Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 28, 2009, 09:00:01 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
345865
Posts
38192
Topics
86755
Members
Latest Member:
salmon739
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Leak Testing/Attacks/Vulnerability Research
Defence+ failed against malware
« previous
next »
Pages:
[
1
]
2
3
Author
Topic: Defence+ failed against malware (Read 14967 times)
aigle
Comodo's Hero
Offline
Posts: 504
Defence+ failed against malware
«
on:
February 02, 2008, 09:29:28 PM »
On my system Defence+ failed against SSDT unhooker rootkit( rootkit EZ). I allowed execution and denied all other behaviouirs of rootkit but it is able to destroy CFP, install hidedden drivers and CDP doesn,t give alerts about execution of any new executables after this.
I allowed execution of Sohand IM worm and denied all other actions of this malware but it was able to bypass Defence+ making Task Manager and RegEdit disabled.
Pretty disappointing. I have the samples. Anyone needs, PM me.
Thanks
«
Last Edit: February 02, 2008, 09:34:16 PM by aigle
»
Logged
00hmh
Comodo Family Member
Offline
Posts: 74
Re: Defence+ failed against malware
«
Reply #1 on:
February 03, 2008, 12:52:55 AM »
What behaviours did you block that you expected to prevent the harm?
Rootkits by nature have powerful abilities inherent in that status.
I am curious to hear from our Comodo folks, but allowing the malware to execute seems a highly dangerous behavior and playing with fire is a good way to burn fingers.
Logged
Ragwing
Global Moderator
Comodo's Hero
Offline
Posts: 3451
Re: Defence+ failed against malware
«
Reply #2 on:
February 03, 2008, 11:41:48 AM »
Greetings!
Quote from: aigle on February 02, 2008, 09:29:28 PM
I allowed execution of Sohand IM worm and denied all other actions of this malware but it was able to bypass Defence+ making Task Manager and RegEdit disabled.
This is because HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ isn't added in My Protected Registry Entries by default.
The virus adds the REG_DWORD's DisableTaskMgr and DisableRegistryTools and set them to 1.
Also, could you please PM me the files so that I could run a test with Defense+?
Cheers,
Ragwing
Logged
Forum Policy
FAQs
aigle
Comodo's Hero
Offline
Posts: 504
Re: Defence+ failed against malware
«
Reply #3 on:
February 05, 2008, 01:36:11 AM »
I have sent to u.
Thanks
Logged
Ultra-Bot
Comodo Family Member
Offline
Posts: 59
Re: Defence+ failed against malware
«
Reply #4 on:
February 05, 2008, 05:33:40 AM »
Quote from: Ragwing on February 03, 2008, 11:41:48 AM
Greetings!
This is because HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ isn't added in My Protected Registry Entries by default.
The virus adds the REG_DWORD's DisableTaskMgr and DisableRegistryTools and set them to 1.
Also, could you please PM me the files so that I could run a test with Defense+?
Cheers,
Ragwing
Than how is possible to pass this rootkit test?
I thought CFP 3.0 protects its files and processes against all kinds of attacks by default, inlcuding the registry files you mentioned above.
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 496
COMODO Volunteer DEModerator
Re: Defence+ failed against malware
«
Reply #5 on:
February 05, 2008, 07:11:49 AM »
Here is couple of registry tests which CFP doesnt completely pass by default (download in attachment)
BTW on regtest phase2 CFP crashes...
Note: for successful testing of regtest you need to allow: regtest.exe to execute regtest.exe and to regtest.exe access regtest.exe in memory, every other request should be denied.
«
Last Edit: February 05, 2008, 07:33:34 AM by salmonela
»
Logged
XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
Ultra-Bot
Comodo Family Member
Offline
Posts: 59
Re: Defence+ failed against malware
«
Reply #6 on:
February 08, 2008, 11:21:15 AM »
Quote from: Ragwing on February 03, 2008, 11:41:48 AM
Greetings!
