Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 18, 2013, 11:57:51 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
662934
Posts
70576
Topics
145149
Members
Latest Member:
DrEsterhazy
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Leak Testing/Attacks/Vulnerability Research
weakness of the gpCode
« previous
next »
Pages:
1
...
5
6
[
7
]
8
9
10
Author
Topic: weakness of the gpCode (Read 76744 times)
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12913
Re: Comodo Defence Plus bypassed by malware
«
Reply #90 on:
April 27, 2011, 10:28:11 PM »
This is an attack on data, rather than the system.
of course its still not desirable.
I will discuss it with the guys to see what their plan is
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
wasgij6
Global Moderator
Comodo's Hero
Offline
Posts: 3062
Re: CFW fails in GPCode ransom test
«
Reply #91 on:
April 27, 2011, 10:34:49 PM »
Quote from: egemen on April 27, 2011, 10:27:54 PM
Hi Guys,
Let me comment on this one more time. First of all, if configured, CIS can very well protect against this and any other threats proactively.
First lets see what this gpcode does: It gets to the users computer drive by download and searches for the files in users harddisk. It then encrypts all picture and text files i.e. damages some non-OS-essential files.
Is this a threat to the user ? YES!
Is this a real threat to be prevented ? YES!
Does CIS prevent against this now? YES!
Then how does COMODO protect against this
BY DEFAULT
. By default, antivirus detection is enough to detect gpcode and any of its variants. Lets not make false comments by saying CIS does not protect its users against gpcode. CIS DOES prevent against the REAL threat wih its antivirus right now.
Now lets talk about preventing this proactively.
Is there a way to configure CIS to prevent this proactively? YES.
Method 1: Add you sensitive files/folders to CIS protected files list and you are done. For example, you can add My Documents, My Pictures folders or *.doc, *.txt, *.jpg etc. to your protected files list and it can be protected.
Method 2: Always run your WEB browsers in COMODO Sandbox by adding them to Sandbox pemanently. And while doing this, make sure File system and registry virtualization are both enabled. If you do this and accidently get gpcode or something like gpcode or actually any virus from WEB, they will be running in a virtual file system and hence they can not acess your files or folders.
You can also directly run GPCODE with right-click menu in CIS sandbpx and you will see it cant do anything.
Ofcourse CIS is capable of preventing it proactively as of now. However, these settings are not configured by default.
So why is COMODO not making an immediate HACK to prevent this proactively. Some other products are preventing it already.
We do not need to make a HACK but offer you a proper solution which is proven to prevent this and any similar threat while not affecting your daily work with your computer.
The proper solution is the active file system virtualization of *SOME* automatically sandboxed applications by default. Yes, we are right now working on this kind of a ideal automatic sandbox which is going to be in CIS 6 and will work similar to method 2.
It is NOT a HACK but a properly engineered solution that *avreage joe* wont have problems when CIS is installed.
It takes 10 minutes to write a HACK which simply checks each applications right to enumerate files and folders and thats it. You are there. And what would be the cost? Joe's photo editor will create a popup asking him if he wants some application to list files. Or Marry, while his new MP3 player builds a playlist, it might conflict.
well this is good to hear that the autosandbox is going to be virtualized eventually. its just a threat now becuz most people are running in default settings and if there happens to be a new variant that cis doesnt detect then the user is going to get infected.
Logged
| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
harsha_mic
Computer Security Testing Group
Comodo Loves me
Offline
Posts: 154
Re: CFW fails in GPCode ransom test
«
Reply #92 on:
April 27, 2011, 10:38:40 PM »
thanks for your reply and suggestions egemen. very much appreciated for prompt response.
sadly, i'm using OA premium now. but, hope to come back to Comodo Firewall soon.
Logged
W7 64 bit | Comodo Fw v5.8 | Eset NOD32 AV v5 | Hitman (ondemand)
harsha_mic
Computer Security Testing Group
Comodo Loves me
Offline
Posts: 154
Re: weakness of the gpCode
«
Reply #93 on:
April 27, 2011, 10:48:10 PM »
i have a question reg method 2 approach with browsers -
suppose, a malware bypasses AV detection and is executed to creates the files on virtual file system (as the browser is run in the manual sandbox). Would the files created by the malware be removed after system restart automatically?
