Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 29, 2009, 08:55:43 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
345977
Posts
38211
Topics
86788
Members
Latest Member:
Ngeta2k
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Feedback/Comments/Announcements/News - CIS
has cis problems under windows vista/7 64bit??
« previous
next »
Pages:
[
1
]
2
Author
Topic: has cis problems under windows vista/7 64bit?? (Read 3330 times)
res1stanCe
Comodo Member
Offline
Posts: 31
has cis problems under windows vista/7 64bit??
«
on:
October 04, 2009, 11:29:28 AM »
hello
http://www.sandboxie.com/index.php?WindowsVista64
i have read this and i wonder ,has cis the same problems under 64bit systems?
has cis really full control over the kernel in 64bit windows?
«
Last Edit: October 04, 2009, 11:33:05 AM by res1stanCe
»
Logged
OmeletParty
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
Offline
Posts: 1695
The only thing i ask for are eggs.
Re: has cis problems under windows vista/7 64bit??
«
Reply #1 on:
October 04, 2009, 02:55:20 PM »
Quote from: res1stanCe on October 04, 2009, 11:29:28 AM
hello
http://www.sandboxie.com/index.php?WindowsVista64
i have read this and i wonder ,has cis the same problems under 64bit systems?
has cis really full control over the kernel in 64bit windows?
CIS does not hook the kernel in Vista 64bit, its a security program by MS that prevents hooking of the kernel by anyone.
Logged
Happy New Year and Holidays
Please follow forum policy. Thank you.
res1stanCe
Comodo Member
Offline
Posts: 31
Re: has cis problems under windows vista/7 64bit??
«
Reply #2 on:
October 04, 2009, 06:55:50 PM »
thx ,but then is cis less secure on 64bit windows
security software is useless on 64bit windows ,many malware can deactivate user-mode (ring3) drivers...
microsoft is thinking at all? i think not... microsoft blocked the only way to make windows secure with other programs
Logged
res1stanCe
Comodo Member
Offline
Posts: 31
Re: has cis problems under windows vista/7 64bit??
«
Reply #3 on:
October 06, 2009, 08:52:23 AM »
push
Logged
OmeletParty
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
Offline
Posts: 1695
The only thing i ask for are eggs.
Re: has cis problems under windows vista/7 64bit??
«
Reply #4 on:
October 06, 2009, 03:48:08 PM »
I would say CIS protects you without a problem.
And scince when does MS think about security.
They added patch Gaurd to prevent malware from hooking the kernel..
Logged
Happy New Year and Holidays
Please follow forum policy. Thank you.
res1stanCe
Comodo Member
Offline
Posts: 31
Re: has cis problems under windows vista/7 64bit??
«
Reply #5 on:
October 06, 2009, 07:32:47 PM »
yes but patchguard is an inadequate protection... is too weak
and prevents other programs in their work ,nice microsoft
«
Last Edit: October 06, 2009, 07:34:26 PM by res1stanCe
»
Logged
wj32
Comodo Loves me
Offline
Posts: 123
Re: has cis problems under windows vista/7 64bit??
«
Reply #6 on:
October 07, 2009, 05:22:08 AM »
Stop talking nonsense.
1. From the link, it appears that the Sandboxie author(s) do not want to get a driver signing certificate. COMODO already has one (obviously).
2. PatchGuard doesn't prevent security software from working. Sandboxie hooks system calls by modifying the SSDT, and this is protected against by PatchGuard. The MS endorsed way to hook is to use the system supplied callbacks - minifilters, registry callbacks, process/thread callbacks. This way CIS can protect itself without having to do anything special.
Now obviously, CIS might not actually use the callbacks - I don't know - but it seems like the most likely thing to do, because otherwise CIS would be vulnerable to all kinds of attacks.
Logged
res1stanCe
Comodo Member
Offline
Posts: 31
Re: has cis problems under windows vista/7 64bit??
«
Reply #7 on:
October 07, 2009, 07:26:29 AM »
hm.. interesting
i understand. i was not aware until now
thank you for explain this
«
Last Edit: October 07, 2009, 07:43:38 AM by res1stanCe
»
Logged
Rambaldi
Newbie
Offline
Posts: 10
Re: has cis problems under windows vista/7 64bit??