This is because HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ isn't added in My Protected Registry Entries by default.
The virus adds the REG_DWORD's DisableTaskMgr and DisableRegistryTools and set them to 1.
Also, could you please PM me the files so that I could run a test with Defense+?
Cheers,
Ragwing
Does CFP 3.0 now pass and block SSDT unhooker rootkit ( rootkit EZ) now and how does CFP 3.0 pass it?
If it doesn't pass, than I hope both Melih and Egemen will respond and react, I hope.
Logged
Ragwing
Global Moderator
Comodo's Hero
Offline
Posts: 3451
Re: Defence+ failed against malware
«
Reply #7 on:
February 08, 2008, 03:14:18 PM »
I've uploaded the tests here in a zip file, containing one avi file (Xvid) for each test.
The unhooker was pretty owned by Dr Watson and DEP.
Tested on a virtual XP PRO SP 2 with DEP enabled for everything and CFP 3 with firewall in Custom Policy Mode and Defense+ in Paranoid Mode.
Cheers,
Ragwing
Logged
Forum Policy
FAQs
Ultra-Bot
Comodo Family Member
Offline
Posts: 59
Re: Defence+ failed against malware
«
Reply #8 on:
February 08, 2008, 04:08:56 PM »
Quote from: Ragwing on February 08, 2008, 03:14:18 PM
I've uploaded the tests here in a zip file, containing one avi file (Xvid) for each test.
The unhooker was pretty owned by Dr Watson and DEP.
Tested on a virtual XP PRO SP 2 with DEP enabled for everything and CFP 3 with firewall in Custom Policy Mode and Defense+ in Paranoid Mode.
Cheers,
Ragwing
Hi, Ragwing!
I want to thank you for your answer. I saw your testing in avi format. But one thing I don't understand.
Does CFP 3.0 pass these tests you tried or not,because I didn't see if it said that CFP passed or not?
What does Windows ask you in the end?
Dat har programmet avslutades for att skydda datorn- what does it mean if you don't mind.
There is also choice:
Andra installnigar and Stang meddelandet (you choose this option)
Does it mean like Windows ask you do you want to and are you sure that you want to install this RTKT Agent EZ. SSDT Unhooker and Sohand.e IM Worm coolpics?
Also, from where I can download these tests and WILL THEY HURT MY COMPUTER IN CASE CFP 3.0 DOESN'T PASS THEM?
Also, what to allow and what to exactly block?
You have allowed rundll32.exe, drwtswin.exe and dumprep.exe and blocked everything else?
How come Aigle (poster who started this thread) failed to block these rootkits tests?
Thank you for your time and patience, again!
Logged
Ragwing
Global Moderator
Comodo's Hero
Offline
Posts: 3451
Re: Defence+ failed against malware
«
Reply #9 on:
February 08, 2008, 04:39:01 PM »
Quote from: Ultra-Bot on February 08, 2008, 04:08:56 PM
Hi, Ragwing!
I want to thank you for your answer. I saw your testing in avi format. But one thing I don't understand.
Does CFP 3.0 pass these tests you tried or not,because I didn't see if it said that CFP passed or not?
I'd say it passed the first one, but for the other one, I can't say it did, since I couldn't test it properly with CFP 3. But DEP will protect you from it.
Quote from: Ultra-Bot on February 08, 2008, 04:08:56 PM
What does Windows ask you in the end?
Dat har programmet avslutades for att skydda datorn- what does it mean if you don't mind.
It means that Windows has terminated the program to protect my computer.
Quote from: Ultra-Bot on February 08, 2008, 04:08:56 PM
There is also choice:
Andra installnigar and Stang meddelandet (you choose this option)
Does it mean like Windows ask you do you want to and are you sure that you want to install this RTKT Agent EZ. SSDT Unhooker and Sohand.e IM Worm coolpics?
No, it means Edit settings and Close this message
Quote from: Ultra-Bot on February 08, 2008, 04:08:56 PM
Also, from where I can download these tests and WILL THEY HURT MY COMPUTER IN CASE CFP 3.0 DOESN'T PASS THEM?
