Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
September 08, 2008, 06:27:31 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
189681
Posts
22067
Topics
52925
Members
Latest Member:
khanraider
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Leak Testing/Attacks/Vulnerability Research
Defence Plus gives no warning about process hiding
« previous
next »
Pages:
[
1
]
Author
Topic: Defence Plus gives no warning about process hiding (Read 1143 times)
aigle
Comodo's Hero
Offline
Posts: 325
Defence Plus gives no warning about process hiding
«
on:
July 18, 2008, 09:19:39 PM »
http://www.iterati.org/Developers/HideProc/Default.aspx
I tried this tool to hide a process and no detection by CFP. TF detects it. Can detection for this behaviour be added in future?
Thanks
Logged
aigle
Comodo's Hero
Offline
Posts: 325
Re: Defence Plus gives no warning about process hiding
«
Reply #1 on:
July 20, 2008, 04:19:50 PM »
Did anyone try this so far?
Thanks
Logged
Ragwing
Guardian of the Light Master of the Force Invincible Legend Almighty
Global Moderator
Comodo's Hero
Offline
Posts: 3048
Re: Defence Plus gives no warning about process hiding
«
Reply #2 on:
July 21, 2008, 03:41:09 PM »
I suppose it uses a driver to hide itself? So you don't get any alert that HideProc.exe tries to install a driver?
Were you trying it in Paranoid Mode for Defense+?
Cheers,
Ragwing
Logged
"The closer you get to the light, the greater your shadow becomes"
XP SP3
2 GHz
768 MB RAM
5 services / 12 processes
aigle
Comodo's Hero
Offline
Posts: 325
Re: Defence Plus gives no warning about process hiding
«
Reply #3 on:
July 21, 2008, 05:29:23 PM »
I use paranoid settings with all custom rules even for the most system aplications.
There are two problems:
1- No detection of driver/ service install/ loading.
2- No detection of the behavior of hiding a process
See here as well.
http://forums.comodo.com/leak_testingattacksvulnerability_research/driver_service_install_not_detected-t25349.0.html
Logged
Ragwing
Guardian of the Light Master of the Force Invincible Legend Almighty
Global Moderator
Comodo's Hero
Offline
Posts: 3048
Re: Defence Plus gives no warning about process hiding
«
Reply #4 on:
July 22, 2008, 08:21:41 AM »
From reading the other topic, it seems like the problem is that the program uses a trusted process to install a driver.
I think this could be fixed by allowing only the drivers that come with XP/Vista by default, and ask for the rest.
There wouldn't be any problems I guess, as drivers for graphic, sound, network or whatever is installed before you reboot, so you would be able to view the alert.
Cheers,
Ragwing
Logged
"The closer you get to the light, the greater your shadow becomes"
XP SP3
2 GHz
768 MB RAM
5 services / 12 processes
ruiky
Comodo Member
Offline
Posts: 29
Re: Defence Plus gives no warning about process hiding
«
Reply #5 on:
July 22, 2008, 06:45:29 PM »
Quote from: Ragwing on July 22, 2008, 08:21:41 AM
From reading the other topic, it seems like the problem is that the program uses a trusted process to install a driver.
I think this could be fixed by allowing only the drivers that come with XP/Vista by default, and ask for the rest.
There wouldn't be any problems I guess, as drivers for graphic, sound, network or whatever is installed before you reboot, so you would be able to view the alert.
Cheers,
Ragwing
there are no any alert when virus uses service.exe to install a driver even if ask.
so this is a big problem need be fixed as soon as possible. this is a security bug.
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
Online
Posts: 4576
Re: Defence Plus gives no warning about process hiding
«
Reply #6 on:
July 22, 2008, 10:08:17 PM »
Is this the result you want to see. Seems to work for me. I actually got 3 warnings. One for explorer.exe trying to run HideProc which is normal. Then another one about the program starting up. Then after I tried to hide Set Point I got the D+ you see. Firewall and D+ in safe mode.