Logged
W7 64 bit | Comodo Fw v5.8 | Eset NOD32 AV v5 | Hitman (ondemand)
egemen
Comodo Staff
Comodo's Hero
Offline
Posts: 3269
Re: weakness of the gpCode
«
Reply #94 on:
April 27, 2011, 10:54:37 PM »
Quote from: harsha_mic on April 27, 2011, 10:48:10 PM
i have a question reg method 2 approach with browsers -
suppose, a malware bypasses AV detection and is executed to creates the files on virtual file system (as the browser is run in the manual sandbox). Would the files created by the malware be removed after system restart automatically?
The files it creates will be in your virtual folder. they wont be cleaned automatically but they are inactive so you can delete them manually. Consider them as some TEMPORARY files.
Logged
wasgij6
Global Moderator
Comodo's Hero
Offline
Posts: 3062
Re: weakness of the gpCode
«
Reply #95 on:
April 27, 2011, 10:59:17 PM »
what happened to the other 2 topics you moved here?
Logged
| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
harsha_mic
Computer Security Testing Group
Comodo Loves me
Offline
Posts: 154
Re: weakness of the gpCode
«
Reply #96 on:
April 27, 2011, 11:10:23 PM »
Quote from: egemen on April 27, 2011, 10:54:37 PM
The files it creates will be in your virtual folder. they wont be cleaned automatically but they are inactive so you can delete them manually. Consider them as some TEMPORARY files.
Thanks egemen
Logged
W7 64 bit | Comodo Fw v5.8 | Eset NOD32 AV v5 | Hitman (ondemand)
morphiusz
Star Group
Comodo's Hero
Offline
Posts: 2195
Comodo's śmieć :)
Re: weakness of the gpCode
«
Reply #97 on:
April 28, 2011, 12:05:37 AM »
Quote
It is NOT a HACK but a properly engineered solution that *avreage joe* wont have problems when CIS is installed.
It takes 10 minutes to write a HACK which simply checks each applications right to enumerate files and folders and thats it. You are there. And what would be the cost? Joe's photo editor will create a popup asking him if he wants some application to list files. Or Marry, while his new MP3 player builds a playlist, it might conflict.
Egemen,
i don't see ANY single problem there.
When application is whitelisted user don't get any popups.
Prompts abour direct disk acces, hook setting also can be very problematic for avreage joe but they are exist. Other firewalls (like OA) have it, and i don;t see anyone who complain about this alert...
The same will be with getting the list of the files. Another method to protect the user's files - TO PROTECT the user finally.
You mentioned about AV, as we (you especially) know AV is very unreliable .
Some day it may not detect new variant of Gpcode etc. (this is why you create a deafult deny system - Melih was talking about this in his video).
So, i don't see any reason to not to do this D+'s funcionality. It will be a prompt as any other (will not be appear with whitelisted apps, etc. - just like others prompts now!).
Here are the good sites:
-it'll prevent the GpCode (user won't lose all his/her pics, docs, movies),
-it'll prevent blackday virus (vulnerabilites mentoined by aigle in this topic)
-and any other unknown Threats...which want to do bad thing with you files
bad sites?
-alert as any other... (actually bad site? good site!)
none which i can see.
Thanks!
mod edit: 15pt changed to 12pt for readability. kail
«
Last Edit: April 28, 2011, 02:00:24 AM by kail
»
Logged
kail
Mostly Benevolent
Global Moderator
Comodo's Hero
Offline
Posts: 10753
The future is much like the present, only longer.
Re: weakness of the gpCode
«
Reply #98 on:
April 28, 2011, 01:55:57 AM »
Quote from: wasgij6 on April 27, 2011, 10:59:17 PM
what happened to the other 2 topics you moved here?
They are all here, please check the Subject of the posts. See
this
topic for more details.
