Welcome, Guest. Please login or register.
January 08, 2010, 06:56:49 AM

Login with username, password and session length

348977 Posts
38574 Topics
87707 Members

Latest Member: mad11

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  CFP fails Clipboard Logger Simulation Test
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: CFP fails Clipboard Logger Simulation Test  (Read 8494 times)
aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« on: April 01, 2008, 07:47:19 PM »

http://www.zemana.com/list/list.asp?ktgr_id=426

More detrails here:

http://www.wilderssecurity.com/showthread.php?t=204941

Can the interception for this behavior be added in some future version?

Thanks
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 501


COMODO Volunteer DEModerator


« Reply #1 on: April 01, 2008, 08:42:50 PM »

Yes, great test.
Another challenge to Comodo crew.
There is also more tests on that site, one particular will be very interested to Comodo (SSL Logger Simulation)

Screeny of CFP failure:
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #2 on: April 01, 2008, 10:18:05 PM »

Hi thanks for that.

BTW u did not tried so far my malware sample where CFP is not able to detect memory modification.
Logged
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 2151



« Reply #3 on: April 02, 2008, 09:55:49 AM »

http://www.zemana.com/list/list.asp?ktgr_id=426

More detrails here:

http://www.wilderssecurity.com/showthread.php?t=204941

Can the interception for this behavior be added in some future version?

Thanks

Yep. It seems CFP misses to catch clipboard callbacks. We will be introducing the defense against this with the upcoming versions. No worries.

the other tests should be ok.
Logged
aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #4 on: April 02, 2008, 08:13:29 PM »

Thanks for this.
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 501


COMODO Volunteer DEModerator


« Reply #5 on: April 20, 2008, 06:04:35 PM »

Yep. It seems CFP misses to catch clipboard callbacks. We will be introducing the defense against this with the upcoming versions. No worries.

the other tests should be ok.
It seems nothing yet for this new 3.0.22.349 build?
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 501


COMODO Volunteer DEModerator


« Reply #6 on: May 22, 2008, 02:27:17 PM »

BUMP
Upcoming version will detect clipboard logger test?
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #7 on: June 01, 2008, 05:13:43 PM »

They promised to add it but seems so far it,s not done.
Logged
Goose19
Comodo's Hero
*****
Offline Offline

Posts: 1218



« Reply #8 on: August 21, 2008, 11:23:40 AM »

*bump*     



Yep. It seems CFP misses to catch clipboard callbacks. We will be introducing the defense against this with the upcoming versions. No worries.

the other tests should be ok.


Any news on on fixing this in a future version?  (L)
Logged

System Specs:  Pentium 4 with HT 3.06 Ghz,  1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB DDR3



New Build: AMD Athlon 64 x2 6000 3.1 Ghz  4 Gb RAM 320GB WDC Hard Drive 650 watt quad rail Power supply(overkill Cheesy) 9500GT Hybrid SLi with 8200 (onboard video) Decent Gaming rig Smiley
aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #9 on: August 21, 2008, 01:45:41 PM »

Hmmmm.... I am still waiting. I did not bump as I was waiting for next version.
Logged
fOrTy_7
Comodo's Hero
*****
Online Online

Posts: 359


« Reply #10 on: September 12, 2008, 02:29:50 PM »

CFP version 3.5.50676.393 still doesn't pass this Clipboard-Logger Simulation Test  Roll Eyes .
Logged

Windows XP Pro SP3 32-bit
Comodo Internet Security 3.13.126709.581
aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #11 on: September 12, 2008, 05:42:18 PM »

Yes, I can confirm.
Logged
hippocrates
Newbie
*
Offline Offline

Posts: 21


« Reply #12 on: September 14, 2008, 12:11:12 AM »

Does anyone know how to configure the latest CIS Beta such that it can detect Zemana keylogger and screen logger?

I failed all the tests with CIS, even on paranoid mode.  Thanks a lot.
Logged
SS26
Comodo's Hero
*****
Offline Offline

Posts: 1508


« Reply #13 on: September 14, 2008, 04:57:46 AM »

I failed all the tests with CIS, even on paranoid mode.  Thanks a lot.
For me CF 3.5 passes these two tests (Defense+ shows relevant alerts and if we block these activities, all is ok). Settings are chosen during installation: proactive defense. After installation of CF relevant Defense+ settings are not changed. Defense+ is in safe mode.

Check if settings "keyboard" and "computer monitor" are checked (are on) under gui-defense+ -advanced-defense+ settings-monitor settings. Make sure relative Zemana's executables (keylogger and screen logger) are not listed under gui-defense+ -my own safe files. Delete appropriate rules for these executables from Computer security policy of Defense+.
Now Defense+ should catch them if set to Safe or Paranoid modes. 
« Last Edit: September 14, 2008, 05:04:18 AM by Yuriy » Logged
hippocrates
Newbie
*
Offline Offline

Posts: 21


« Reply #14 on: September 14, 2008, 08:12:36 AM »

For me CF 3.5 passes these two tests (Defense+ shows relevant alerts and if we block these activities, all is ok). Settings are chosen during installation: proactive defense. After installation of CF relevant Defense+ settings are not changed. Defense+ is in safe mode.

Check if settings "keyboard" and "computer monitor" are checked (are on) under gui-defense+ -advanced-defense+ settings-monitor settings. Make sure relative Zemana's executables (keylogger and screen logger) are not listed under gui-defense+ -my own safe files. Delete appropriate rules for these executables from Computer security policy of Defense+.
Now Defense+ should catch them if set to Safe or Paranoid modes. 

Wow, it worked! Thanks a lot. Smiley

It seems that the 'Computer monitor' and 'keyboard' are not selected by default under the normal installation of CIS.  In fact under 'Monitor Settings', most of the objects are not selected to be monitored.  It's unlike a normal installation of CFP 3.0 where all the options are ticked.

One thing that I had noticed soon after enabling keyboard monitor was Firefox 3.0.1 asked for permission to access to the keyboard.  At first I thought it was because I was typing this reply.  However, after I blocked it (just to experiment with it), I found that I can still type into this message box, right now!  If this is not the case, why on earth is Firefox trying to monitor my keystrokes?

Going back to the keylogger issue, should we suggest to Comodo to enable keyboard, monitor, and probably disk monitors by default in CIS?  Under current default settings, Defense+ is vulnerable against key- and screen-loggers.

And how about other activities to monitor?  Is it wise to leave them unticked too?

------------------

NEWLY ADDED: Now Firefox tried to monitor my screen, what is going on? Smiley

« Last Edit: September 14, 2008, 08:21:08 AM by hippocrates » Logged
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.126 seconds with 20 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com