Welcome, Guest. Please login or register.
September 08, 2008, 06:26:54 AM

Login with username, password and session length

189681 Posts
22067 Topics
52925 Members

Latest Member: khanraider

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  Memory modification not detected?
« previous next »
Pages: [1] 2 3 Go Down Print
Author Topic: Memory modification not detected?  (Read 4269 times)
aigle
Comodo's Hero
*****
Offline Offline

Posts: 325



« on: March 06, 2008, 06:54:24 PM »

When I run this spoofed jpg image, It starts a hidden window of InternetExplorer. Seems that spoofed jpg then modifies the memory of InternetExplorer( IE)  and IE then in turn creates more copies of malicious executabels.

CFP D plus does not give any warning about memory modification. Is it some thing missing?
Any explanation from the developers will be appreciated. I can send the file if asked.

 Thanks
Logged
aigle
Comodo's Hero
*****
Offline Offline

Posts: 325



« Reply #1 on: March 10, 2008, 01:04:59 PM »

Bump!

Anyone please?
Logged
Blas
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 361


« Reply #2 on: March 10, 2008, 01:20:57 PM »

Ok send it.
Im not a programmer neither a specialist but I can try it out.
Is it malicious or just a POC?
Logged
aigle
Comodo's Hero
*****
Offline Offline

Posts: 325



« Reply #3 on: March 10, 2008, 06:38:22 PM »

No, it,s a real malware. So are u willing to try it?

Thanks
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 442


Spy...nah...sorry but I am just a bot


« Reply #4 on: March 10, 2008, 08:25:58 PM »

When I run this spoofed jpg image, It starts a hidden window of InternetExplorer. Seems that spoofed jpg then modifies the memory of InternetExplorer( IE)  and IE then in turn creates more copies of malicious executabels.

CFP D plus does not give any warning about memory modification. Is it some thing missing?
Any explanation from the developers will be appreciated. I can send the file if asked.

 Thanks
Just curiosity... Does that ".jpg" pulls the same trigger as a eq secure (mem. access/mod.) in CFP if you put *.jpg in groups  of executables  in "My Protected Files"?
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
aigle
Comodo's Hero
*****
Offline Offline

Posts: 325



« Reply #5 on: March 10, 2008, 10:31:52 PM »

Just curiosity... Does that ".jpg" pulls the same trigger as a eq secure (mem. access/mod.) in CFP if you put *.jpg in groups  of executables  in "My Protected Files"?

I don,t expect so but I did not try. I will try it later.
Logged
aigle
Comodo's Hero
*****
Offline Offline

Posts: 325



« Reply #6 on: March 10, 2008, 10:34:06 PM »

Another one. This is with virus W32/Jefoo.A.

Infact it seems that Defence Plus is missing too many memeory modifications. I don,t know what is the issue.
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 442


Spy...nah...sorry but I am just a bot


« Reply #7 on: March 11, 2008, 07:25:43 AM »

Hmmm I dont see anything unsafe in third picture, If you wanna see prompt between two safe apps. you should run CFP in paranoid mode...
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
Yuriy
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 972


« Reply #8 on: March 11, 2008, 12:29:41 PM »

aigle,

As for third alert set d+ to paranoid mode (like salmonela suggested) and make sure iexplore.exe is not already allowed to access explorer.exe in memory and not allowed to execute explorer.exe.
Logged
Blas
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 361


« Reply #9 on: March 11, 2008, 01:14:31 PM »

The popup from defense+ asking if malware.exe can access iexplorer.exe in memory was allowed or blocked?
If you allowed it then it is normal behavior that you didn't received alert for the further actions of iexplorer.exe. This is because iexplorer.exe is considered safe. Try deleting the rules for iexplorer.exe and set defense+ to paranoid mode and disable 'learn automatically applications signed by comodo". In this case you should receive the second alert too..

Oh and the sample...if its malware, I cant test it right now. Im using my VM to test firewalls for testmypcsecurity.com and I haven't got cfp installed at the moment..Maybe later, but thanks.
Logged
aigle
Comodo's Hero
*****
Offline Offline

Posts: 325



« Reply #10 on: March 12, 2008, 02:08:28 AM »

Hi Salmonela, goodbrazer and Blas.

Thanks for the reply.

About third alert you are right. I missed that point.

My first post is still a question. Here Defence + is not ginving an alert.

[ at ] Blis

Sending you the file link via PM.

Thanks
Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 442


Spy...nah...sorry but I am just a bot


« Reply #11 on: March 12, 2008, 01:15:16 PM »

Please aigle, could you PM me with fake jpg (malware) link, also?
I would like to test it,
Tia
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5391


... and I say to myself, "What a wonderful world"


« Reply #12 on: March 12, 2008, 05:36:33 PM »

Out of curiousity, how do you run a JPG?

It's not an executable extension and would merely call whatever app is registered to handle them.

Or do you mean that it is an EXE with a double extension of ".jpg.exe"?

Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
ggf31416
Comodo Loves me
****
Offline Offline

Posts: 108


« Reply #13 on: March 12, 2008, 06:14:41 PM »

Out of curiousity, how do you run a JPG?

It's not an executable extension and would merely call whatever app is registered to handle them.


I think you need an unpatched vulnerability or outdated software to run it in Internet explorer

Of course, you can always run a renamed executable in the command no matter the extension.

Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5391


... and I say to myself, "What a wonderful world"


« Reply #14 on: March 12, 2008, 07:19:49 PM »

Q.E.D.

You're not running the JPG, per se, you're loading it into another application that may or may not have vulnerabilities. The flaw lies in the application, not the data file.

Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
Tags:
Pages: [1] 2 3 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.273 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com