Welcome, Guest. Please login or register.
November 22, 2009, 01:44:13 PM

Login with username, password and session length

336865 Posts
37276 Topics
84511 Members

Latest Member: dusty197

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Feedback/Comments/Announcements/News - CIS
| | | |-+  has cis problems under windows vista/7 64bit??
« previous next »
Pages: 1 [2] Go Down Print
Author Topic: has cis problems under windows vista/7 64bit??  (Read 1914 times)
Timo Schmidt
Comodo Member
**
Offline Offline

Posts: 32


« Reply #15 on: October 12, 2009, 06:06:17 AM »

However, CIS still protects 64bit enough. Comodo would NOT leave you vulnerable knowingly.

Let me translate. There are some Protection Features that are disabled in CIS on 64 bit?

Or to speak "leaktest": Many matousec-tests won't be passed on 64bit.


Greetings

Timo
Logged
evil_religion
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 329


« Reply #16 on: October 12, 2009, 02:33:30 PM »

Let me translate. There are some Protection Features that are disabled in CIS on 64 bit?
They aren't disabled, they are implemented via a weak way.

Or to speak "leaktest": Many matousec-tests won't be passed on 64bit.
Indeed Sad
Logged
wj32
Comodo Loves me
****
Offline Offline

Posts: 122



WWW
« Reply #17 on: October 13, 2009, 12:45:14 AM »

But it's wrong. Comodo partially uses unsecured ring 3 hooks which can be avoided by Matousec SSTS.

Any evidence? I know I didn't give any for my case, but you have made quite a big statement. Also, what do you mean by "unsecured"?

Quote
window messages don't get intercepted in kernel mode by Comodo.

And impossible to do correctly (i.e. in kernel-mode) due to the fact that the shadow SSDT is protected by PatchGuard and MS doesn't provide any callbacks for win32k.

Quote
Outpost FW passes some more tests of SSTS on x64 than Comodo, maybe they use secured user mode hooks. Comodo should do the same. I don't think that it won't be useful if Agnitum goes this way.

What do you mean by "secured", and how secure can they get? Are they secure from people directly using the "syscall" instruction?
Logged
evil_religion
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 329


« Reply #18 on: October 13, 2009, 08:49:17 AM »

Any evidence? I know I didn't give any for my case, but you have made quite a big statement.
egemen said so (indirectly) and SSTS proves that. For the original non SSTS leaktests Comodo gives warnings, but the SSTS ones with ring 3 unhooker are failed by Comodo, for example keyloggers.

Also, what do you mean by "unsecured"?
That the unhooker of SSTS can unhook them.

And impossible to do correctly (i.e. in kernel-mode) due to the fact that the shadow SSDT is protected by PatchGuard and MS doesn't provide any callbacks for win32k.
However, KIS catches the window message handles of SSTS on x64. So what?


What do you mean by "secured", and how secure can they get?
I don't know, ask the Outpost developers, hopefully they will share their secret with Comodo Roll Eyes

Are they secure from people directly using the "syscall" instruction?
You are the expert, not me Wink
Maybe you should look into the SC of SSTS and get your own impressions of how several products score on x64.
Logged
wj32
Comodo Loves me
****
Offline Offline

Posts: 122



WWW
« Reply #19 on: October 13, 2009, 03:59:07 PM »

 
Quote
However, KIS catches the window message handles of SSTS on x64. So what?

Then it uses user-mode hooks. Unlike kernel-mode hooks, user-mode hooks can always be bypassed, no matter what protection you try to set up.
Logged
evil_religion
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 329


« Reply #20 on: October 14, 2009, 11:39:55 AM »

It seems the Kaspersky and Agnitum developers have another opinion.

You are an expert, you could look how KIS and Outpost hook several calls on x64.
Logged
Tags:
Pages: 1 [2] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in -0 seconds with 20 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com