Welcome, Guest. Please login or register.
October 13, 2008, 05:47:11 AM

Login with username, password and session length

199821 Posts
22938 Topics
55049 Members

Latest Member: eerieuk

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Help for v3
| | | |-+  Firefox and Opera asking for direct keyboard access.. do I have a keylogger?
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: Firefox and Opera asking for direct keyboard access.. do I have a keylogger?  (Read 544 times)
Memnock
Newbie
*
Offline Offline

Posts: 3


« on: July 15, 2008, 08:10:58 PM »

I just installed Comodo Firewall Pro 3 and when I opened up Firefox or Opera, one of the alerts I received is that these applications requested "direct keyboard access".   I did not recieve this message when using IE.  Is this normal for Firefox and Opera or do I have a keylogger?

I've scanned my PC with Nod32 and Ewido and nothing was detected.  I'm running Vista Ultimate 64bit. 

Any information welcome.  Thanks.

 Mod StarThis Issue Is Resolved- 3xist. Mod Star
« Last Edit: July 16, 2008, 11:45:32 PM by 3xist » Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 4631



« Reply #1 on: July 15, 2008, 08:16:25 PM »

There is a new feature now with Firefox 3.0 and its called virtual keyboard so that warning is normal.
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 4631



« Reply #2 on: July 15, 2008, 08:20:39 PM »

I am pretty sure of this.
Logged
3xist
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2707



« Reply #3 on: July 15, 2008, 09:56:36 PM »

There is a new feature now with Firefox 3.0 and its called virtual keyboard so that warning is normal.

Never heard of it? Unless it's part of the malware protection...
Logged

Memnock
Newbie
*
Offline Offline

Posts: 3


« Reply #4 on: July 15, 2008, 10:25:20 PM »

Hmm. now I've gotten this alert with several applications when I launch them, including Nero.  Why would any of these need direct keyboard access?
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 4631



« Reply #5 on: July 15, 2008, 10:52:53 PM »

Sorry I remember something about KAV09 having a virtual keyboard. But every program out there now uses keyboard short cuts including Firefox,Winamp,Nero. You can browse the internet using Firefox and only a keyboard.
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3652


I'm not grumpy, just misunderstood.


« Reply #6 on: July 16, 2008, 09:15:19 AM »

Correct me if I'm wrong.. but, doesn't anything that you actually type into or use the keyboard with need direct access to the.. erm.. keyboard?
Logged

XP Pro+SP3 and Vista Bus+SP1 with CFP 3.0.25.378 & AntiVir PE 8.1 & Firefox 3.0.1
__
Will computers ever be as smart as humans? Probably.. very, very briefly.
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 4631



« Reply #7 on: July 16, 2008, 09:44:00 AM »

Exactly....................
Logged
gibran
Forum Member
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3839


Sometimes words are meaningless indeed...


« Reply #8 on: July 16, 2008, 09:58:24 AM »

Correct me if I'm wrong.. but, doesn't anything that you actually type into or use the keyboard with need direct access to the.. erm.. keyboard?

Maybe. I wasn't able to understand what specifically trigger that alert but even if you disable direct keyboard access right for ,eg. notepad, it still possible to type text (please test this to sort out the chance there is something wrong with my setup  Tongue ).

According to Anti-Keylogger Tester v3.0 direct keyboard access is at least required for GetKeyState,GetAsyncKeyState,GetKeyboardState,GetRawInputData APIs but CFP may trap also other APIs as well.

Those APIs are not malicious by themseves but they could be used for keyloggin purposes.
Opera, Firefox and other applications (even IE on my PC) trigger Direct keyboard alerts, maybe a totally different API is involved.
Such alerts alerts doesn't look relevant enough to guess the app has a keyogging purpose.

IMHO some alerts means that an app has "chances" to be used for keylogging purposes.

If you run Anti-Keylogger Tester v3.0 and deny direct screen access at startup you'll see that the splashscreen will not be displayed correctly.
The corresponding APIs needed for such feature could also be used also to grab a screenshoot (screenshot2 test).