I can send them to you. But they
will harm your computer
if CFP 3 fails to block them. That's why I tested them in a virtual PC.
Quote from: Ultra-Bot on February 08, 2008, 04:08:56 PM
Also, what to allow and what to exactly block?
You have allowed rundll32.exe, drwtswin.exe and dumprep.exe and blocked everything else?
You should only allow executions.and block all other actions.
Quote from: Ultra-Bot on February 08, 2008, 04:08:56 PM
How come Aigle (poster who started this thread) failed to block these rootkits tests?
We used different versions of CFP 3, and we both have different system configurations
Cheers,
Ragwing
«
Last Edit: February 08, 2008, 05:15:58 PM by Ragwing
»
Logged
Forum Policy
FAQs
Ultra-Bot
Comodo Family Member
Offline
Posts: 59
Re: Defence+ failed against malware
«
Reply #10 on:
February 08, 2008, 05:14:10 PM »
Quote from: Ragwing on February 08, 2008, 04:39:01 PM
I'd say it passed the first one, but for the other one, I can't say it did, since I couldn't test it properly with CFP 3. But DEP will protect you from it.
It means that Windows has terminated the program to protect my computer.
No, it means Edit settings and Close this message
I can send them to you. But they
will harm your computer[/u] if CFP 3 fails to block them. That's why I tested them in a virtual PC.
You should only allow executions.and block all other actions.
We used different versions of CFP 3, and we both have different system configurations
Cheers,
Ragwing
Again thanks for your time and patience, but what do you mean by DEP?
Also, could you please retest the second for which you're not sure if you passed or not?
And how do you know you passed the second test (the one you're not sure that you passed)?
Also, did you pick up these tests from Unhooker malware tests:
http://membres.lycos.fr/nicmtests/Unhookers/unhooking_tests.htm
I tried to email to this guy Nicola to test CFP 3.0 the same as Dynamic Security Agent in about 80 tests, but there was no response:
Here is the review of Dynamic Security Agent:
http://membres.lycos.fr/nicmtests/Dynamic-Security-agent-tests/DSA_index.htm
Big thanks, again.
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 2151
Re: Defence+ failed against malware
«
Reply #11 on:
February 08, 2008, 05:56:45 PM »
Quote from: aigle on February 02, 2008, 09:29:28 PM
On my system Defence+ failed against SSDT unhooker rootkit( rootkit EZ). I allowed execution and denied all other behaviouirs of rootkit but it is able to destroy CFP, install hidedden drivers and CDP doesn,t give alerts about execution of any new executables after this.
That sounds alarming. I dont think it is possible unless there is something wrong with your configuration. Can you please urgently PM me this rootkit?
Quote
I allowed execution of Sohand IM worm and denied all other actions of this malware but it was able to bypass Defence+ making Task Manager and RegEdit disabled.
That should be because of the registry key Ragwing mentioned. Need to check to see. It can be easily added to my protected registry keys by default though. It is not bypassing D+. It is just that D+ does not protect that key. Thats all.
But this issue is not really important compared to the first one in which you claim a driver is installed. That would really be a serious problem. Please urgently send me these samples so that we can protect our users if there is something wrong.
Thanks,
egemen
Logged
Ragwing
Global Moderator
Comodo's Hero
Offline
Posts: 3451
Re: Defence+ failed against malware
«
Reply #12 on:
February 08, 2008, 06:32:43 PM »
Quote from: Ultra-Bot on February 08, 2008, 05:14:10 PM
Again thanks for your time and patience, but what do you mean by DEP?
Data Execution Prevention
Quote from: Ultra-Bot on February 08, 2008, 05:14:10 PM
Also, could you please retest the second for which you're not sure if you passed or not?
And how do you know you passed the second test (the one you're not sure that you passed)?
