Welcome, Guest. Please login or register.
Did you miss your activation email?
May 18, 2013, 07:51:36 AM

Login with username, password and session length

662849 Posts
70567 Topics
145137 Members

Latest Member: tacchan23

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Leak Testing/Attacks/Vulnerability Research
| | |-+  Comodo DLL injection via weak hash function exploitation Vulnerability
« previous next »
Pages: [1] Go Down Print
Author Topic: Comodo DLL injection via weak hash function exploitation Vulnerability  (Read 6058 times)
srinath
Newbie
*
Offline Offline

Posts: 5


« on: February 17, 2007, 06:52:12 AM »

                               This originally appeared in the wilders security forums by a person called grey87y.
"Comodo Firewall Pro (former Comodo Personal Firewall) implements a component control, which is based on a checksum comparison of process modules. Probably to achieve a better performance, cyclic redundancy check (CRC32) is used as a checksum function in its implementation. However, CRC32 was developed for error detection purposes and can not be used as a reliable cryptographic hashing function because it is possible to generate collisions in real time. The character of CRC32 allows attacker to construct a malicious module with the same CRC32 checksum as a chosen trusted module in the target system and thus bypass the protection of the component control.
Vulnerable software:

* Comodo Firewall Pro 2.4.17.183
* Comodo Firewall Pro 2.4.16.174
* Comodo Personal Firewall 2.3.6.81
* probably all older versions of Comodo Personal Firewall 2
* possibly older versions of Comodo Personal Firewall"
                                      I don't know the truth behind it but just wanted to bring it your notice.  I love and greatly admire comodo firewall and looking forward to the stable version ofCAVS. Many members at wilders security are not very grateful though. (B)
« Last Edit: February 17, 2007, 07:11:34 AM by srinath » Logged
soyabeaner
Guest
« Reply #1 on: February 17, 2007, 07:53:39 AM »

That originated from Matousec's advisory and it shows Comodo was notified on 2007-02-01.
Logged
Dwarden
Newbie
*
Offline Offline

Posts: 19


« Reply #2 on: February 17, 2007, 12:18:47 PM »

IMHO use of CRC32 was performance/easy coding trick ...

now when CPF matured it's time to offer users minimum of MD5 or some SHA hashing
(or ideally both, switchable in options (who want perf use MD5 who want safe use SHA-256) ...

« Last Edit: February 17, 2007, 12:20:31 PM by Dwarden » Logged

Ideas are like ocean w/o borders!
srinath
Newbie
*
Offline Offline

Posts: 5


« Reply #3 on: February 18, 2007, 02:27:56 AM »

That originated from Matousec's advisory and it shows Comodo was notified on 2007-02-01.
Thanks for clarification.
Logged
Rotty
Comodo's Hero
*****
Offline Offline

Posts: 903


http://www.venganza.org/ - Noodly Appendage


« Reply #4 on: February 18, 2007, 04:15:08 AM »

I gotta say that using a Cyclic redundancy check for a cryptographic check is against cryptography 101 and should really not have happened.

That being said, i am sure they will fix it.
Logged

The opinions expressed in my posts are my own. 
They do NOT necessarily represent or reflect the views of my employer.
Toxteth O'Grady
Comodo's Hero
*****
Offline Offline

Posts: 588


« Reply #5 on: February 18, 2007, 04:32:17 AM »

If it is that bad, why did they use it in the first place?  Huh
This calls for an offical Comodo reply\clarification
Logged
Rotty
Comodo's Hero
*****
Offline Offline

Posts: 903


http://www.venganza.org/ - Noodly Appendage


« Reply #6 on: February 18, 2007, 06:23:56 AM »

I can't support the original decision as i know too much  Tongue .  That being said, allot of vendors seem to make poor programming decisions and quick-fixes and in the end, development time and the security added may not have made business sense...

Anything i say is my opinion and not the opinion of Comodo, or any organization or person i may have contact with, but let me re-state for this thread that anything said by myself is MY opinion ONLY.

An official comment would be a good idea....



Logged

The opinions expressed in my posts are my own. 
They do NOT necessarily represent or reflect the views of my employer.
edeppi
Newbie
*
Offline Offline

Posts: 24


« Reply #7 on: February 19, 2007, 04:28:58 AM »

Will be fixed or not???

Comodo please reply.

Thanks
Logged
soccerfan
Newbie
*
Offline Offline

Posts: 7


« Reply #8 on: February 19, 2007, 03:15:51 PM »

The silence from Comodo in regard to this problem is deafening.
Wonder why Melih and/or others are not responding!

Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 12913



WWW
« Reply #9 on: February 19, 2007, 04:31:59 PM »

this is already fixed for v3...

Melih
Logged

Bubu74
Comodo Loves me
****
Offline Offline

Posts: 177


« Reply #10 on: February 19, 2007, 05:26:58 PM »

this is already fixed for v3...

Melih

I'm glad to hear that, and hope it will be released soon.  Grin
Logged

COMODO user since January 2007
soccerfan
Newbie
*
Offline Offline

Posts: 7


« Reply #11 on: February 19, 2007, 05:57:21 PM »

Thanks for the update, Melih.
This new version 3 should be worth the wait.

Any fixes for the current 2.x in sight?
Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 12913



WWW
« Reply #12 on: February 19, 2007, 06:18:27 PM »

Thanks for the update, Melih.
This new version 3 should be worth the wait.

Any fixes for the current 2.x in sight?

the 3 is only weeks away..
this attack is in the wild and we don't expect to see it within next few weeks.
Hence we decided to concentrate all the developers on v3 rather than take their focus off it.

Melih
Logged

VaMPiRiC_CRoW
Guest
« Reply #13 on: February 19, 2007, 06:26:08 PM »

this is already fixed for v3...
Cheers
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 1.829 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com