Welcome, Guest. Please login or register.
August 21, 2008, 11:39:33 PM

Login with username, password and session length

185080 Posts
21490 Topics
52098 Members

Latest Member: marcaro62

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Memory Firewall(Buffer Overflow Protection)
| | |-+  Frequently Asked Questions (Comodo Memory Firewall)
| | | |-+  CGM & DEP
« previous next »
Pages: [1] Go Down Print
Author Topic: CGM & DEP  (Read 5536 times)
SiberLynx
Comodo's Hero
*****
Offline Offline

Posts: 213



« on: September 02, 2007, 06:42:48 AM »

Greetings all,
Ok! Another Comodo product installed. 110 Percent
We have system software DEP implemented. Most contemporary PCs (like this one here) have Hardware-enforced DEP, which is enabled in BIOS, as recommended.
May I ask the respective community where CMG stands?
Is it a strong(-est!) additional layer of such particular type of needed security or, ideally,  in the nearest “after-beta” future – that’s all we may pray for and use?
Where can one read more detailed technical info, comparisons, reviews,.. how CMG can fight some known methods to circumvent HD and/or  SW DEP protection etc.
Thanks in advance
Logged

XP Pro, SP3; CFP v3, Defense+; CMF; BOClean; VE (currently out of order :-(
Tyler Durden
Global Moderator
Comodo Loves me
*****
Offline Offline

Posts: 164



« Reply #1 on: September 02, 2007, 07:18:59 AM »

I've allready answered that question in other topic mate Smiley Ok here we go again:
1. Software DEP is nothing but SEH chain validator (means it's not a DEP but some way to prevent one rare type of shellcode's injection)
2. Hardware DEP is very incompatible thing, that's why:
 a) DEP mode by default is OptIn = all system services are protected, user apps aren't protected
 b) DEP is _VERY_ incompatible thing so we 've got one more "layer" over DEP-mode - windows disables DEP for app which is know to be incompatible with DEP (this includes many checks, like exe-packers check and so on)
3. DEP-protection is vulnerable to ret2libc kind of attack (so you're not protected at all)

So we 've got CMG Smiley A fast and compatible way to be protected. It protects all apps against ret2libc and common BO attacks, and it doesn't treminate your favorite apps as well Smiley
« Last Edit: September 02, 2007, 07:24:01 AM by Tyler Durden » Logged

The Verve RETURNED !!! Can't you feel this beauty in life ?!
SiberLynx
Comodo's Hero
*****
Offline Offline

Posts: 213



« Reply #2 on: September 02, 2007, 09:44:43 AM »

Hi Tyler,
Thank you very much, mate Smiley
Very interesting and that's info I was searching for (ret2libc in particular).
As a matter of fact, I was searching for "DEP" before posting. I usually do that. I found some DEP-CPF related Q&A but missed that "other topic" you are referring to.
I'm sure another mate will come with the similar Q and you will be quite annoyed to
write:
I've allready answered that question in other topic mate Smiley Ok here we go again:...
It is very helpful and important info, mate Smiley. It deserves to be Sticky
I do appreciate your reply.
Ok here we go again...Mate! Wave Cheers   
Logged

XP Pro, SP3; CFP v3, Defense+; CMF; BOClean; VE (currently out of order :-(
Tyler Durden
Global Moderator
Comodo Loves me
*****
Offline Offline

Posts: 164



« Reply #3 on: September 02, 2007, 09:56:23 AM »

No problem  Cheers Cheers Cheers Cheers Cheers Cheers Cheers
Logged

The Verve RETURNED !!! Can't you feel this beauty in life ?!
SiberLynx
Comodo's Hero
*****
Offline Offline

Posts: 213



« Reply #4 on: September 02, 2007, 11:38:00 AM »

7 beers!!!???
I am not sure I will be interested in DEP after that...
unless it stands for Damn Enuresis Piss
 Smiler
Logged

XP Pro, SP3; CFP v3, Defense+; CMF; BOClean; VE (currently out of order :-(
MikeH
Comodo Loves me
****
Offline Offline

Posts: 169


« Reply #5 on: November 23, 2007, 03:32:24 PM »

It is very helpful and important info, mate Smiley. It deserves to be Sticky

I could not agree more!

Regards,
Mike
Logged
Yuriy
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 972


« Reply #6 on: February 25, 2008, 04:55:05 PM »

Just to make sure: can someone who has CMF running disable DEP completely (NoExecute=AlwaysOff) as it is useless (with CMF running)?
Logged
Tyler Durden
Global Moderator
Comodo Loves me
*****
Offline Offline

Posts: 164



« Reply #7 on: February 25, 2008, 05:59:58 PM »

Yes, you can. But overprotection is not bad too Smiley
Logged

The Verve RETURNED !!! Can't you feel this beauty in life ?!
Yuriy
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 972


« Reply #8 on: February 25, 2008, 06:34:23 PM »

Yes, you can. But overprotection is not bad too Smiley
Thanks for reply Thumb Up
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.144 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com