Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
September 08, 2008, 06:26:54 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
189681
Posts
22067
Topics
52925
Members
Latest Member:
khanraider
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Leak Testing/Attacks/Vulnerability Research
Memory modification not detected?
« previous
next »
Pages:
[
1
]
2
3
Author
Topic: Memory modification not detected? (Read 4269 times)
aigle
Comodo's Hero
Offline
Posts: 325
Memory modification not detected?
«
on:
March 06, 2008, 06:54:24 PM »
When I run this spoofed jpg image, It starts a hidden window of InternetExplorer. Seems that spoofed jpg then modifies the memory of InternetExplorer( IE) and IE then in turn creates more copies of malicious executabels.
CFP D plus does not give any warning about memory modification. Is it some thing missing?
Any explanation from the developers will be appreciated. I can send the file if asked.
Thanks
Logged
aigle
Comodo's Hero
Offline
Posts: 325
Re: Memory modification not detected?
«
Reply #1 on:
March 10, 2008, 01:04:59 PM »
Bump!
Anyone please?
Logged
Blas
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 361
Re: Memory modification not detected?
«
Reply #2 on:
March 10, 2008, 01:20:57 PM »
Ok send it.
Im not a programmer neither a specialist but I can try it out.
Is it malicious or just a POC?
Logged
aigle
Comodo's Hero
Offline
Posts: 325
Re: Memory modification not detected?
«
Reply #3 on:
March 10, 2008, 06:38:22 PM »
No, it,s a real malware. So are u willing to try it?
Thanks
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 442
Spy...nah...sorry but I am just a bot
Re: Memory modification not detected?
«
Reply #4 on:
March 10, 2008, 08:25:58 PM »
Quote from: aigle on March 06, 2008, 06:54:24 PM
When I run this spoofed jpg image, It starts a hidden window of InternetExplorer. Seems that spoofed jpg then modifies the memory of InternetExplorer( IE) and IE then in turn creates more copies of malicious executabels.
CFP D plus does not give any warning about memory modification. Is it some thing missing?
Any explanation from the developers will be appreciated. I can send the file if asked.
Thanks
Just curiosity... Does that ".jpg" pulls the same trigger as a eq secure (mem. access/mod.) in CFP if you put *.jpg in groups of executables in "My Protected Files"?
Logged
XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
aigle
Comodo's Hero
Offline
Posts: 325
Re: Memory modification not detected?
«
Reply #5 on:
March 10, 2008, 10:31:52 PM »
Quote from: salmonela on March 10, 2008, 08:25:58 PM
Just curiosity... Does that ".jpg" pulls the same trigger as a eq secure (mem. access/mod.) in CFP if you put *.jpg in groups of executables in "My Protected Files"?
I don,t expect so but I did not try. I will try it later.
Logged
aigle
Comodo's Hero
Offline
Posts: 325
Re: Memory modification not detected?
«
Reply #6 on:
March 10, 2008, 10:34:06 PM »
Another one. This is with virus W32/Jefoo.A.
Infact it seems that Defence Plus is missing too many memeory modifications. I don,t know what is the issue.
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 442
Spy...nah...sorry but I am just a bot
Re: Memory modification not detected?
«
Reply #7 on:
March 11, 2008, 07:25:43 AM »
Hmmm I dont see anything unsafe in third picture, If you wanna see prompt between two safe apps. you should run CFP in paranoid mode...
Logged
XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
Yuriy
Global Moderator
Comodo's Hero
Offline
Posts: 972
Re: Memory modification not detected?
«
Reply #8 on:
March 11, 2008, 12:29:41 PM »
aigle,
As for third alert set d+ to paranoid mode (like salmonela suggested) and make sure iexplore.exe is not already allowed to access explorer.exe in memory and not allowed to execute explorer.exe.
Logged
Blas
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 361
Re: Memory modification not detected?
«
Reply #9 on:
March 11, 2008, 01:14:31 PM »
The popup from defense+ asking if malware.exe can access iexplorer.exe in memory was allowed or blocked?
If you allowed it then it is normal behavior that you didn't received alert for the further actions of iexplorer.exe. This is because iexplorer.exe is considered safe. Try deleting the rules for iexplorer.exe and set defense+ to paranoid mode and disable 'learn automatically applications signed by comodo". In this case you should receive the second alert too..
Oh and the sample...if its malware, I cant test it right now. Im using my VM to test firewalls for testmypcsecurity.com and I haven't got cfp installed at the moment..Maybe later, but thanks.
Logged
aigle
Comodo's Hero
Offline
Posts: 325
Re: Memory modification not detected?
«
Reply #10 on:
March 12, 2008, 02:08:28 AM »
Hi Salmonela, goodbrazer and Blas.
Thanks for the reply.
About third alert you are right. I missed that point.
My first post is still a question. Here Defence + is not ginving an alert.
[ at ] Blis
Sending you the file link via PM.
Thanks
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 442
Spy...nah...sorry but I am just a bot
Re: Memory modification not detected?
«
Reply #11 on:
March 12, 2008, 01:15:16 PM »
Please aigle, could you PM me with fake jpg (malware) link, also?
I would like to test it,
Tia
Logged
XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
panic
Global Moderator
Comodo's Hero
Offline
Posts: 5391
... and I say to myself, "What a wonderful world"
Re: Memory modification not detected?
«
Reply #12 on:
March 12, 2008, 05:36:33 PM »
Out of curiousity, how do you run a JPG?
It's not an executable extension and would merely call whatever app is registered to handle them.
Or do you mean that it is an EXE with a double extension of ".jpg.exe"?
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
ggf31416
Comodo Loves me
Offline
Posts: 108
Re: Memory modification not detected?
«
Reply #13 on:
March 12, 2008, 06:14:41 PM »
Quote from: panic on March 12, 2008, 05:36:33 PM
Out of curiousity, how do you run a JPG?
It's not an executable extension and would merely call whatever app is registered to handle them.
I think you need an unpatched vulnerability or outdated software to run it in Internet explorer
Of course, you can always run a renamed executable in the command no matter the extension.
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 5391
... and I say to myself, "What a wonderful world"
Re: Memory modification not detected?
«
Reply #14 on:
March 12, 2008, 07:19:49 PM »
Q.E.D.
You're not running the JPG, per se, you're loading it into another application that may or may not have vulnerabilities. The flaw lies in the application, not the data file.
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Tags:
Pages:
[
1
]
2
3
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.273 seconds with 20 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com