In such cases I guess that the answer to these alerts can be only based on the trust abiut the legitimate purpose of such programs.
Only a RE professional could be able to find out if a program is really malicious.

IMHO it won't hurt to test more restrictive policies to find out if a software really need some access rights.

I really hope that something like a behavioural fingerprinting standard could be used in future.

Logged

kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3652


I'm not grumpy, just misunderstood.


« Reply #9 on: July 16, 2008, 10:16:19 AM »

With this alert, I think you should only be concerned if something unexpected appears.. unknown or unusual EXE/DLL requesting keyboard access.

Notepad: Difficult to test.. I can't get CFP to prompt for it at all. Even if I turn trusted vendors off, remove the existing rule & switch Defense to Paranoid Mode. Also tried WordPad to no avail. No keyboard prompts here.
« Last Edit: July 16, 2008, 10:18:10 AM by kail » Logged

XP Pro+SP3 and Vista Bus+SP1 with CFP 3.0.25.378 & AntiVir PE 8.1 & Firefox 3.0.1
__
Will computers ever be as smart as humans? Probably.. very, very briefly.
gibran
Forum Member
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3839


Sometimes words are meaningless indeed...


« Reply #10 on: July 16, 2008, 10:41:25 AM »

With this alert, I think you should only be concerned if something unexpected appears.. unknown or unusual EXE/DLL requesting keyboard access.

Notepad: Difficult to test.. I can't get CFP to prompt for it at all. Even if I turn trusted vendors off, remove the existing rule & switch Defense to Paranoid Mode. Also tried WordPad to no avail. No keyboard prompts here.

Maybe my setup cause this but I'm not able to find a way to sort this out. The only application I guess could trigger this are Logitech setpoint or windows advanced text services.

Anyway I guess the OP could test if disabling direct keyboard access in opera prevent him for typing text or using keyboard shortcuts.
Logged

kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3652


I'm not grumpy, just misunderstood.


« Reply #11 on: July 16, 2008, 11:12:15 AM »

Ah.. now that's possible. If you have a keyboard with special keys that has the obligatory special software, then its "hooks" into other applications might be triggering the alert. I have a standard keyboard & mouse plugged into a hardware KVM switch that is connected to 3 systems (including the monitor). There is no special software & it's transparent to Windows.
Logged

XP Pro+SP3 and Vista Bus+SP1 with CFP 3.0.25.378 & AntiVir PE 8.1 & Firefox 3.0.1
__
Will computers ever be as smart as humans? Probably.. very, very briefly.
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 4631



« Reply #12 on: July 16, 2008, 11:16:49 AM »

I have a Logitech G15 USB keyboard and I have gottin alerts like this.
Logged
gibran
Forum Member
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3839


Sometimes words are meaningless indeed...


« Reply #13 on: July 16, 2008, 11:21:56 AM »

Ah.. now that's possible. If you have a keyboard with special keys that has the obligatory special software, then its "hooks" into other applications might be triggering the alert. I have a standard keyboard & mouse plugged into a hardware KVM switch that is connected to 3 systems (including the monitor). There is no special software & it's transparent to Windows.
Guess so. Other apps that come to mind are ATI Catalyst Control Center or Nvidia nView desktop Manager. I recently uninstalled my AV to test some CFP behaviours so I don't plan to do a mass uninstall to track down the culprit.
Anyway having an app to place a globalhook without even a notice in those apps is really bothersome. It would have been nice to know what to check beforehand Undecided
« Last Edit: July 16, 2008, 11:25:58 AM by gibran » Logged

frogger
Comodo's Hero
*****
Offline Offline

Posts: 339



« Reply #14 on: July 16, 2008, 11:52:42 AM »

i got these alerts to i have a special kyb a Microsoft natural ergonomic keyboard 4000 i think this is what triggered these for me and it has special keys for internet shortcuts and favorites and the like.
« Last Edit: July 16, 2008, 11:56:28 AM by frogger » Logged

God Bless
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.109 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com