I'll disable DEP and re-run the test tomorrow, got to sleep now
Quote from: egemen on February 08, 2008, 05:56:45 PM
That sounds alarming. I dont think it is possible unless there is something wrong with your configuration. Can you please urgently PM me this rootkit?
I've PM'ed it to you now.
Cheers,
Ragwing
Logged
Forum Policy
FAQs
egemen
Administrator
Comodo's Hero
Offline
Posts: 2151
Re: Defence+ failed against malware
«
Reply #13 on:
February 08, 2008, 06:32:57 PM »
Quote from: Ragwing on February 08, 2008, 03:14:18 PM
I've uploaded the tests here in a zip file, containing one avi file (Xvid) for each test.
The unhooker was pretty owned by Dr Watson and DEP.
Tested on a virtual XP PRO SP 2 with DEP enabled for everything and CFP 3 with firewall in Custom Policy Mode and Defense+ in Paranoid Mode.
Cheers,
Ragwing
Ok i have just reviewed the videos.
As I see from the AVI videos of Ragwing(Kudos!), there are 2 popups which prevent this rootkit.EZ. first one is about privilege escalletion:
1 - rootkit is trying to obtain debug privilege. This is blocked and hence it crashes because it assumes it can obtain such a privilege without being intercepted. So if it is allowed, i believe we can see other things such as interprocess memory access etc. Since it is blocked, it just crashes.
2 - rootkit is trying to access the Service Control Manager. This is another important alert because it is trying to install a driver, which, if installed , could be a serious problem.
There are other popups like rundll32.exe etc which could be a problem later on. Thank you for the AVI Ragwing. It was really cool.
Other than that, we can also see in video 1, CFP D+ detects Sohand IM Trojan as a virus! This demontrates another aspect of what a powerful engine Defense+ is against the unknown malware.
Egemen
«
Last Edit: February 08, 2008, 06:45:04 PM by egemen
»
Logged
Ragwing
Global Moderator
Comodo's Hero
Offline
Posts: 3451
Re: Defence+ failed against malware
«
Reply #14 on:
February 08, 2008, 06:38:07 PM »
Quote from: egemen on February 08, 2008, 06:32:57 PM
1 - rootkit is trying to obtain debug privilege. This is blocked and hence it crashes because it assumes it can obtain such a privilege without being intercepted. So if it is allowed, i believe we can see other things such as interprocess memory access etc. Since it is blocked, it just crashes.
I thought DEP prevented it, but it looks like Microsoft can't do anything right after all...
And most users that know what they're doing would never give Debug to a completely unknown process. That's just insane!
Quote from: Ultra-Bot on February 08, 2008, 05:14:10 PM
2 - rootkit is trying to access the Service Control Manager. This is another important alert because it is trying to install a driver, which, if installed , could be a serious problem.
Yes, but if you allow it, it should say that it's trying to create name.drv in system 32 or some other location.
Quote from: Ultra-Bot on February 08, 2008, 05:14:10 PM
There are other popups like rundll32.exe etc which could be a problem later on.
Yeah, but it's because of Dr Watson, I guess
Quote from: Ultra-Bot on February 08, 2008, 05:14:10 PM
Thank you for the AVI Ragwing. It was really cool.
No problem.
Quote from: Ultra-Bot on February 08, 2008, 05:14:10 PM
Except the service control manager alert, if you try to allow Debug privilege popup, i am sure there will be other sorts of interesting alerts like LoadDriver or interprocess meory access etc.
Yes. But you can't properly test a HIPS if you allow suspicious stuff like giving it Debug.
Quote from: Ultra-Bot on February 08, 2008, 05:14:10 PM
Other than that, we can also see in video 1, CFP D+ detects Sohand IM Trojan as a virus! This demontrates another aspect of what a powerful engine Defense+ is against the unknown malware.
Does it work by scanning the behaviour of the files or does it analyze the code?
Cheers,
Ragwing
Logged
Forum Policy
FAQs
Tags:
Pages:
[
1
]
2
3
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.071 seconds with 17 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com