Logged
System Details: W7x64U with CIS 6, Firefox 20, IceDragon 20 & Becky! 2.65
Forum Policy
.
____
I don't know what weapons countries might use to fight World War III, but wars after that will be fought with sticks and stones. Einstein
mkowalski8
Newbie
Offline
Posts: 13
Re: weakness of the gpCode
«
Reply #99 on:
April 28, 2011, 02:06:52 AM »
I don't understand one thing. Comodo owns a cloud, so when someone is attacked by new malware/virus/etc the unknown file should be sent to Comodo servers and analyzed by experts. After that, it is marked as dangerous and every user, who uses cloud is protected. Does it really work, because I see that there are trouble with new malware, but it should be blocked by cloud even if automated software doesn't recognize it (I think, that there are people at Comodo, not only computers).
Logged
kail
Mostly Benevolent
Global Moderator
Comodo's Hero
Offline
Posts: 10753
The future is much like the present, only longer.
Re: weakness of the gpCode
«
Reply #100 on:
April 28, 2011, 02:35:48 AM »
Hi mkowalski8
You are correct. However, I believe the guys above are specifically talking about Defense+ only (ie. CIS without the AV component).
Logged
System Details: W7x64U with CIS 6, Firefox 20, IceDragon 20 & Becky! 2.65
Forum Policy
.
____
I don't know what weapons countries might use to fight World War III, but wars after that will be fought with sticks and stones. Einstein
aigle
Comodo's Hero
Offline
Posts: 673
Re: CFW fails in GPCode ransom test
«
Reply #101 on:
April 28, 2011, 04:38:06 AM »
Quote from: egemen on April 27, 2011, 10:27:54 PM
Hi Guys,
Let me comment on this one more time. First of all, if configured, CIS can very well protect against this and any other threats proactively.
First lets see what this gpcode does: It gets to the users computer drive by download and searches for the files in users harddisk. It then encrypts all picture and text files i.e. damages some non-OS-essential files.
Is this a threat to the user ? YES!
Is this a real threat to be prevented ? YES!
Does CIS prevent against this now? YES!
Then how does COMODO protect against this
BY DEFAULT
. By default, antivirus detection is enough to detect gpcode and any of its variants. Lets not make false comments by saying CIS does not protect its users against gpcode. CIS DOES prevent against the REAL threat wih its antivirus right now.
Now lets talk about preventing this proactively.
Is there a way to configure CIS to prevent this proactively? YES.
Method 1: Add you sensitive files/folders to CIS protected files list and you are done. For example, you can add My Documents, My Pictures folders or *.doc, *.txt, *.jpg etc. to your protected files list and it can be protected.
Method 2: Always run your WEB browsers in COMODO Sandbox by adding them to Sandbox pemanently. And while doing this, make sure File system and registry virtualization are both enabled. If you do this and accidently get gpcode or something like gpcode or actually any virus from WEB, they will be running in a virtual file system and hence they can not acess your files or folders.
You can also directly run GPCODE with right-click menu in CIS sandbpx and you will see it cant do anything.
Ofcourse CIS is capable of preventing it proactively as of now. However, these settings are not configured by default.
So why is COMODO not making an immediate HACK to prevent this proactively. Some other products are preventing it already.
We do not need to make a HACK but offer you a proper solution which is proven to prevent this and any similar threat while not affecting your daily work with your computer.
The proper solution is the active file system virtualization of *SOME* automatically sandboxed applications by default. Yes, we are right now working on this kind of a ideal automatic sandbox which is going to be in CIS 6 and will work similar to method 2.
It is NOT a HACK but a properly engineered solution that *avreage joe* wont have problems when CIS is installed.
It takes 10 minutes to write a HACK which simply checks each applications right to enumerate files and folders and thats it. You are there. And what would be the cost? Joe's photo editor will create a popup asking him if he wants some application to list files. Or Marry, while his new MP3 player builds a playlist, it might conflict.
Hi egemen! Thanks for your response.