«
Reply #8 on:
October 08, 2009, 07:00:33 AM »
Quote from: wj32 on October 07, 2009, 05:22:08 AM
Stop talking nonsense.
1. From the link, it appears that the Sandboxie author(s) do not want to get a driver signing certificate. COMODO already has one (obviously).
2. PatchGuard doesn't prevent security software from working. Sandboxie hooks system calls by modifying the SSDT, and this is protected against by PatchGuard. The MS endorsed way to hook is to use the system supplied callbacks - minifilters, registry callbacks, process/thread callbacks. This way CIS can protect itself without having to do anything special.
Now obviously, CIS might not actually use the callbacks - I don't know - but it seems like the most likely thing to do, because otherwise CIS would be vulnerable to all kinds of attacks.
That's good to know, however is there any test on Win 64bit? AFAIK matousec makes test on 32bit systems, so I think that the OP raised a legitimate question here.
Logged
3xist
Global Moderator
Comodo's Hero
Offline
Posts: 273
Re: has cis problems under windows vista/7 64bit??
«
Reply #9 on:
October 08, 2009, 07:06:51 AM »
CIS, On Vista SP1 64x and later, Hooks in the kernel as much as possible - Comodo were also in the technical discussions with Microsoft and other Vendors of Patch Guard on Vista 64bit. However, CIS still protects 64bit enough. Comodo would NOT leave you vulnerable knowingly. As for Sandboxing, Yes, CIS 4 is coming and the Sandboxing in that will work on 64bit. For software like Sandboxie to work on 64bit, it seems to me the developer (Tzuk) would have to re-write Sandboxie from scratch.
Cheers,
Josh
Logged
Rambaldi
Newbie
Offline
Posts: 10
Re: has cis problems under windows vista/7 64bit??
«
Reply #10 on:
October 08, 2009, 07:47:10 AM »
Quote from: 3xist on October 08, 2009, 07:06:51 AM
CIS, On Vista SP1 64x and later, Hooks in the kernel as much as possible - Comodo were also in the technical discussions with Microsoft and other Vendors of Patch Guard on Vista 64bit. However, CIS still protects 64bit enough. Comodo would NOT leave you vulnerable knowingly. As for Sandboxing, Yes, CIS 4 is coming and the Sandboxing in that will work on 64bit. For software like Sandboxie to work on 64bit, it seems to me the developer (Tzuk) would have to re-write Sandboxie from scratch.
Cheers,
Josh
OK thanks very much for the information.
Logged
res1stanCe
Comodo Member
Offline
Posts: 31
Re: has cis problems under windows vista/7 64bit??
«
Reply #11 on:
October 08, 2009, 10:05:43 AM »
sounds good
Logged
evil_religion
Malware Research Group
Comodo's Hero
Offline
Posts: 341
Re: has cis problems under windows vista/7 64bit??
«
Reply #12 on:
October 10, 2009, 01:32:15 PM »
But it's wrong. Comodo partially uses unsecured ring 3 hooks which can be avoided by Matousec SSTS.
Global hooks (injecting code into all processes), keyloggers and if I recall correctly also window messages don't get intercepted in kernel mode by Comodo.
Outpost FW passes some more tests of SSTS on x64 than Comodo, maybe they use secured user mode hooks. Comodo should do the same. I don't think that it won't be useful if Agnitum goes this way.
Logged
res1stanCe
Comodo Member
Offline
Posts: 31
Re: has cis problems under windows vista/7 64bit??
«
Reply #13 on:
October 10, 2009, 03:06:35 PM »
agnitum say to me outpost fw has ring0 control over the windows 64bit kernel
Logged
evil_religion
Malware Research Group
Comodo's Hero
Offline
Posts: 341
Re: has cis problems under windows vista/7 64bit??
«
Reply #14 on:
October 11, 2009, 12:43:39 PM »
I would like to know if there are further improvements planned for the x64 version
(at egemen
)
Also the self defense could be a bit better.
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.041 seconds with 17 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com