Welcome, Guest. Please login or register.
October 12, 2008, 10:43:02 PM

Login with username, password and session length

199786 Posts
22932 Topics
55032 Members

Latest Member: noebro

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  CFP fails Clipboard Logger Simulation Test
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: CFP fails Clipboard Logger Simulation Test  (Read 3393 times)
aigle
Comodo's Hero
*****
Offline Offline

Posts: 327



« on: April 01, 2008, 07:47:19 PM »

http://www.zemana.com/list/list.asp?ktgr_id=426

More detrails here:

http://www.wilderssecurity.com/showthread.php?t=204941

Can the interception for this behavior be added in some future version?

Thanks
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 445


Spy...nah...sorry but I am just a bot


« Reply #1 on: April 01, 2008, 08:42:50 PM »

Yes, great test.
Another challenge to Comodo crew.
There is also more tests on that site, one particular will be very interested to Comodo (SSL Logger Simulation)

Screeny of CFP failure:
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
aigle
Comodo's Hero
*****
Offline Offline

Posts: 327



« Reply #2 on: April 01, 2008, 10:18:05 PM »

Hi thanks for that.

BTW u did not tried so far my malware sample where CFP is not able to detect memory modification.
Logged
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 1740



« Reply #3 on: April 02, 2008, 09:55:49 AM »

http://www.zemana.com/list/list.asp?ktgr_id=426

More detrails here:

http://www.wilderssecurity.com/showthread.php?t=204941

Can the interception for this behavior be added in some future version?

Thanks

Yep. It seems CFP misses to catch clipboard callbacks. We will be introducing the defense against this with the upcoming versions. No worries.

the other tests should be ok.
Logged
aigle
Comodo's Hero
*****
Offline Offline

Posts: 327



« Reply #4 on: April 02, 2008, 08:13:29 PM »

Thanks for this.
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 445


Spy...nah...sorry but I am just a bot


« Reply #5 on: April 20, 2008, 06:04:35 PM »

Yep. It seems CFP misses to catch clipboard callbacks. We will be introducing the defense against this with the upcoming versions. No worries.

the other tests should be ok.
It seems nothing yet for this new 3.0.22.349 build?
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 445


Spy...nah...sorry but I am just a bot


« Reply #6 on: May 22, 2008, 02:27:17 PM »

BUMP
Upcoming version will detect clipboard logger test?
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
aigle
Comodo's Hero
*****
Offline Offline

Posts: 327



« Reply #7 on: June 01, 2008, 05:13:43 PM »

They promised to add it but seems so far it,s not done.
Logged
Goose18
Comodo's Hero
*****
Offline Offline

Posts: 1145



« Reply #8 on: August 21, 2008, 11:23:40 AM »

*bump*     



Yep. It seems CFP misses to catch clipboard callbacks. We will be introducing the defense against this with the upcoming versions. No worries.

the other tests should be ok.


Any news on on fixing this in a future version?  Love Comodo
Logged

Avast! 4.8, BOClean, CFP3 and did i mention Avast! 4.8 Grin  OH guess what!!! Avast! 4.8 Grin


System Specs:  Pentium 4 with HT 3.06 Ghz,  1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB
aigle
Comodo's Hero
*****
Offline Offline

Posts: 327



« Reply #9 on: August 21, 2008, 01:45:41 PM »

Hmmmm.... I am still waiting. I did not bump as I was waiting for next version.
Logged
fOrTy_7
Comodo Family Member
***
Offline Offline

Posts: 65


« Reply #10 on: September 12, 2008, 02:29:50 PM »

CFP version 3.5.50676.393 still doesn't pass this Clipboard-Logger Simulation Test  Roll Eyes .
Logged

Windows XP Pro 32-bit SP3
Avira Antivir 8.1 PE
CF 3.5.52764.414
aigle
Comodo's Hero
*****
Offline Offline

Posts: 327



« Reply #11 on: September 12, 2008, 05:42:18 PM »

Yes, I can confirm.
Logged
hippocrates
Newbie
*
Offline Offline

Posts: 21


« Reply #12 on: September 14, 2008, 12:11:12 AM »

Does anyone know how to configure the latest CIS Beta such that it can detect Zemana keylogger and screen logger?

I failed all the tests with CIS, even on paranoid mode.  Thanks a lot.
Logged
Yuriy
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1009


« Reply #13 on: September 14, 2008, 04:57:46 AM »

I failed all the tests with CIS, even on paranoid mode.  Thanks a lot.
For me CF 3.5 passes these two tests (Defense+ shows relevant alerts and if we block these activities, all is ok). Settings are chosen during installation: proactive defense. After installation of CF relevant Defense+ settings are not changed. Defense+ is in safe mode.

Check if settings "keyboard" and "computer monitor" are checked (are on) under gui-defense+ -advanced-defense+ settings-monitor settings. Make sure relative Zemana's executables (keylogger and screen logger) are not listed under gui-defense+ -my own safe files. Delete appropriate rules for these executables from Computer security policy of Defense+.
Now Defense+ should catch them if set to Safe or Paranoid modes. 
« Last Edit: September 14, 2008, 05:04:18 AM by Yuriy » Logged
hippocrates
Newbie
*
Offline Offline

Posts: 21


« Reply #14 on: September 14, 2008, 08:12:36 AM »

For me CF 3.5 passes these two tests (Defense+ shows relevant alerts and if we block these activities, all is ok). Settings are chosen during installation: proactive defense. After installation of CF relevant Defense+ settings are not changed. Defense+ is in safe mode.

Check if settings "keyboard" and "computer monitor" are checked (are on) under gui-defense+ -advanced-defense+ settings-monitor settings. Make sure relative Zemana's executables (keylogger and screen logger) are not listed under gui-defense+ -my own safe files. Delete appropriate rules for these executables from Computer security policy of Defense+.
Now Defense+ should catch them if set to Safe or Paranoid modes. 

Wow, it worked! Thanks a lot. Smiley

It seems that the 'Computer monitor' and 'keyboard' are not selected by default under the normal installation of CIS.  In fact under 'Monitor Settings', most of the objects are not selected to be monitored.  It's unlike a normal installation of CFP 3.0 where all the options are ticked.

One thing that I had noticed soon after enabling keyboard monitor was Firefox 3.0.1 asked for permission to access to the keyboard.  At first I thought it was because I was typing this reply.  However, after I blocked it (just to experiment with it), I found that I can still type into this message box, right now!  If this is not the case, why on earth is Firefox trying to monitor my keystrokes?

Going back to the keylogger issue, should we suggest to Comodo to enable keyboard, monitor, and probably disk monitors by default in CIS?  Under current default settings, Defense+ is vulnerable against key- and screen-loggers.

And how about other activities to monitor?  Is it wise to leave them unticked too?

------------------

NEWLY ADDED: Now Firefox tried to monitor my screen, what is going on? Smiley

« Last Edit: September 14, 2008, 08:21:08 AM by hippocrates » Logged
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 1 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com