Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 12, 2008, 10:43:02 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
199786
Posts
22932
Topics
55032
Members
Latest Member:
noebro
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Leak Testing/Attacks/Vulnerability Research
CFP fails Clipboard Logger Simulation Test
« previous
next »
Pages:
[
1
]
2
Author
Topic: CFP fails Clipboard Logger Simulation Test (Read 3393 times)
aigle
Comodo's Hero
Offline
Posts: 327
CFP fails Clipboard Logger Simulation Test
«
on:
April 01, 2008, 07:47:19 PM »
http://www.zemana.com/list/list.asp?ktgr_id=426
More detrails here:
http://www.wilderssecurity.com/showthread.php?t=204941
Can the interception for this behavior be added in some future version?
Thanks
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 445
Spy...nah...sorry but I am just a bot
Re: CFP fails Clipboard Logger Simulation Test
«
Reply #1 on:
April 01, 2008, 08:42:50 PM »
Yes, great test.
Another challenge to Comodo crew.
There is also more tests on that site, one particular will be very interested to Comodo (SSL Logger Simulation)
Screeny of CFP failure:
Logged
XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
aigle
Comodo's Hero
Offline
Posts: 327
Re: CFP fails Clipboard Logger Simulation Test
«
Reply #2 on:
April 01, 2008, 10:18:05 PM »
Hi thanks for that.
BTW u did not tried so far my malware sample where CFP is not able to detect memory modification.
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 1740
Re: CFP fails Clipboard Logger Simulation Test
«
Reply #3 on:
April 02, 2008, 09:55:49 AM »
Quote from: aigle on April 01, 2008, 07:47:19 PM
http://www.zemana.com/list/list.asp?ktgr_id=426
More detrails here:
http://www.wilderssecurity.com/showthread.php?t=204941
Can the interception for this behavior be added in some future version?
Thanks
Yep. It seems CFP misses to catch clipboard callbacks. We will be introducing the defense against this with the upcoming versions. No worries.
the other tests should be ok.
Logged
aigle
Comodo's Hero
Offline
Posts: 327
Re: CFP fails Clipboard Logger Simulation Test
«
Reply #4 on:
April 02, 2008, 08:13:29 PM »
Thanks for this.
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 445
Spy...nah...sorry but I am just a bot
Re: CFP fails Clipboard Logger Simulation Test
«
Reply #5 on:
April 20, 2008, 06:04:35 PM »
Quote from: egemen on April 02, 2008, 09:55:49 AM
Yep. It seems CFP misses to catch clipboard callbacks. We will be introducing the defense against this with the upcoming versions. No worries.
the other tests should be ok.
It seems nothing yet for this new 3.0.22.349 build?
Logged
XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
salmonela
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 445
Spy...nah...sorry but I am just a bot
Re: CFP fails Clipboard Logger Simulation Test
«
Reply #6 on:
May 22, 2008, 02:27:17 PM »
BUMP
Upcoming version will detect clipboard logger test?
Logged
XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
aigle
Comodo's Hero
Offline
Posts: 327
Re: CFP fails Clipboard Logger Simulation Test
«
Reply #7 on:
June 01, 2008, 05:13:43 PM »
They promised to add it but seems so far it,s not done.
Logged
Goose18
Comodo's Hero
Offline
Posts: 1145
Re: CFP fails Clipboard Logger Simulation Test
«
Reply #8 on:
August 21, 2008, 11:23:40 AM »
*bump*
Quote from: egemen on April 02, 2008, 09:55:49 AM
Yep. It seems CFP misses to catch clipboard callbacks. We will be introducing the defense against this with the upcoming versions. No worries.
the other tests should be ok.
Any news on on fixing this in a future version?
Logged
Avast! 4.8, BOClean, CFP3 and did i mention Avast! 4.8
OH guess what!!! Avast! 4.8
System Specs: Pentium 4 with HT 3.06 Ghz, 1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB
aigle
Comodo's Hero
Offline
Posts: 327
Re: CFP fails Clipboard Logger Simulation Test
«
Reply #9 on:
August 21, 2008, 01:45:41 PM »
Hmmmm.... I am still waiting. I did not bump as I was waiting for next version.