1- I think if you use the HACK, user will not get many pop ups due to the white list. Right? I fail to understand why there will be pop ups about the photo editor of MP3 player when they will be in the white list( in all probability).
2- The method you are going to use in future( method 2) has one flaw. It will be good for the users who are using default config of Defence Plus as malware will run virtualized and can,t touch the actual system or data files. Bt what about uesrs who are not using sandbox and are using just proactive HIPS feature of Defence Plus. It is not very much practical to add all your sensitive files in one folder and then protect this folder. One might have many .doc, .txt and image files scattered here n there on hard disk. Besides what you will do about blackday trojan that is targeting so many types of files.
To be honest I don,t see any good reason for not adding the HACK to protect against such malware. Gpcode n blackday trojan are just an example, one might face a very similar trojan but more clever, more destructive and more nasty.
«
Last Edit: April 28, 2011, 04:43:02 AM by aigle
»
Logged
egemen
Comodo Staff
Comodo's Hero
Offline
Posts: 3269
Re: CFW fails in GPCode ransom test
«
Reply #102 on:
April 28, 2011, 09:00:29 AM »
Quote from: aigle on April 28, 2011, 04:38:06 AM
Hi egemen! Thanks for your response.
1- I think if you use the HACK, user will not get many pop ups due to the white list. Right? I fail to understand why there will be pop ups about the photo editor of MP3 player when they will be in the white list( in all probability).
Sure. If whitelisted, there wont be a problem. Howevver we have all the whitelist + cloud and yet there are popups causing the users simply shutdown or uinstall the protection. In this case, less is more.
Quote
2- The method you are going to use in future( method 2) has one flaw. It will be good for the users who are using default config of Defence Plus as malware will run virtualized and can,t touch the actual system or data files. Bt what about uesrs who are not using sandbox and are using just proactive HIPS feature of Defence Plus. It is not very much practical to add all your sensitive files in one folder and then protect this folder. One might have many .doc, .txt and image files scattered here n there on hard disk. Besides what you will do about blackday trojan that is targeting so many types of files.
To be honest I don,t see any good reason for not adding the HACK to protect against such malware. Gpcode n blackday trojan are just an example, one might face a very similar trojan but more clever, more destructive and more nasty.
Hack is a hack. Not a solution. Putting such a hack into 30 million computers for just a few detectable trojans which are already easily detected already is not preferable. Why? Because it will detect more white files then bad files. Guaranteed.
Btw, it is already detected by the cloud based behavior analysis. So for example, if a user does not use an AV and does not use Sandbox, still, cloud based analysis will alert the user about the trojan.
So there are many ways that a default user is being protcted now hence no need for hacks. The problem is protecting the data of the user. And this requires a more sophisticated method of prevention which is what we are doing now.
The upcoming solution is not specificaly designed for this threat however it prevents much more important data attacks as well as this one.
Logged
loverboy
Comodo's Hero
Offline
Posts: 402
Re: weakness of the gpCode
«
Reply #103 on:
April 28, 2011, 11:11:43 AM »
Sorry for the stupid question, but if I run Internet Explorer in the sandbox what will happen if I save a file on the Desktop?
Will it go there or will it go somewhere in a "virtual" folder?
Logged
Windows 7 Home Premium 64bit SP1
NOD32 Antivirus 4.2.71.2
COMODO CIS 5.10.228257.2253
Configuration: Proactive Security
Firewall Security Level: Custom Policy Mode
Defense+ Security Level: Clean PC Mode
Sandbox: Disabled
egemen
Comodo Staff
Comodo's Hero
Offline
Posts: 3269
Re: weakness of the gpCode
«
Reply #104 on:
April 28, 2011, 11:15:11 AM »
Quote from: loverboy on April 28, 2011, 11:11:43 AM
Sorry for the stupid question, but if I run Internet Explorer in the sandbox what will happen if I save a file on the Desktop?
Will it go there or will it go somewhere in a "virtual" folder?
Sure. It will go to the virtual folder the original desktop will remain clean.
Logged
Tags:
Pages:
1
...
5
6
[
7
]
8
9
10
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.055 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com