Logged
aigle
Comodo's Hero
Offline
Posts: 325
Re: Defence Plus gives no warning about process hiding
«
Reply #7 on:
July 23, 2008, 12:03:29 PM »
Quote from: Vettetech on July 22, 2008, 10:08:17 PM
Is this the result you want to see. Seems to work for me. I actually got 3 warnings. One for explorer.exe trying to run HideProc which is normal. Then another one about the program starting up. Then after I tried to hide Set Point I got the D+ you see. Firewall and D+ in safe mode.
What does it mean?
There is no indication that HideProc is trying to hide a process from Task Manager at all. Pop up about service control manager access is vague as it is not even specific like a driver/ service instal alertl.
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
Online
Posts: 4576
Re: Defence Plus gives no warning about process hiding
«
Reply #8 on:
July 23, 2008, 12:16:34 PM »
Its an alert. Something you said you didnt get and yes this is XP. I guess you never heard of Stardock.
«
Last Edit: July 23, 2008, 12:24:42 PM by Vettetech
»
Logged
Rafel
Comodo's Hero
Offline
Posts: 290
I use only the best, I use Comodo firewall
Re: Defence Plus gives no warning about process hiding
«
Reply #9 on:
July 23, 2008, 12:48:46 PM »
I need allow the program, but, it's true, the advice can be a bit vague, no alert about drivers/service.
Logged
Matty_R
Global Moderator
Comodo's Hero
Online
Posts: 952
Nice to see you,to see you nice!
Re: Defence Plus gives no warning about process hiding
«
Reply #10 on:
July 24, 2008, 06:45:12 AM »
Lets be fair the alert does say "The service control manager can be used to perform priveleged operations including installing high privelege applications or even
device drivers
"
I think in some cases the wording could be differant/better but deciding what is tricky.
Logged
KYLE`S ALLRIGHT
I love Aussies
Vettetech
Computer Security Testing Group
Comodo's Hero
Online
Posts: 4576
Re: Defence Plus gives no warning about process hiding
«
Reply #11 on:
July 24, 2008, 07:07:08 AM »
Quote from: Matty_R on July 24, 2008, 06:45:12 AM
Lets be fair the alert does say "The service control manager can be used to perform priveleged operations including installing high privelege applications or even
device drivers
"
I think in some cases the wording could be differant/better but deciding what is tricky.
Exactly Matty. It is an alert.
Logged
aigle
Comodo's Hero
Offline
Posts: 325
Re: Defence Plus gives no warning about process hiding
«
Reply #12 on:
July 25, 2008, 03:15:57 AM »
Ok, now it,s a totally different discussion whether we like the SCM alert or not.
But my thread is about something alert. I like CFP to give a bit better alert just like TF.
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
Online
Posts: 4576
Re: Defence Plus gives no warning about process hiding
«
Reply #13 on:
July 25, 2008, 06:02:53 AM »
Well you made a post stating it doesn't give a warning and looking at my screen shot it does. A warning is a warning in my eyes. Maybe it could be more descriptive but either way D+ did its job.
Logged
aigle
Comodo's Hero
Offline
Posts: 325
Re: Defence Plus gives no warning about process hiding
«
Reply #14 on:
July 25, 2008, 09:48:23 AM »
U r not getting my point. It,s OK that CFP give SCM access warning but I want it to be better than this. It should clearly tell that a service/ driver being installed( instaed of just a privilege alert) like other classical HIPS, like EQS, SSM etc.
Now not only this but I want CFP to go one step ahead and give even another alert about process hiding just like TF. It wil be part of behavioral detection by CFP.
CFP already has atleast some behavioral detection like:
Detection of files being hidden by ADS
I want this behavioral detection to expand that will make CFP exceptional among other classical HIPS. NeoavaGuard HIPS has such features but it,s development is stopped.
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.514 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com