Logged
fOrTy_7
Comodo Family Member
Offline
Posts: 65
Re: CFP fails Clipboard Logger Simulation Test
«
Reply #10 on:
September 12, 2008, 02:29:50 PM »
CFP version 3.5.50676.393 still doesn't pass this Clipboard-Logger Simulation Test
.
Logged
Windows XP Pro 32-bit SP3
Avira Antivir 8.1 PE
CF 3.5.52764.414
aigle
Comodo's Hero
Offline
Posts: 327
Re: CFP fails Clipboard Logger Simulation Test
«
Reply #11 on:
September 12, 2008, 05:42:18 PM »
Yes, I can confirm.
Logged
hippocrates
Newbie
Offline
Posts: 21
Re: CFP fails Clipboard Logger Simulation Test
«
Reply #12 on:
September 14, 2008, 12:11:12 AM »
Does anyone know how to configure the latest CIS Beta such that it can detect Zemana keylogger and screen logger?
I failed all the tests with CIS, even on paranoid mode. Thanks a lot.
Logged
Yuriy
Global Moderator
Comodo's Hero
Offline
Posts: 1009
Re: CFP fails Clipboard Logger Simulation Test
«
Reply #13 on:
September 14, 2008, 04:57:46 AM »
Quote from: hippocrates on September 14, 2008, 12:11:12 AM
I failed all the tests with CIS, even on paranoid mode. Thanks a lot.
For me CF 3.5 passes these two tests (Defense+ shows relevant alerts and if we block these activities, all is ok). Settings are chosen during installation: proactive defense. After installation of CF relevant Defense+ settings are not changed. Defense+ is in safe mode.
Check if settings "keyboard" and "computer monitor" are checked (are on) under gui-defense+ -advanced-defense+ settings-monitor settings. Make sure relative Zemana's executables (keylogger and screen logger) are not listed under gui-defense+ -my own safe files. Delete appropriate rules for these executables from Computer security policy of Defense+.
Now Defense+ should catch them if set to Safe or Paranoid modes.
«
Last Edit: September 14, 2008, 05:04:18 AM by Yuriy
»
Logged
hippocrates
Newbie
Offline
Posts: 21
Re: CFP fails Clipboard Logger Simulation Test
«
Reply #14 on:
September 14, 2008, 08:12:36 AM »
Quote from: Yuriy on September 14, 2008, 04:57:46 AM
For me CF 3.5 passes these two tests (Defense+ shows relevant alerts and if we block these activities, all is ok). Settings are chosen during installation: proactive defense. After installation of CF relevant Defense+ settings are not changed. Defense+ is in safe mode.
Check if settings "keyboard" and "computer monitor" are checked (are on) under gui-defense+ -advanced-defense+ settings-monitor settings. Make sure relative Zemana's executables (keylogger and screen logger) are not listed under gui-defense+ -my own safe files. Delete appropriate rules for these executables from Computer security policy of Defense+.
Now Defense+ should catch them if set to Safe or Paranoid modes.
Wow, it worked! Thanks a lot.
It seems that the 'Computer monitor' and 'keyboard' are not selected by default under the normal installation of CIS. In fact under 'Monitor Settings', most of the objects are not selected to be monitored. It's unlike a normal installation of CFP 3.0 where all the options are ticked.
One thing that I had noticed soon after enabling keyboard monitor was Firefox 3.0.1 asked for permission to access to the keyboard. At first I thought it was because I was typing this reply. However, after I blocked it (just to experiment with it), I found that I can still type into this message box, right now! If this is not the case, why on earth is Firefox trying to monitor my keystrokes?
Going back to the keylogger issue, should we suggest to Comodo to enable keyboard, monitor, and probably disk monitors by default in CIS? Under current default settings, Defense+ is vulnerable against key- and screen-loggers.
And how about other activities to monitor? Is it wise to leave them unticked too?
------------------
NEWLY ADDED: Now Firefox tried to monitor my screen, what is going on?
«
Last Edit: September 14, 2008, 08:21:08 AM by hippocrates
»
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 1 seconds with 20 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com