Welcome, Guest. Please login or register.
March 22, 2010, 07:21:36 AM

Login with username, password and session length

373653 Posts
41473 Topics
94220 Members

Latest Member: milanas

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  News / Announcements / Feedback - CIS
| | | |-+  Add sandbox feature into CIS
« previous next »
Pages: 1 2 3 [4] Go Down Print
Author Topic: Add sandbox feature into CIS  (Read 5273 times)
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 501


COMODO Volunteer DEModerator


« Reply #45 on: July 13, 2009, 01:00:06 PM »

   
So, I mean, this is a huge concern for the people who love Sandboxie because they want Sandboxie in the future, in fully patched Windows 64 or in Vista 64. But there just isn't - there is not a way to do it. I mean, it's just oil and water. You cannot make them cohabitate.

Eh, I guess you have never heard about margarine, emulsifier is the keyword for oil and water...  Grin
BTW that brings another question, CIS already now uses user mode hooks in D+ for 64bits OSes, so is it CIS now strong on 64bits OSes as on 32bits where it hooks kernel or ring0?

btw. this is one of my first questions when I become registered uzer of Comodo forum, till today my question stays unanswered
https://forums.comodo.com/hips_host_intrusion_prevention_systems/please_feel_free_to_ask_any_questions_to_learn_all_about_computer_security-t4916.0.html;msg97695#msg97695
« Last Edit: July 13, 2009, 01:06:45 PM by salmonela » Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
evil_religion
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 372


« Reply #46 on: July 13, 2009, 01:07:47 PM »

BTW that brings another question, CIS already now uses user mode hooks in D+ for 64bits OSes, so is it CIS now strong on 64bits OSes as on 32bits where it hooks kernel or ring0?
No, it's not as strong. Matousec SSTS can send window messages, set global hooks and can keylog what you write -> D+ is bypassed. I've mentioned that many many times but nothing happened, egemen didn't tell if they will improve that Sad

Outpost is much better there (but has other weak points).
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 501


COMODO Volunteer DEModerator


« Reply #47 on: July 13, 2009, 01:17:21 PM »

No, it's not as strong. Matousec SSTS can send window messages, set global hooks and can keylog what you write -> D+ is bypassed. I've mentioned that many many times but nothing happened, egemen didn't tell if they will improve that Sad

Outpost is much better there (but has other weak points).
I think it is matter of implementation only, if Matousec modify little his user mode unhooker it will bypass Outpost too, it is nature of user mode hooks it can be unhooked easy...
Did you tried that technique "send window messages" with another keylogger which do not unhook?

P.S. sorry I know very little about matter and my English is weak too, and I don't have 64bits capable processor  Embarrassed
« Last Edit: July 13, 2009, 01:25:56 PM by salmonela » Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
evil_religion
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 372


« Reply #48 on: July 13, 2009, 01:43:39 PM »

I think it is matter of implementation only, if Matousec modify little his user mode unhooker it will bypass Outpost too, it is nature of user mode hooks it can be unhooked easy...
Would be sad if that was true Sad
Is there no strong method to avoid ring 3 hooks getting unhooked?
Are the new APIs which came along with Vista SP1 a real alternative?

Did you tried that technique "send window messages" with another keylogger which do not unhook?
I meant the ddetest leaktest. It sends window messages to remote control other processes (with window).
Logged
Rambaldi
Newbie
*
Offline Offline

Posts: 10


« Reply #49 on: July 16, 2009, 08:59:42 AM »

I believe it works with IE  and Firefox (not 100% sure on which versions it's supported)
There's a 30 day trial available here:

http://www.snapfiles.com/goto.php?id=111768&t=87463528&d=7112658&gourl=/get/forcefield.html

I think that more extensive sandboxing on 64bit would be difficult to say the least,not sure if these issues are eased at all in Windows 7  Huh

It works on IE 6 and above and FF 2.0 and above. They claim it works on Win x64. I found it used a lot of ressources (on Win x86), I had to uninstall it and now am using Sandboxie.
Logged
Rambaldi
Newbie
*
Offline Offline

Posts: 10


« Reply #50 on: July 16, 2009, 09:09:59 AM »

Eh, I guess you have never heard about margarine, emulsifier is the keyword for oil and water...  Grin
BTW that brings another question, CIS already now uses user mode hooks in D+ for 64bits OSes, so is it CIS now strong on 64bits OSes as on 32bits where it hooks kernel or ring0?

btw. this is one of my first questions when I become registered uzer of Comodo forum, till today my question stays unanswered
https://forums.comodo.com/hips_host_intrusion_prevention_systems/please_feel_free_to_ask_any_questions_to_learn_all_about_computer_security-t4916.0.html;msg97695#msg97695

I also asked the same question and did not get any answer either (https://forums.comodo.com/feedbackcommentsannouncementsnews_cis/windows_x64_and_security-t38941.0.html;msg281478#msg281478).

Now that we have an answer thanks to evil_religion, I wonder how to ponder the situation planning ahead for the next PC purchase, given that on Win x64 we won't get the same level of secuirty from CIS as on Win x86. Of course there are some mitigating factors (Kernel Patch Protection should make some infections less probable), but it is obviously not hackproof either.
Logged
andyman35
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1139


« Reply #51 on: July 16, 2009, 10:15:31 AM »

It works on IE 6 and above and FF 2.0 and above. They claim it works on Win x64. I found it used a lot of ressources (on Win x86), I had to uninstall it and now am using Sandboxie.

With 32bit systems Sandboxie is pretty much in a league of its own,near perfection. Thumb Up
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 501


COMODO Volunteer DEModerator


« Reply #52 on: July 16, 2009, 11:42:51 AM »

With 32bit systems Sandboxie is pretty much in a league of its own,near perfection. Thumb Up
ok, but why we don't have statement from Comodo developers about D+ and 64bits implementation of D+, is it so hard to tell? or we should wait for Matoušec to start testing on 64bits platforms so Comodo devs. to tell us any peep about it?
I personally do not like silence in security of any kind, are all api's defended well on 64bits like are defended on 32bits...please answer
« Last Edit: July 16, 2009, 11:52:28 AM by salmonela » Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
Tags:
Pages: 1 2 3 [4] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 6.447 seconds with 19 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com