Welcome, Guest. Please login or register.
September 08, 2008, 06:27:31 AM

Login with username, password and session length

189681 Posts
22067 Topics
52925 Members

Latest Member: khanraider

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  Defence Plus gives no warning about process hiding
« previous next »
Pages: [1] Go Down Print
Author Topic: Defence Plus gives no warning about process hiding  (Read 1143 times)
aigle
Comodo's Hero
*****
Offline Offline

Posts: 325



« on: July 18, 2008, 09:19:39 PM »

http://www.iterati.org/Developers/HideProc/Default.aspx

I tried this tool to hide a process and no detection by CFP. TF detects it. Can detection for this behaviour be added in future?

Thanks
Logged
aigle
Comodo's Hero
*****
Offline Offline

Posts: 325



« Reply #1 on: July 20, 2008, 04:19:50 PM »

Did anyone try this so far?

Thanks
Logged
Ragwing
Guardian of the Light Master of the Force Invincible Legend Almighty
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3048



« Reply #2 on: July 21, 2008, 03:41:09 PM »

I suppose it uses a driver to hide itself? So you don't get any alert that HideProc.exe tries to install a driver?
Were you trying it in Paranoid Mode for Defense+?

Cheers,
Ragwing
Logged

"The closer you get to the light, the greater your shadow becomes"

XP SP3 2 GHz 768 MB RAM
5 services / 12 processes
aigle
Comodo's Hero
*****
Offline Offline

Posts: 325



« Reply #3 on: July 21, 2008, 05:29:23 PM »

I use paranoid settings with all custom rules even for the most system aplications.

There are two problems:

1- No detection of driver/ service install/ loading.
2- No detection of the behavior of hiding a process

See here as well.

http://forums.comodo.com/leak_testingattacksvulnerability_research/driver_service_install_not_detected-t25349.0.html
Logged
Ragwing
Guardian of the Light Master of the Force Invincible Legend Almighty
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3048



« Reply #4 on: July 22, 2008, 08:21:41 AM »

From reading the other topic, it seems like the problem is that the program uses a trusted process to install a driver.
I think this could be fixed by allowing only the drivers that come with XP/Vista by default, and ask for the rest.
There wouldn't be any problems I guess, as drivers for graphic, sound, network or whatever is installed before you reboot, so you would be able to view the alert.

Cheers,
Ragwing
Logged

"The closer you get to the light, the greater your shadow becomes"

XP SP3 2 GHz 768 MB RAM
5 services / 12 processes
ruiky
Comodo Member
**
Offline Offline

Posts: 29


« Reply #5 on: July 22, 2008, 06:45:29 PM »

From reading the other topic, it seems like the problem is that the program uses a trusted process to install a driver.
I think this could be fixed by allowing only the drivers that come with XP/Vista by default, and ask for the rest.
There wouldn't be any problems I guess, as drivers for graphic, sound, network or whatever is installed before you reboot, so you would be able to view the alert.

Cheers,
Ragwing
there are no any alert when virus uses service.exe to install a driver even if ask.
so this is a big problem need be fixed as soon as possible. this is a security bug.
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Online Online

Posts: 4576



« Reply #6 on: July 22, 2008, 10:08:17 PM »

Is this the result you want to see. Seems to work for me. I actually got 3 warnings. One for explorer.exe trying to run HideProc which is normal. Then another one about the program starting up. Then after I tried to hide Set Point I got the D+ you see. Firewall and D+ in safe mode.
Logged
aigle
Comodo's Hero
*****
Offline Offline

Posts: 325



« Reply #7 on: July 23, 2008, 12:03:29 PM »

Is this the result you want to see. Seems to work for me. I actually got 3 warnings. One for explorer.exe trying to run HideProc which is normal. Then another one about the program starting up. Then after I tried to hide Set Point I got the D+ you see. Firewall and D+ in safe mode.
What does it mean?

There is no indication that HideProc is trying to hide a process from Task Manager at all. Pop up about service control manager access is vague as it is not even specific like a driver/ service instal alertl.
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Online Online

Posts: 4576



« Reply #8 on: July 23, 2008, 12:16:34 PM »

Its an alert. Something you said you didnt get and yes this is XP. I guess you never heard of Stardock.
« Last Edit: July 23, 2008, 12:24:42 PM by Vettetech » Logged
Rafel
Comodo's Hero
*****
Offline Offline

Posts: 290


I use only the best, I use Comodo firewall


« Reply #9 on: July 23, 2008, 12:48:46 PM »

I need allow the program, but, it's true, the advice can be a bit vague, no alert about drivers/service.
Logged

Matty_R
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 952


Nice to see you,to see you nice!


« Reply #10 on: July 24, 2008, 06:45:12 AM »

Lets be fair the alert does say "The service control manager can be used to perform priveleged operations including installing high privelege applications or even device drivers"

I think in some cases the wording could be differant/better but deciding what is tricky.
Logged

KYLE`S ALLRIGHT Smiley I love Aussies
CCleaner - Freeware Windows Optimization
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Online Online

Posts: 4576



« Reply #11 on: July 24, 2008, 07:07:08 AM »

Lets be fair the alert does say "The service control manager can be used to perform priveleged operations including installing high privelege applications or even device drivers"

I think in some cases the wording could be differant/better but deciding what is tricky.

Exactly Matty. It is an alert.
Logged
aigle
Comodo's Hero
*****
Offline Offline

Posts: 325



« Reply #12 on: July 25, 2008, 03:15:57 AM »

Ok, now it,s a totally different discussion whether we like the SCM alert or not.

But my thread is about something alert. I like CFP to give a bit better alert just like TF.
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Online Online

Posts: 4576



« Reply #13 on: July 25, 2008, 06:02:53 AM »

Well you made a post stating it doesn't give a warning and looking at my screen shot it does. A warning is a warning in my eyes. Maybe it could be more descriptive but either way D+ did its job.
Logged
aigle
Comodo's Hero
*****
Offline Offline

Posts: 325



« Reply #14 on: July 25, 2008, 09:48:23 AM »

U r not getting my point. It,s OK that CFP give SCM access warning but I want it to be better than this. It should clearly tell that a service/ driver being installed( instaed of just a privilege alert) like other classical HIPS, like EQS, SSM etc.

Now not only this but I want CFP to go one step ahead and give even another alert about process hiding just like TF. It wil be part of behavioral detection by CFP.

CFP already has atleast some behavioral detection like:

Detection of files being hidden by ADS

I want this behavioral detection to expand that will make CFP exceptional among other classical HIPS. NeoavaGuard HIPS has such features but it,s development is stopped.
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.514 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com