
I believe it works with IE and Firefox (not 100% sure on which versions it's supported)
There's a 30 day trial available here:
http://www.snapfiles.com/goto.php?id=111768&t=87463528&d=7112658&gourl=/get/forcefield.html
I think that more extensive sandboxing on 64bit would be difficult to say the least,not sure if these issues are eased at all in Windows 7
It works on IE 6 and above and FF 2.0 and above. They claim it works on Win x64. I found it used a lot of ressources (on Win x86), I had to uninstall it and now am using Sandboxie.
Logged
Rambaldi
Newbie
Offline
Posts: 10
Re: Interview with Sandboxie author
«
Reply #50 on:
July 16, 2009, 09:09:59 AM »
Quote from: salmonela on July 13, 2009, 01:00:06 PM
Eh, I guess you have never heard about margarine,
emulsifier
is the keyword for oil and water...
BTW that brings another question, CIS already now uses user mode hooks in D+ for 64bits OSes, so is it CIS now strong on 64bits OSes as on 32bits where it hooks kernel or ring0?
btw. this is one of my first questions when I become registered uzer of Comodo forum, till today my question stays unanswered
https://forums.comodo.com/hips_host_intrusion_prevention_systems/please_feel_free_to_ask_any_questions_to_learn_all_about_computer_security-t4916.0.html;msg97695#msg97695
I also asked the same question and did not get any answer either (
https://forums.comodo.com/feedbackcommentsannouncementsnews_cis/windows_x64_and_security-t38941.0.html;msg281478#msg281478
).
Now that we have an answer thanks to evil_religion, I wonder how to ponder the situation planning ahead for the next PC purchase, given that on Win x64 we won't get the same level of secuirty from CIS as on Win x86. Of course there are some mitigating factors (Kernel Patch Protection should make some infections less probable), but it is obviously not hackproof either.
Logged
andyman35
Global Moderator
Comodo's Hero
Online
Posts: 1139
Re: Add sandbox feature into CIS
«
Reply #51 on:
July 16, 2009, 10:15:31 AM »
Quote from: Rambaldi on July 16, 2009, 08:59:42 AM
It works on IE 6 and above and FF 2.0 and above. They claim it works on Win x64. I found it used a lot of ressources (on Win x86), I had to uninstall it and now am using Sandboxie.
With 32bit systems Sandboxie is pretty much in a league of its own,near perfection.
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 501
COMODO Volunteer DEModerator
Re: Add sandbox feature into CIS
«
Reply #52 on:
July 16, 2009, 11:42:51 AM »
Quote from: andyman35 on July 16, 2009, 10:15:31 AM
With 32bit systems Sandboxie is pretty much in a league of its own,near perfection.
ok, but why we don't have statement from Comodo developers about D+ and 64bits implementation of D+, is it so hard to tell? or we should wait for Matoušec to start testing on 64bits platforms so Comodo devs. to tell us any peep about it?
I personally do not like silence in security of any kind, are all api's defended well on 64bits like are defended on 32bits...please answer
«
Last Edit: July 16, 2009, 11:52:28 AM by salmonela
»
Logged
XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
Tags:
Pages:
1
2
3
[
4
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 6.447 seconds with 19 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com